Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE: 2018:2332-1 Important: Kernel Local Attack Mitigations

suse
Calendar Grey August 15, 2018
Scroller Suse
SUSE Security Patch for the Linux Kernel addresses 12 vulnerabilities and enhances overall system protection. More information and updates can be found.
An update that solves 13 vulnerabilities and has four fixes is now available

Summary

The SUSE Linux Enterprise 11 SP4 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-3620: Local attackers on baremetal systems could use speculative code patterns on hyperthreaded processors to read data present in the L1 Datacache used by other hyperthreads on the same CPU core, potentially leaking sensitive data. (bnc#1087081). - CVE-2018-3646: Local attackers in virtualized guest systems could use speculative code patterns on hyperthreaded processors to read data present in the L1 Datacache used by other hyperthreads on the same CPU core, potentially leaking sensitive data, even from other virtual machines or the host system. (bnc#1089343). - CVE-2018-1000204: A malformed SG_IO ioctl issued for a SCSI device could

References

#1082962 #1083900 #1085107 #1087081 #1089343

#1092904 #1094353 #1096480 #1096728 #1097234

#1098016 #1099924 #1099942 #1100418 #1104475

#1104684 #909361

Cross- CVE-2016-8405 CVE-2017-13305 CVE-2018-1000204

CVE-2018-1068 CVE-2018-1130 CVE-2018-12233

CVE-2018-13053 CVE-2018-13406 CVE-2018-3620

CVE-2018-3646 CVE-2018-5803 CVE-2018-5814

CVE-2018-7492

Affected Products:

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Server 11-EXTRA

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2016-8405.html

https://www.suse.com/security/cve/CVE-2017-13305.html

https://www.suse.com/security/cve/CVE-2018-1000204.html

https://www.suse.com/security/cve/CVE-2018-1068.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:2332-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.