The SUSE Linux Enterprise 12 SP3 RT kernel was updated to 4.4.139 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-13053: The alarm_timer_nsleep function had an integer overflow via a large relative timeout because ktime_add_safe was not used (bnc#1099924) - CVE-2018-9385: Prevent overread of the "driver_override" buffer (bsc#1100491) - CVE-2018-13405: The inode_init_owner function allowed local users to create files with an unintended group ownership allowing attackers to escalate privileges by making a plain file executable and SGID (bnc#1100416) - CVE-2018-13406: An integer overflow in the uvesafb_setcmap function could have result in local attackers being able to crash the kernel or potentially elevate privileges because kmalloc_array is not used
#1012382 #1068032 #1074562 #1074578 #1074701
#1075006 #1075419 #1075748 #1075876 #1080039
#1085185 #1085657 #1087084 #1087939 #1089525
#1090435 #1090888 #1091171 #1092207 #1094244
#1094248 #1094643 #1095453 #1096790 #1097034
#1097140 #1097492 #1097501 #1097551 #1097808
#1097931 #1097961 #1098016 #1098236 #1098425
#1098435 #1098527 #1099042 #1099183 #1099279
#1099713 #1099732 #1099810 #1099918 #1099924
#1099966 #1099993 #1100089 #1100340 #1100416
#1100418 #1100491
Cross- CVE-2017-5753 CVE-2018-13053 CVE-2018-13405
CVE-2018-13406 CVE-2018-9385
Affected Products:
SUSE Linux Enterprise Real Time Extension 12-SP3
https://www.suse.com/security/cve/CVE-2017-5753.html
https://www.suse.com/security/cve/CVE-2018-13053.html
Get the latest Linux and open source security news straight to your inbox.