Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

SUSE: 2019:0683-1 Important: Kernel Memory Issues Addressed

suse
Calendar Grey March 21, 2019
Dist Suse Esm H88
SUSE has released a vital security patch addressing severe kernel flaws in Live Patch 21 for SLE 12 SP2, along with detailed installation guidelines.
An update that fixes three vulnerabilities is now available

Summary

This update for the Linux Kernel 4.4.121-92_73 fixes several issues. The following security issues were fixed: - CVE-2019-9213: Expand_downwards in mm/mmap.c lacked a check for the mmap minimum address, which made it easier for attackers to exploit kernel NULL pointer dereferences on non-SMAP platforms. This is related to a capability check for the wrong task (bsc#1128378). - CVE-2019-7221: Fixed a user-after-free vulnerability in the KVM hypervisor related to the emulation of a preemption timer, allowing an guest user/process to crash the host kernel. (bsc#1124734). - CVE-2019-6974: kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandled reference counting because of a race condition, leading to a use-after-free (bsc#1124729). Patch Instructions:

References

#1124729 #1124734 #1128378

Cross- CVE-2019-6974 CVE-2019-7221 CVE-2019-9213

Affected Products:

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server 12-SP2-LTSS

https://www.suse.com/security/cve/CVE-2019-6974.html

https://www.suse.com/security/cve/CVE-2019-7221.html

https://www.suse.com/security/cve/CVE-2019-9213.html

https://bugzilla.suse.com/1124729

https://bugzilla.suse.com/1124734

https://bugzilla.suse.com/1128378

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:0683-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here