Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 438
Alerts This Week
Warning Icon 1 438

SUSE 11-SP3 Important: 2018:1308-1 kvm Security Update Spectre Fixes

suse
Calendar Grey May 16, 2018
Scroller Suse
Crucial SUSE security patch for kvm resolves various concerns, delivering essential updates for corporate reliability.
An update that solves four vulnerabilities and has one errata is now available

Summary

This update for kvm fixes the following issues: This update has the next round of Spectre v2 related patches, which now integrates with corresponding changes in libvirt. A January 2018 release of qemu initially addressed the Spectre v2 vulnerability for KVM guests by exposing the spec-ctrl feature for all x86 vcpu types, which was the quick and dirty approach, but not the proper solution. We remove that initial patch and now rely on patches from upstream. This update defines spec_ctrl and ibpb cpu feature flags as well as new cpu models which are clones of existing models with either -IBRS or -IBPB added to the end of the model name. These new vcpu models explicitly include the new feature(s), whereas the feature flags can be added to the cpu parameter as with other

References

#1068032 #1076114 #1076179 #1082276 #1083291

Cross- CVE-2017-18030 CVE-2017-5715 CVE-2018-5683

CVE-2018-7550

Affected Products:

SUSE Linux Enterprise Server 11-SP3-LTSS

SUSE Linux Enterprise Point of Sale 11-SP3

https://www.suse.com/security/cve/CVE-2017-18030.html

https://www.suse.com/security/cve/CVE-2017-5715.html

https://www.suse.com/security/cve/CVE-2018-5683.html

https://www.suse.com/security/cve/CVE-2018-7550.html

https://bugzilla.suse.com/1068032

https://bugzilla.suse.com/1076114

https://bugzilla.suse.com/1076179

https://bugzilla.suse.com/1082276

https://bugzilla.suse.com/1083291

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:1308-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.