The SUSE Linux Enterprise 12 SP3 kernel was updated to 4.4.114 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2017-5715: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis (bnc#1068032). The previous fix using CPU Microcode has been complemented by building the Linux Kernel with return trampolines aka "retpolines". - CVE-2017-15129: A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel in the function get_net_ns_by_id() in net/core/net_namespace.c did not check for the net::count value after it has found a peer network in netns_ids idr,
#1005778 #1005780 #1005781 #1012382 #1012917
#1015342 #1015343 #1019784 #1022476 #1022595
#1022912 #1024296 #1024376 #1031395 #1031492
#1031717 #1037838 #1038078 #1038085 #1040182
#1043652 #1048325 #1048585 #1053472 #1060279
#1062129 #1066163 #1066223 #1068032 #1068038
#1068569 #1068984 #1069138 #1069160 #1070052
#1070799 #1072163 #1072484 #1073229 #1073928
#1074134 #1074488 #1074621 #1074709 #1074839
#1074847 #1075066 #1075078 #1075087 #1075091
#1075397 #1075428 #1075617 #1075621 #1075627
#1075811 #1075994 #1076017 #1076110 #1076187
#1076232 #1076805 #1076847 #1076872 #1076899
#1077068 #1077560 #1077592 #1077704 #1077871
#1078002 #1078681 #963844 #966170 #966172
#973818 #985025
...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.