The SUSE Linux Enterprise 12 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-14634: Prevent integer overflow in create_elf_tables that allowed a local attacker to exploit this vulnerability via a SUID-root binary and obtain full root privileges (bsc#1108912) - CVE-2018-14617: Prevent NULL pointer dereference and panic in hfsplus_lookup() when opening a file (that is purportedly a hard link) in an hfs+ filesystem that has malformed catalog data, and is mounted read-only without a metadata directory (bsc#1102870) - CVE-2018-16276: Incorrect bounds checking in the yurex USB driver in yurex_read allowed local attackers to use user access read/writes to crash the kernel or potentially escalate privileges (bsc#1106095)
#1012382 #1062604 #1064232 #1065999 #1092903
#1093215 #1096547 #1097104 #1099811 #1099813
#1099844 #1099845 #1099846 #1099849 #1099863
#1099864 #1099922 #1100001 #1100089 #1102870
#1103445 #1104319 #1104495 #1104906 #1105322
#1105412 #1106095 #1106369 #1106509 #1106511
#1107689 #1108399 #1108912
Cross- CVE-2018-10853 CVE-2018-10876 CVE-2018-10877
CVE-2018-10878 CVE-2018-10879 CVE-2018-10880
CVE-2018-10881 CVE-2018-10882 CVE-2018-10883
CVE-2018-10902 CVE-2018-10940 CVE-2018-12896
CVE-2018-13093 CVE-2018-14617 CVE-2018-14634
CVE-2018-16276 CVE-2018-16658 CVE-2018-17182
CVE-2018-6554 CVE-2018-6555
Affected Products:
SUSE Linux Enterprise Server 12-LTSS
SUSE Linux Enterprise Module for Public Cloud 12
https:...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.