Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The SUSE Linux Enterprise 12 SP3 kernel was updated to 4.4.136 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-5848: In the function wmi_set_ie(), the length validation code did not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument could have caused a buffer overflow (bnc#1097356). - CVE-2017-18249: The add_free_nid function did not properly track an allocated nid, which allowed local users to cause a denial of service (race condition) or possibly have unspecified other impact via concurrent threads (bnc#1087036). - CVE-2018-3665: Prevent disclosure of FPU registers (including XMM and AVX registers) between processes. These registers might contain encryption keys when doing SSE accelerated AES enc/decryption
#1012382 #1024718 #1031717 #1035432 #1041740
#1045330 #1056415 #1066223 #1068032 #1068054
#1068951 #1070404 #1073311 #1075428 #1076049
#1078583 #1079152 #1080542 #1080656 #1081500
#1081514 #1082153 #1082504 #1082979 #1085185
#1085308 #1086400 #1086716 #1087036 #1087086
#1088871 #1090435 #1090534 #1090734 #1090955
#1091594 #1094532 #1095042 #1095147 #1096037
#1096140 #1096214 #1096242 #1096281 #1096751
#1096982 #1097234 #1097356 #1098009 #1098012
#971975 #973378 #978907
Cross- CVE-2017-17741 CVE-2017-18241 CVE-2017-18249
CVE-2018-12233 CVE-2018-3665 CVE-2018-5848
Affected Products:
SUSE Linux Enterprise Workstation Extension 12-SP3
SUSE Linux Enterprise Software Development Kit 12-SP3
...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.