Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

SUSE: 2018:2384-1 Important: Kernel Security Fixes and Updates

suse
Calendar Grey August 16, 2018
Dist Suse Esm H88
SUSE has published a crucial kernel security update that resolves various vulnerabilities and includes bug corrections for SUSE Linux.
An update that solves 6 vulnerabilities and has 10 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP1 LTSS kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-3620: Local attackers on baremetal systems could use speculative code patterns on hyperthreaded processors to read data present in the L1 Datacache used by other hyperthreads on the same CPU core, potentially leaking sensitive data. (bnc#1087081). - CVE-2018-3646: Local attackers in virtualized guest systems could use speculative code patterns on hyperthreaded processors to read data present in the L1 Datacache used by other hyperthreads on the same CPU core, potentially leaking sensitive data, even from other virtual machines or the host system. (bnc#1089343). - CVE-2018-14734: drivers/infiniband/core/ucma.c allowed

References

#1012382 #1064233 #1068032 #1076110 #1083635

#1086654 #1087081 #1089343 #1098016 #1099592

#1099924 #1100089 #1100416 #1100418 #1103119

#1104365

Cross- CVE-2018-13053 CVE-2018-13405 CVE-2018-13406

CVE-2018-14734 CVE-2018-3620 CVE-2018-3646

Affected Products:

SUSE Linux Enterprise Server for SAP 12-SP1

SUSE Linux Enterprise Server 12-SP1-LTSS

SUSE Linux Enterprise Module for Public Cloud 12

https://www.suse.com/security/cve/CVE-2018-13053.html

https://www.suse.com/security/cve/CVE-2018-13405.html

https://www.suse.com/security/cve/CVE-2018-13406.html

https://www.suse.com/security/cve/CVE-2018-14734.html

https://www.suse.com/security/cve/CVE-2018-3620.html

https://www.suse.com/security/cve/CVE-2018-3646.html

https://bugzilla.suse.com/1012382

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:2384-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here