Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

SUSE: 2018:2539-1 Important: Linux Kernel Security Issues Resolved

suse
Calendar Grey August 28, 2018
Dist Suse Esm H88
Critical SUSE security update addresses kernel bugs and vulnerabilities with significant enhancements.
An update that solves four vulnerabilities and has 52 fixes is now available

Summary

The SUSE Linux Enterprise 15 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-15572: The spectre_v2_select_mitigation function in arch/x86/kernel/cpu/bugs.c did not always fill RSB upon a context switch, which made it easier for attackers to conduct userspace-userspace spectreRSB attacks (bnc#1102517 bnc#1105296). - CVE-2018-10902: It was found that the raw midi kernel driver did not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. A malicious local attacker could possibly use this for privilege escalation (bnc#1105322).

References

#1046305 #1046306 #1046307 #1051510 #1065600

#1081917 #1083647 #1086288 #1086315 #1086317

#1086327 #1086331 #1086906 #1087092 #1090888

#1097104 #1097577 #1097583 #1097584 #1097585

#1097586 #1097587 #1097588 #1097808 #1100132

#1101480 #1101669 #1101822 #1102517 #1102715

#1103269 #1103277 #1103363 #1103445 #1103886

#1104353 #1104365 #1104427 #1104482 #1104494

#1104495 #1104683 #1104708 #1104777 #1104890

#1104897 #1105292 #1105296 #1105322 #1105355

#1105378 #1105396 #1105467 #1105731 #802154

#971975

Cross- CVE-2018-10853 CVE-2018-10902 CVE-2018-15572

CVE-2018-9363

Affected Products:

SUSE Linux Enterprise Workstation Extension 15

SUSE Linux Enterprise Module for Legacy Software 15

SUSE ...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:2539-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here