Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

SUSE: 2018:1220-1 Important: Linux Kernel Privilege Escalation Fix

suse
Calendar Grey May 11, 2018
Dist Suse Esm H88
Security update fixes multiple vulnerabilities in the Linux Kernel with essential actions to ensure system protection.
An update that solves 11 vulnerabilities and has 7 fixes is now available.

Summary

The SUSE Linux Enterprise 12 SP1 LTSS kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-1087: And an unprivileged KVM guest user could use this flaw to potentially escalate their privileges inside a guest. (bsc#1087088) - CVE-2018-8897: An unprivileged system user could use incorrect set up interrupt stacks to crash the Linux kernel resulting in DoS issue. (bsc#1087088) - CVE-2018-8781: The udl_fb_mmap function in drivers/gpu/drm/udl/udl_fb.c had an integer-overflow vulnerability allowing local users with access to the udldrmfb driver to obtain full read and write permissions on kernel physical pages, resulting in a code execution in kernel space (bnc#1090643). - CVE-2018-10124: The kill_something_info function in kernel/signal.c

References

#1076537 #1082299 #1083125 #1083242 #1083275

#1084536 #1085279 #1085331 #1086162 #1086194

#1087088 #1087260 #1088147 #1088260 #1088261

#1089608 #1089752 #1090643

Cross- CVE-2017-0861 CVE-2017-11089 CVE-2017-13220

CVE-2017-18203 CVE-2018-10087 CVE-2018-10124

CVE-2018-1087 CVE-2018-7757 CVE-2018-8781

CVE-2018-8822 CVE-2018-8897

Affected Products:

SUSE OpenStack Cloud 6

SUSE Linux Enterprise Server for SAP 12-SP1

SUSE Linux Enterprise Server 12-SP1-LTSS

SUSE Linux Enterprise Module for Public Cloud 12

https://www.suse.com/security/cve/CVE-2017-0861.html

https://www.suse.com/security/cve/CVE-2017-11089.html

https://www.suse.com/security/cve/CVE-2017-13220.html

https://www.suse.com/security/cve/CVE-2017-18203.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:1220-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here