The SUSE Linux Enterprise 12 SP2 LTSS kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-3620: Local attackers on baremetal systems could use speculative code patterns on hyperthreaded processors to read data present in the L1 Datacache used by other hyperthreads on the same CPU core, potentially leaking sensitive data. (bnc#1087081). - CVE-2018-3646: Local attackers in virtualized guest systems could use speculative code patterns on hyperthreaded processors to read data present in the L1 Datacache used by other hyperthreads on the same CPU core, potentially leaking sensitive data, even from other virtual machines or the host system. (bnc#1089343). - CVE-2018-5390 aka "SegmentSmack": The Linux Kernel can be forced to make
#1064232 #1076110 #1083635 #1085042 #1086652
#1087081 #1089343 #1090123 #1091171 #1094248
#1096130 #1096480 #1096978 #1097140 #1097551
#1098016 #1098425 #1098435 #1099924 #1100089
#1100416 #1100418 #1100491 #1101557 #1102340
#1102851 #1103097 #1103119 #1103580
Cross- CVE-2017-18344 CVE-2018-13053 CVE-2018-13405
CVE-2018-13406 CVE-2018-14734 CVE-2018-3620
CVE-2018-3646 CVE-2018-5390 CVE-2018-5391
CVE-2018-5814 CVE-2018-9385
Affected Products:
SUSE OpenStack Cloud 7
SUSE Linux Enterprise Server for SAP 12-SP2
SUSE Linux Enterprise Server 12-SP2-LTSS
SUSE Linux Enterprise High Availability 12-SP2
SUSE Enterprise Storage 4
OpenStack Cloud Magnum Orchestration 7
https://www.suse.com/security/cve/CVE-2017-18344...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.