The SUSE Linux Enterprise 15 kernel-azure was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-5390 aka "SegmentSmack": A remote attacker even with relatively low bandwidth could have caused lots of CPU usage by triggering the worst case scenario during IP and/or TCP fragment reassembly (bsc#1102340) - CVE-2017-18344: The timer_create syscall implementation didn't properly validate input, which could have lead to out-of-bounds access. This allowed userspace applications to read arbitrary kernel memory in some setups. (bsc#1102851) - CVE-2018-13406: An integer overflow in the uvesafb_setcmap function could have result in local attackers being able to crash the kernel or potentially elevate privileges because kmalloc_array is not used (bnc#1100418)
#1012382 #1037697 #1046299 #1046300 #1046302
#1046303 #1046305 #1046306 #1046307 #1046533
#1046543 #1048129 #1050242 #1050529 #1050536
#1050538 #1050540 #1050549 #1051510 #1054245
#1056651 #1056787 #1058115 #1058169 #1058659
#1060463 #1066110 #1068032 #1075087 #1075360
#1075876 #1077338 #1077761 #1077989 #1078248
#1085042 #1085536 #1085539 #1086282 #1086283
#1086286 #1086301 #1086313 #1086314 #1086319
#1086323 #1086324 #1086457 #1086652 #1087092
#1087202 #1087217 #1087233 #1087978 #1088821
#1088866 #1090098 #1090888 #1091041 #1091171
#1091424 #1091860 #1092472 #1093035 #1093118
#1093148 #1093290 #1093666 #1094119 #1094244
#1094978 #1095155 #1095337 #1096330 #1096529
#1096790 #109...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.