Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

SUSE: 2018:2051-1 Important: Kernel Update Fixes Four Issues

suse
Calendar Grey July 24, 2018
Dist Suse Esm H88
Major SUSE release rectifies several flaws in the Linux core, featuring 44 essential patches.
An update that solves four vulnerabilities and has 44 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP3 kernel was updated to 4.4.140 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-13053: The alarm_timer_nsleep function had an integer overflow via a large relative timeout because ktime_add_safe was not used (bnc#1099924) - CVE-2018-9385: Prevent overread of the "driver_override" buffer (bsc#1100491) - CVE-2018-13405: The inode_init_owner function allowed local users to create files with an unintended group ownership allowing attackers to escalate privileges by making a plain file executable and SGID (bnc#1100416) - CVE-2018-13406: An integer overflow in the uvesafb_setcmap function could have result in local attackers being able to crash the kernel or potentially elevate privileges because kmalloc_array is not used

References

#1012382 #1064232 #1075876 #1076110 #1085185

#1085657 #1089525 #1090435 #1090888 #1091171

#1092207 #1094244 #1094248 #1094643 #1095453

#1096790 #1097034 #1097140 #1097492 #1097501

#1097551 #1097808 #1097931 #1097961 #1098016

#1098236 #1098425 #1098435 #1098527 #1098599

#1099042 #1099183 #1099279 #1099713 #1099732

#1099792 #1099810 #1099918 #1099924 #1099966

#1099993 #1100089 #1100340 #1100416 #1100418

#1100491 #1100843 #1101296

Cross- CVE-2018-13053 CVE-2018-13405 CVE-2018-13406

CVE-2018-9385

Affected Products:

SUSE Linux Enterprise Workstation Extension 12-SP3

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Live Patching 12-SP3

...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:2051-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here