The SUSE Linux Enterprise 12 SP3 kernel was updated to 4.4.140 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-13053: The alarm_timer_nsleep function had an integer overflow via a large relative timeout because ktime_add_safe was not used (bnc#1099924) - CVE-2018-9385: Prevent overread of the "driver_override" buffer (bsc#1100491) - CVE-2018-13405: The inode_init_owner function allowed local users to create files with an unintended group ownership allowing attackers to escalate privileges by making a plain file executable and SGID (bnc#1100416) - CVE-2018-13406: An integer overflow in the uvesafb_setcmap function could have result in local attackers being able to crash the kernel or potentially elevate privileges because kmalloc_array is not used
#1012382 #1064232 #1075876 #1076110 #1085185
#1085657 #1089525 #1090435 #1090888 #1091171
#1092207 #1094244 #1094248 #1094643 #1095453
#1096790 #1097034 #1097140 #1097492 #1097501
#1097551 #1097808 #1097931 #1097961 #1098016
#1098236 #1098425 #1098435 #1098527 #1098599
#1099042 #1099183 #1099279 #1099713 #1099732
#1099792 #1099810 #1099918 #1099924 #1099966
#1099993 #1100089 #1100340 #1100416 #1100418
#1100491 #1100843 #1101296
Cross- CVE-2018-13053 CVE-2018-13405 CVE-2018-13406
CVE-2018-9385
Affected Products:
SUSE Linux Enterprise Workstation Extension 12-SP3
SUSE Linux Enterprise Software Development Kit 12-SP3
SUSE Linux Enterprise Server 12-SP3
SUSE Linux Enterprise Live Patching 12-SP3
...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.