Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE: 2018:1772-1 Important: Linux Kernel Security Updates

suse
Calendar Grey June 21, 2018
Scroller Suse
Canonical Security Announcement for Ubuntu Kernel resolves critical vulnerabilities, tackling 5 issues and delivering 42 enhancements.
An update that solves 6 vulnerabilities and has 47 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP3 kernel was updated to 4.4.136 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-5848: In the function wmi_set_ie(), the length validation code did not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument could have caused a buffer overflow (bnc#1097356). - CVE-2017-18249: The add_free_nid function did not properly track an allocated nid, which allowed local users to cause a denial of service (race condition) or possibly have unspecified other impact via concurrent threads (bnc#1087036). - CVE-2018-3665: Prevent disclosure of FPU registers (including XMM and AVX registers) between processes. These registers might contain encryption keys when doing SSE accelerated AES enc/decryption

References

#1012382 #1024718 #1031717 #1035432 #1041740

#1045330 #1056415 #1066223 #1068032 #1068054

#1068951 #1070404 #1073311 #1075428 #1076049

#1078583 #1079152 #1080542 #1080656 #1081500

#1081514 #1082153 #1082504 #1082979 #1085185

#1085308 #1086400 #1086716 #1087036 #1087086

#1088871 #1090435 #1090534 #1090734 #1090955

#1091594 #1094532 #1095042 #1095147 #1096037

#1096140 #1096214 #1096242 #1096281 #1096751

#1096982 #1097234 #1097356 #1098009 #1098012

#971975 #973378 #978907

Cross- CVE-2017-17741 CVE-2017-18241 CVE-2017-18249

CVE-2018-12233 CVE-2018-3665 CVE-2018-5848

Affected Products:

SUSE Linux Enterprise Workstation Extension 12-SP3

SUSE Linux Enterprise Software Development Kit 12-SP3

...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:1772-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.