Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

SUSE: 2018:0482-1 Critical: Linux Kernel Update Addressing DoS

suse
Calendar Grey February 20, 2018
Dist Suse Esm H88
Stay secure with SUSE Linux by applying necessary kernel patches for identified vulnerabilities. Follow outlined instructions for a safer system upgrade
An update that solves 9 vulnerabilities and has 44 fixes is now available.

Summary

The SUSE Linux Enterprise 12 SP2 Realtime kernel was updated to 4.4.114 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2017-5715: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis (bnc#1068032). The previous fix using CPU Microcode has been complemented by building the Linux Kernel with return trampolines aka "retpolines". - CVE-2018-5333: In the Linux kernel the rds_cmsg_atomic function in net/rds/rdma.c mishandled cases where page pinning fails or an invalid address is supplied, leading to an rds_atomic_free_op NULL pointer dereference (bnc#1075617).

References

#1012382 #1019784 #1031717 #1036737 #1038078

#1038085 #1043652 #1048585 #1052360 #1060279

#1066223 #1066842 #1068032 #1068038 #1068569

#1068984 #1069160 #1070799 #1072163 #1072484

#1072589 #1073229 #1073230 #1073928 #1074134

#1074488 #1074621 #1074709 #1074839 #1074847

#1075066 #1075078 #1075087 #1075091 #1075428

#1075617 #1075621 #1075627 #1075994 #1076017

#1076110 #1076806 #1076809 #1076872 #1076899

#1077068 #1077560 #1077592 #1077871 #1078526

#1078681 #963844 #988524

Cross- CVE-2017-15129 CVE-2017-17712 CVE-2017-17862

CVE-2017-17864 CVE-2017-18017 CVE-2017-5715

CVE-2018-1000004 CVE-2018-5332 CVE-2018-5333

Affected Products:

SUSE Linux Enterprise Real Time Extension 12-SP2

https://www.suse.com/secu...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:0482-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here