The SUSE Linux Enterprise 11 SP4 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-3639: Information leaks using "Memory Disambiguation" feature in modern CPUs were mitigated, aka "Spectre Variant 4" (bnc#1087082). A new boot commandline option was introduced, "spec_store_bypass_disable", which can have following values: - auto: Kernel detects whether your CPU model contains an implementation of Speculative Store Bypass and picks the most appropriate mitigation. - on: disable Speculative Store Bypass - off: enable Speculative Store Bypass - prctl: Control Speculative Store Bypass per thread via prctl. Speculative Store Bypass is enabled for a process by default. The state of the control is inherited on fork.
#1046610 #1052943 #1068032 #1075087 #1075088
#1080157 #1084760 #1087082 #1087092 #1089895
#1090630 #1090888 #1091041 #1091671 #1091755
#1091815 #1092372 #1092497 #1094019
Cross- CVE-2017-5715 CVE-2017-5753 CVE-2018-1000199
CVE-2018-10675 CVE-2018-3639
Affected Products:
SUSE Linux Enterprise Software Development Kit 11-SP4
SUSE Linux Enterprise Server 11-SP4
SUSE Linux Enterprise Server 11-EXTRA
SUSE Linux Enterprise Debuginfo 11-SP4
https://www.suse.com/security/cve/CVE-2017-5715.html
https://www.suse.com/security/cve/CVE-2017-5753.html
https://www.suse.com/security/cve/CVE-2018-1000199.html
https://www.suse.com/security/cve/CVE-2018-10675.html
https://www.suse.com/security/cve/CVE-2018-3639.html
https://bugzilla.suse.com/1046610
Get the latest Linux and open source security news straight to your inbox.