The SUSE Linux Enterprise 12 SP2 kernel was updated to 4.4.114 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2017-5715: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis (bnc#1068032). The previous fix using CPU Microcode has been complemented by building the Linux Kernel with return trampolines aka "retpolines". - CVE-2017-15129: A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel The function get_net_ns_by_id() in net/core/net_namespace.c did not check for the net::count value after it has found a peer network in netns_ids idr,
#1012382 #1012917 #1019784 #1022476 #1031717
#1038078 #1038085 #1043652 #1048585 #1052360
#1060279 #1066223 #1066842 #1068032 #1068038
#1068569 #1068984 #1069160 #1070799 #1072163
#1072484 #1072589 #1073229 #1073928 #1074134
#1074392 #1074488 #1074621 #1074709 #1074839
#1074847 #1075066 #1075078 #1075087 #1075091
#1075428 #1075617 #1075621 #1075627 #1075994
#1076017 #1076110 #1076806 #1076809 #1076872
#1076899 #1077068 #1077560 #1077592 #1078526
#1078681 #963844 #988524
Cross- CVE-2017-15129 CVE-2017-17712 CVE-2017-17862
CVE-2017-17864 CVE-2017-18017 CVE-2017-5715
CVE-2018-1000004 CVE-2018-5332 CVE-2018-5333
Affected Products:
SUSE Linux Enterprise Workstation Extension 12-SP2
SUSE L...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.