Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The SUSE Linux Enterprise 11 SP4 kernel was updated to receive various security and bugfixes. This update main focus is a regression fix in SystemV IPC handling. (bsc#1093600) The following non-security bugs were fixed: - Drop cBPF SSBD as classic BPF does not really have a proper concept of pointers, and without eBPF maps the out-of-bounds access in speculative execution branch can't be mounted. Moreoever, seccomp BPF uses only such a subset of BPF that can only do absolute indexing, and therefore seccomp data buffer boundarier can't be crossed. Information condensed from Alexei and Kees. - ibrs used instead of retpoline on Haswell processor with spectre_v2=retpoline (bsc#1092497) - ib/mlx4: Convert slave port before building address-handle (bug#919382 FATE#317529).
#1013018 #1070404 #1072689 #1087082 #1088343
#1089386 #1090607 #1091659 #1092497 #1093600
#1093710 #919382
Affected Products:
SUSE Linux Enterprise Software Development Kit 11-SP4
SUSE Linux Enterprise Server 11-SP4
SUSE Linux Enterprise Server 11-EXTRA
SUSE Linux Enterprise Debuginfo 11-SP4
https://bugzilla.suse.com/1013018
https://bugzilla.suse.com/1070404
https://bugzilla.suse.com/1072689
https://bugzilla.suse.com/1087082
https://bugzilla.suse.com/1088343
https://bugzilla.suse.com/1089386
https://bugzilla.suse.com/1090607
https://bugzilla.suse.com/1091659
https://bugzilla.suse.com/1092497
https://bugzilla.suse.com/1093600
https://bugzilla.suse.com/1093710
https://bugzilla.suse.com/919382
Get the latest Linux and open source security news straight to your inbox.