The SUSE Linux Enterprise 12 SP2 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-19985: The function hso_probe read if_num from the USB device (as an u8) and used it without a length check to index an array, resulting in an OOB memory read in hso_probe or hso_get_config_data that could be used by local attackers (bnc#1120743). - CVE-2018-16884: NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_process() use wrong back-channel IDs and cause a use-after-free vulnerability. Thus a malicious container user can cause a host kernel memory corruption and a system panic. Due to the nature of the flaw, privilege escalation cannot be fully ruled out (bnc#1119946).
#1012382 #1023175 #1042286 #1065600 #1065726
#1070805 #1084721 #1086095 #1086535 #1091158
#1091171 #1091197 #1094825 #1095344 #1098996
#1099523 #1099597 #1100105 #1101555 #1103624
#1104731 #1105025 #1105931 #1106293 #1107256
#1107299 #1107385 #1107866 #1108145 #1108498
#1109330 #1110286 #1110837 #1111062 #1113192
#1113751 #1113769 #1114190 #1114648 #1114763
#1115433 #1115440 #1116027 #1116183 #1116345
#1117186 #1117187 #1118152 #1118319 #1119714
#1119946 #1119947 #1120743 #1120758 #1121621
#1123161
Cross- CVE-2018-16862 CVE-2018-16884 CVE-2018-18281
CVE-2018-18386 CVE-2018-18690 CVE-2018-18710
CVE-2018-19824 CVE-2018-19985 CVE-2018-20169
CVE-2018-9516 CVE-2018-9568 CVE-2019-3459
CV...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.