Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

SUSE: 2018:2223-1 Important: Linux Kernel Security Advisory

suse
Calendar Grey August 7, 2018
Dist Suse Esm H88
Crucial SUSE Security Patch for the Linux Kernel tackles vulnerabilities and introduces corrections for improved reliability.
An update that solves two vulnerabilities and has 75 fixes is now available

Summary

The SUSE Linux Enterprise 15 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: CVE-2018-5390 aka SegmentSmack: A remote attacker even with relatively low bandwidth could have caused lots of CPU usage by triggering the worst case scenario during IP and/or TCP fragment reassembly (bsc#1102340) CVE-2017-18344: The timer_create syscall implementation didn't properly validate input, which could have lead to out-of-bounds access. This allowed userspace applications to read arbitrary kernel memory in some setups. (bsc#1102851) The following non-security bugs were fixed: - acpi, apei, einj: Subtract any matching Register Region from Trigger resources (bsc#1051510). - acpi, nfit: Fix scrub idle detection (bsc#1094119).

References

#1012382 #1037697 #1046299 #1046300 #1046302

#1046303 #1046305 #1046306 #1046307 #1046533

#1046543 #1050242 #1050536 #1050538 #1050540

#1051510 #1054245 #1056651 #1056787 #1058169

#1058659 #1060463 #1068032 #1075087 #1075360

#1077338 #1077761 #1077989 #1085042 #1085536

#1085539 #1086301 #1086313 #1086314 #1086324

#1086457 #1087092 #1087202 #1087217 #1087233

#1090098 #1090888 #1091041 #1091171 #1093148

#1093666 #1094119 #1096330 #1097583 #1097584

#1097585 #1097586 #1097587 #1097588 #1098633

#1099193 #1100132 #1100884 #1101143 #1101337

#1101352 #1101564 #1101669 #1101674 #1101789

#1101813 #1101816 #1102088 #1102097 #1102147

#1102340 #1102512 #1102851 #1103216 #1103220

#1103230 #110...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:2223-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here