Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

SUSE: 2018:2907-1 Important: Linux Kernel Update Addressing 8 Issues

suse
Calendar Grey September 27, 2018
Dist Suse Esm H88
SUSE Security Update for Linux Kernel fixes 8 significant vulnerabilities with vital references for system administrators.
An update that solves 8 vulnerabilities and has 11 fixes is now available

Summary

The SUSE Linux Enterprise 11 SP3 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-14634: Prevent integer overflow in create_elf_tables that allowed a local attacker to exploit this vulnerability via a SUID-root binary and obtain full root privileges (bsc#1108912). - CVE-2018-10940: The cdrom_ioctl_media_changed function allowed local attackers to use a incorrect bounds check in the CDROM driver CDROM_MEDIA_CHANGED ioctl to read out kernel memory (bsc#1092903) - CVE-2018-16658: Prevent information leak in cdrom_ioctl_drive_status that could have been used by local attackers to read kernel memory (bnc#1107689) - CVE-2018-6555: The irda_setsockopt function allowed local users to cause

References

#1057199 #1087081 #1092903 #1102517 #1103119

#1104367 #1104684 #1104818 #1105100 #1105296

#1105322 #1105323 #1105536 #1106369 #1106509

#1106511 #1107001 #1107689 #1108912

Cross- CVE-2018-10902 CVE-2018-10940 CVE-2018-14634

CVE-2018-14734 CVE-2018-15572 CVE-2018-16658

CVE-2018-6554 CVE-2018-6555

Affected Products:

SUSE Linux Enterprise Server 11-SP3-LTSS

SUSE Linux Enterprise Server 11-EXTRA

SUSE Linux Enterprise Point of Sale 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP3

https://www.suse.com/security/cve/CVE-2018-10902.html

https://www.suse.com/security/cve/CVE-2018-10940.html

https://www.suse.com/security/cve/CVE-2018-14634.html

https://www.suse.com/security/cve/CVE-2018-14734.html

https://www.suse.com/security/cve/CVE-2018-15572.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:2907-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here