Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

SUSE: 2018:1171-1 Important: Linux Kernel DoS And Privilege Escalation

suse
Calendar Grey May 9, 2018
Dist Suse Esm H88
The SUSE Linux kernel received a critical update aimed at rectifying vulnerabilities that could lead to Denial of Service and elevation of privileges.
An update that solves three vulnerabilities and has four fixes is now available.

Summary

The SUSE Linux Enterprise 11 SP4 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-1087: And an unprivileged KVM guest user could use this flaw to potentially escalate their privileges inside a guest. (bsc#1087088) - CVE-2018-8897: An unprivileged system user could use incorrect set up interrupt stacks to crash the Linux kernel resulting in DoS issue. (bsc#1087088) - CVE-2018-10124: The kill_something_info function in kernel/signal.c in the Linux kernel before 4.13, when an unspecified architecture and compiler is used, might allow local users to cause a denial of service via an INT_MIN argument (bnc#1089752). The following non-security bugs were fixed: - kvm/x86: fix icebp instruction handling (bsc#1087088).

References

#1032084 #1050431 #1065726 #1087088 #1089665

#1089668 #1089752

Cross- CVE-2018-10124 CVE-2018-1087 CVE-2018-8897

Affected Products:

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Server 11-EXTRA

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2018-10124.html

https://www.suse.com/security/cve/CVE-2018-1087.html

https://www.suse.com/security/cve/CVE-2018-8897.html

https://bugzilla.suse.com/1032084

https://bugzilla.suse.com/1050431

https://bugzilla.suse.com/1065726

https://bugzilla.suse.com/1087088

https://bugzilla.suse.com/1089665

https://bugzilla.suse.com/1089668

https://bugzilla.suse.com/1089752

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:1171-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here