Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

SUSE: 2018:1366-1 Important: Linux Kernel Security Flaws Addressed

suse
Calendar Grey May 23, 2018
Scroller Suse
SUSE's recent security update fixes critical vulnerabilities in the Linux kernel. Patch your systems promptly and responsibly.
An update that solves 9 vulnerabilities and has 71 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP3 kernel was updated to 4.4.131 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-3639: Information leaks using "Memory Disambiguation" feature in modern CPUs were mitigated, aka "Spectre Variant 4" (bnc#1087082). A new boot commandline option was introduced, "spec_store_bypass_disable", which can have following values: - auto: Kernel detects whether your CPU model contains an implementation of Speculative Store Bypass and picks the most appropriate mitigation. - on: disable Speculative Store Bypass - off: enable Speculative Store Bypass - prctl: Control Speculative Store Bypass per thread via prctl. Speculative Store Bypass is enabled for a process by default. The state of the control is inherited on fork.

References

#1005778 #1005780 #1005781 #1009062 #1012382

#1015336 #1015337 #1015340 #1015342 #1015343

#1022604 #1022743 #1024296 #1031492 #1036215

#1043598 #1044596 #1056415 #1056427 #1060799

#1068032 #1075087 #1075091 #1075994 #1076263

#1080157 #1082153 #1082299 #1082485 #1082962

#1083125 #1083635 #1083650 #1083900 #1084721

#1085058 #1085185 #1085511 #1085958 #1087082

#1088242 #1088865 #1089023 #1089115 #1089198

#1089393 #1089608 #1089644 #1089752 #1089895

#1089925 #1090225 #1090643 #1090658 #1090663

#1090708 #1090718 #1090734 #1090953 #1091041

#1091325 #1091728 #1091925 #1091960 #1092289

#1092497 #1092566 #1092904 #1093008 #1093144

#1093215 #1094019 #802154 #966170 #966172

#966186 #966191 ...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:1366-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.