Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The SUSE Linux Enterprise 12 GA LTSS kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-3665: Prevent disclosure of FPU registers (including XMM and AVX registers) between processes. These registers might contain encryption keys when doing SSE accelerated AES enc/decryption (bsc#1087086) - CVE-2018-5848: In the function wmi_set_ie(), the length validation code did not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument could have caused a buffer overflow (bnc#1097356) - CVE-2018-1000204: Prevent infoleak caused by incorrect handling of the SG_IO ioctl (bsc#1096728) - CVE-2017-13305: Prevent information disclosure vulnerability in encrypted-keys (bsc#1094353)
#1046610 #1079152 #1082962 #1083900 #1087007
#1087012 #1087082 #1087086 #1087095 #1092552
#1092813 #1092904 #1094033 #1094353 #1094823
#1096140 #1096242 #1096281 #1096480 #1096728
#1097356
Cross- CVE-2017-13305 CVE-2018-1000204 CVE-2018-1092
CVE-2018-1093 CVE-2018-1094 CVE-2018-1130
CVE-2018-3665 CVE-2018-5803 CVE-2018-5848
CVE-2018-7492
Affected Products:
SUSE Linux Enterprise Server 12-LTSS
SUSE Linux Enterprise Module for Public Cloud 12
https://www.suse.com/security/cve/CVE-2017-13305.html
https://www.suse.com/security/cve/CVE-2018-1000204.html
https://www.suse.com/security/cve/CVE-2018-1092.html
https://www.suse.com/security/cve/CVE-2018-1093.html
https://https://www.suse.com/security/cve/CVE-2018-1094.html
Get the latest Linux and open source security news straight to your inbox.