Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The SUSE Linux Enterprise 12 SP1 LTSS kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-3665: Prevent disclosure of FPU registers (including XMM and AVX registers) between processes. These registers might contain encryption keys when doing SSE accelerated AES enc/decryption (bsc#1087086) - CVE-2018-5848: In the function wmi_set_ie(), the length validation code did not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument could have caused a buffer overflow (bnc#1097356) - CVE-2018-1000204: Prevent infoleak caused by incorrect handling of the SG_IO ioctl (bsc#1096728) - CVE-2017-13305: Prevent information disclosure vulnerability in encrypted-keys (bsc#1094353)
#1038553 #1046610 #1079152 #1082962 #1083382
#1083900 #1087007 #1087012 #1087082 #1087086
#1087095 #1092813 #1092904 #1094033 #1094353
#1094823 #1096140 #1096242 #1096281 #1096480
#1096728 #1097356
Cross- CVE-2017-13305 CVE-2018-1000204 CVE-2018-1092
CVE-2018-1093 CVE-2018-1094 CVE-2018-1130
CVE-2018-3665 CVE-2018-5803 CVE-2018-5848
CVE-2018-7492
Affected Products:
SUSE Linux Enterprise Server for SAP 12-SP1
SUSE Linux Enterprise Server 12-SP1-LTSS
SUSE Linux Enterprise Module for Public Cloud 12
https://www.suse.com/security/cve/CVE-2017-13305.html
https://www.suse.com/security/cve/CVE-2018-1000204.html
https://www.suse.com/security/cve/CVE-2018-1092.html
https://www.suse.com/security/cve/CVE-2018-1093.html
Get the latest Linux and open source security news straight to your inbox.