The SUSE Linux Enterprise 12 SP3 RT kernel was updated to 4.4.138 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-12233: A memory corruption bug in JFS could have been triggered by calling setxattr twice with two different extended attribute names on the same file. This vulnerability could be triggered by an unprivileged user with the ability to create files and execute programs (bsc#1097234) - CVE-2018-3665: Prevent disclosure of FPU registers (including XMM and AVX registers) between processes. These registers might contain encryption keys when doing SSE accelerated AES enc/decryption (bsc#1087086) - CVE-2018-5848: In the function wmi_set_ie(), the length validation code did not handle unsigned integer overflow properly. As a result, a large
#1009062 #1012382 #1019695 #1019699 #1022604
#1022607 #1022743 #1024718 #1031717 #1035432
#1036215 #1041740 #1043598 #1044596 #1045330
#1056415 #1056427 #1060799 #1066223 #1068032
#1068054 #1068951 #1070404 #1073059 #1073311
#1075087 #1075428 #1076049 #1076263 #1076805
#1078583 #1079152 #1080157 #1080542 #1080656
#1081500 #1081514 #1081599 #1082153 #1082299
#1082485 #1082504 #1082962 #1082979 #1083635
#1083650 #1083900 #1084721 #1085185 #1085308
#1086400 #1086716 #1087007 #1087012 #1087036
#1087082 #1087086 #1087095 #1088810 #1088871
#1089023 #1089115 #1089393 #1089895 #1090225
#1090435 #1090534 #1090643 #1090658 #1090663
#1090708 #1090718 #1090734 #1090953 #1090955
#1091041 #109...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.