Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

SUSE: 2018:1816-1 Important: Linux Kernel Denial of Service Fixes

suse
Calendar Grey June 26, 2018
Dist Suse Esm H88
SUSE launched a critical kernel upgrade targeting 17 security flaws and implementing various enhancements for improved protection.
An update that solves 17 vulnerabilities and has 109 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP3 RT kernel was updated to 4.4.138 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-12233: A memory corruption bug in JFS could have been triggered by calling setxattr twice with two different extended attribute names on the same file. This vulnerability could be triggered by an unprivileged user with the ability to create files and execute programs (bsc#1097234) - CVE-2018-3665: Prevent disclosure of FPU registers (including XMM and AVX registers) between processes. These registers might contain encryption keys when doing SSE accelerated AES enc/decryption (bsc#1087086) - CVE-2018-5848: In the function wmi_set_ie(), the length validation code did not handle unsigned integer overflow properly. As a result, a large

References

#1009062 #1012382 #1019695 #1019699 #1022604

#1022607 #1022743 #1024718 #1031717 #1035432

#1036215 #1041740 #1043598 #1044596 #1045330

#1056415 #1056427 #1060799 #1066223 #1068032

#1068054 #1068951 #1070404 #1073059 #1073311

#1075087 #1075428 #1076049 #1076263 #1076805

#1078583 #1079152 #1080157 #1080542 #1080656

#1081500 #1081514 #1081599 #1082153 #1082299

#1082485 #1082504 #1082962 #1082979 #1083635

#1083650 #1083900 #1084721 #1085185 #1085308

#1086400 #1086716 #1087007 #1087012 #1087036

#1087082 #1087086 #1087095 #1088810 #1088871

#1089023 #1089115 #1089393 #1089895 #1090225

#1090435 #1090534 #1090643 #1090658 #1090663

#1090708 #1090718 #1090734 #1090953 #1090955

#1091041 #109...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:1816-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here