Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

SUSE Linux Enterprise 12 SP3: 2021:0456-2 Critical Kernel Patch

suse
Calendar Grey February 19, 2019
Dist Suse Esm H88
Patch addresses 15 concerns and introduces 40 adjustments for SUSE Enterprise platforms concerning security flaws in the Linux Kernel.
An update that solves 13 vulnerabilities and has 43 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP2 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-19985: The function hso_probe read if_num from the USB device (as an u8) and used it without a length check to index an array, resulting in an OOB memory read in hso_probe or hso_get_config_data that could be used by local attackers (bnc#1120743). - CVE-2018-16884: NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_process() use wrong back-channel IDs and cause a use-after-free vulnerability. Thus a malicious container user can cause a host kernel memory corruption and a system panic. Due to the nature of the flaw, privilege escalation cannot be fully ruled out (bnc#1119946).

References

#1012382 #1023175 #1042286 #1065600 #1065726

#1070805 #1084721 #1086095 #1086535 #1091158

#1091171 #1091197 #1094825 #1095344 #1098996

#1099523 #1099597 #1100105 #1101555 #1103624

#1104731 #1105025 #1105931 #1106293 #1107256

#1107299 #1107385 #1107866 #1108145 #1108498

#1109330 #1110286 #1110837 #1111062 #1113192

#1113751 #1113769 #1114190 #1114648 #1114763

#1115433 #1115440 #1116027 #1116183 #1116345

#1117186 #1117187 #1118152 #1118319 #1119714

#1119946 #1119947 #1120743 #1120758 #1121621

#1123161

Cross- CVE-2018-16862 CVE-2018-16884 CVE-2018-18281

CVE-2018-18386 CVE-2018-18690 CVE-2018-18710

CVE-2018-19824 CVE-2018-19985 CVE-2018-20169

CVE-2018-9516 CVE-2018-9568 CVE-2019-3459

CV...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:0439-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here