Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

SUSE 12 SP3: 2018:2858-1 critical: Linux Kernel Denial Of Service

suse
Calendar Grey September 25, 2018
Dist Suse Esm H88
Vital patch release for SUSE Linux Kernel tackles severe vulnerabilities, encompassing service disruption and data integrity flaws.
An update that solves 22 vulnerabilities and has 96 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP3 azure kernel was updated to 4.4.155 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-13093: Prevent NULL pointer dereference and panic in lookup_slow() on a NULL inode->i_ops pointer when doing pathwalks on a corrupted xfs image. This occured because of a lack of proper validation that cached inodes are free during allocation (bnc#1100001) - CVE-2018-13095: Prevent denial of service (memory corruption and BUG) that could have occurred for a corrupted xfs image upon encountering an inode that is in extent format, but has more extents than fit in the inode fork (bnc#1099999) - CVE-2018-13094: Prevent OOPS that may have occured for a corrupted xfs image after xfs_da_shrink_inode() is called with a NULL bp (bnc#1100000)

References

#1012382 #1015342 #1015343 #1017967 #1019695

#1019699 #1020412 #1021121 #1022604 #1024361

#1024365 #1024376 #1027968 #1030552 #1033962

#1042286 #1048317 #1050431 #1053685 #1055014

#1056596 #1062604 #1063646 #1064232 #1065364

#1066223 #1068032 #1068075 #1069138 #1078921

#1080157 #1083663 #1085042 #1085536 #1085539

#1086457 #1087092 #1089066 #1090888 #1091171

#1091860 #1092903 #1096254 #1096748 #1097105

#1098253 #1098822 #1099597 #1099810 #1099811

#1099813 #1099832 #1099844 #1099845 #1099846

#1099849 #1099863 #1099864 #1099922 #1099999

#1100000 #1100001 #1100132 #1101822 #1101841

#1102346 #1102486 #1102517 #1102715 #1102797

#1103269 #1103445 #1104319 #1104485 #1104494

#1104495 #110...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:2858-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here