Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

SUSE: 2018:0383-1 Important: Linux Kernel Security Update

suse
Calendar Grey February 7, 2018
Dist Suse Esm H88
Stay informed on critical updates for SUSE Linux Kernel that address various security vulnerabilities. The following are comprehensive patch instructions for implementation.
An update that solves 9 vulnerabilities and has 68 fixes is now available.

Summary

The SUSE Linux Enterprise 12 SP3 kernel was updated to 4.4.114 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2017-5715: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis (bnc#1068032). The previous fix using CPU Microcode has been complemented by building the Linux Kernel with return trampolines aka "retpolines". - CVE-2017-15129: A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel in the function get_net_ns_by_id() in net/core/net_namespace.c did not check for the net::count value after it has found a peer network in netns_ids idr,

References

#1005778 #1005780 #1005781 #1012382 #1012917

#1015342 #1015343 #1019784 #1022476 #1022595

#1022912 #1024296 #1024376 #1031395 #1031492

#1031717 #1037838 #1038078 #1038085 #1040182

#1043652 #1048325 #1048585 #1053472 #1060279

#1062129 #1066163 #1066223 #1068032 #1068038

#1068569 #1068984 #1069138 #1069160 #1070052

#1070799 #1072163 #1072484 #1073229 #1073928

#1074134 #1074488 #1074621 #1074709 #1074839

#1074847 #1075066 #1075078 #1075087 #1075091

#1075397 #1075428 #1075617 #1075621 #1075627

#1075811 #1075994 #1076017 #1076110 #1076187

#1076232 #1076805 #1076847 #1076872 #1076899

#1077068 #1077560 #1077592 #1077704 #1077871

#1078002 #1078681 #963844 #966170 #966172

#973818 #985025

...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:0383-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here