The SUSE Linux Enterprise 15 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-15572: The spectre_v2_select_mitigation function in arch/x86/kernel/cpu/bugs.c did not always fill RSB upon a context switch, which made it easier for attackers to conduct userspace-userspace spectreRSB attacks (bnc#1102517 bnc#1105296). - CVE-2018-10902: It was found that the raw midi kernel driver did not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. A malicious local attacker could possibly use this for privilege escalation (bnc#1105322).
#1046305 #1046306 #1046307 #1051510 #1065600
#1081917 #1083647 #1086288 #1086315 #1086317
#1086327 #1086331 #1086906 #1087092 #1090888
#1097104 #1097577 #1097583 #1097584 #1097585
#1097586 #1097587 #1097588 #1097808 #1100132
#1101480 #1101669 #1101822 #1102517 #1102715
#1103269 #1103277 #1103363 #1103445 #1103886
#1104353 #1104365 #1104427 #1104482 #1104494
#1104495 #1104683 #1104708 #1104777 #1104890
#1104897 #1105292 #1105296 #1105322 #1105355
#1105378 #1105396 #1105467 #1105731 #802154
#971975
Cross- CVE-2018-10853 CVE-2018-10902 CVE-2018-15572
CVE-2018-9363
Affected Products:
SUSE Linux Enterprise Module for Live Patching 15
https://www.suse.com/security/cve/CVE-2018-10853.html
https://www.suse.com/security/cve/...
Read the Full Advisory