The SUSE Linux Enterprise 12 GA LTSS kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2017-5715: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis (bnc#1068032). The previous fix using CPU Microcode has been complemented by building the Linux Kernel with return trampolines aka "retpolines". - CVE-2017-18079: drivers/input/serio/i8042.c allowed attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact because the port->exists value can change after it is validated (bnc#1077922)
#1012382 #1047626 #1068032 #1070623 #1073311
#1073792 #1073874 #1075091 #1075908 #1075994
#1076017 #1076110 #1076154 #1076278 #1077355
#1077560 #1077922 #893777 #893949 #902893
#951638
Cross- CVE-2015-1142857 CVE-2017-13215 CVE-2017-17741
CVE-2017-17805 CVE-2017-17806 CVE-2017-18079
CVE-2017-5715 CVE-2018-1000004
Affected Products:
SUSE Linux Enterprise Server 12-LTSS
SUSE Linux Enterprise Module for Public Cloud 12
https://www.suse.com/security/cve/CVE-2015-1142857.html
https://www.suse.com/security/cve/CVE-2017-13215.html
https://www.suse.com/security/cve/CVE-2017-17741.html
https://www.suse.com/security/cve/CVE-2017-17805.html
https://www.suse.com/security/cve/CVE-2017-17806.html
https://www.suse.com/security/cve/CVE-2017-18079.html
Get the latest Linux and open source security news straight to your inbox.