Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

SUSE Linux Enterprise 12-SP3: 2018:2150-1 Critical: Kernel Security Fix

suse
Calendar Grey July 31, 2018
Dist Suse Esm H88
A critical security patch for CentOS addresses various kernel issues and potential vulnerabilities comprehensively.
An update that solves 5 vulnerabilities and has 47 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP3 RT kernel was updated to 4.4.139 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-13053: The alarm_timer_nsleep function had an integer overflow via a large relative timeout because ktime_add_safe was not used (bnc#1099924) - CVE-2018-9385: Prevent overread of the "driver_override" buffer (bsc#1100491) - CVE-2018-13405: The inode_init_owner function allowed local users to create files with an unintended group ownership allowing attackers to escalate privileges by making a plain file executable and SGID (bnc#1100416) - CVE-2018-13406: An integer overflow in the uvesafb_setcmap function could have result in local attackers being able to crash the kernel or potentially elevate privileges because kmalloc_array is not used

References

#1012382 #1068032 #1074562 #1074578 #1074701

#1075006 #1075419 #1075748 #1075876 #1080039

#1085185 #1085657 #1087084 #1087939 #1089525

#1090435 #1090888 #1091171 #1092207 #1094244

#1094248 #1094643 #1095453 #1096790 #1097034

#1097140 #1097492 #1097501 #1097551 #1097808

#1097931 #1097961 #1098016 #1098236 #1098425

#1098435 #1098527 #1099042 #1099183 #1099279

#1099713 #1099732 #1099810 #1099918 #1099924

#1099966 #1099993 #1100089 #1100340 #1100416

#1100418 #1100491

Cross- CVE-2017-5753 CVE-2018-13053 CVE-2018-13405

CVE-2018-13406 CVE-2018-9385

Affected Products:

SUSE Linux Enterprise Real Time Extension 12-SP3

https://www.suse.com/security/cve/CVE-2017-5753.html

https://www.suse.com/security/cve/CVE-2018-13053.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:2150-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here