The SUSE Linux Enterprise 12 realtime kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2017-18249: Fixed tracking on allocated nid in the add_free_nid function fs/f2fs/node.c, which previously allowed local users to cause a denial of service (bnc#1087036). - CVE-2019-3459: Fixed remote heap address information leak in use of l2cap_get_conf_opt (bnc#1120758). - CVE-2019-3460: Fixed remote data leak in multiple location in the function l2cap_parse_conf_rsp (bnc#1120758). The following non-security bugs were fixed: - Disable MSI also when pcie-octeon.pcie_disable on (bnc#1012382). - Fix problem with sharetransport= and NFSv4 (bsc#1114893). - Revert "bs-upload-kernel: do not set %opensuse_bs" This reverts commit
#1012382 #1023175 #1087036 #1094823 #1102875
#1102877 #1102879 #1102882 #1102896 #1106105
#1106929 #1107866 #1109695 #1114893 #1116653
#1119680 #1120722 #1120758 #1120902 #1121726
#1122650 #1122651 #1122779 #1122885 #1123321
#1123323 #1123357
Cross- CVE-2017-18249 CVE-2019-3459 CVE-2019-3460
Affected Products:
SUSE Linux Enterprise Real Time Extension 12-SP3
https://www.suse.com/security/cve/CVE-2017-18249.html
https://www.suse.com/security/cve/CVE-2019-3459.html
https://www.suse.com/security/cve/CVE-2019-3460.html
https://bugzilla.suse.com/1012382
https://bugzilla.suse.com/1023175
https://bugzilla.suse.com/1087036
https://bugzilla.suse.com/1094823
https://bugzilla.suse.com/1102875
https://bugzilla.suse.com/1102877
Get the latest Linux and open source security news straight to your inbox.