The SUSE Linux Enterprise 12 SP3 kernel was updated to 4.4.156 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-16597: Incorrect access checking in overlayfs mounts could have been used by local attackers to modify or truncate files in the underlying filesystem (bnc#1106512). - CVE-2018-14613: Prevent invalid pointer dereference in io_ctl_map_page() when mounting and operating a crafted btrfs image, caused by a lack of block group item validation in check_leaf_item (bsc#1102896) - CVE-2018-14617: Prevent NULL pointer dereference and panic in hfsplus_lookup() when opening a file (that is purportedly a hard link) in an hfs+ filesystem that has malformed catalog data, and is mounted read-only without a metadata directory (bsc#1102870)
#1012382 #1044189 #1063026 #1066223 #1082863
#1082979 #1084427 #1084536 #1087209 #1088087
#1090535 #1091815 #1094244 #1094555 #1094562
#1095344 #1095753 #1096547 #1099810 #1102495
#1102715 #1102870 #1102875 #1102877 #1102879
#1102882 #1102896 #1103156 #1103269 #1106095
#1106434 #1106512 #1106594 #1106934 #1107924
#1108096 #1108170 #1108240 #1108399 #1108803
#1108823 #1109333 #1109336 #1109337 #1109441
#1110297 #1110337
Cross- CVE-2018-14613 CVE-2018-14617 CVE-2018-16276
CVE-2018-16597 CVE-2018-17182 CVE-2018-7480
CVE-2018-7757
Affected Products:
SUSE Linux Enterprise Live Patching 12-SP3
https://www.suse.com/security/cve/CVE-2018-14613.html
https://www.suse.com/security/cve/CVE-2018-14617.html
https://www.suse.com/security/cve/CVE-201...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.