The SUSE Linux Enterprise 12 SP3 kernel was updated to 4.4.176 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2019-9213: expand_downwards in mm/mmap.c lacked a check for the mmap minimum address, which made it easier for attackers to exploit kernel NULL pointer dereferences on non-SMAP platforms. This is related to a capability check for the wrong task (bnc#1128166). - CVE-2019-2024: A use-after-free when disconnecting a source was fixed which could lead to crashes. bnc#1129179). The following non-security bugs were fixed: - ax25: fix possible use-after-free (bnc#1012382). - block_dev: fix crash on chained bios with O_DIRECT (bsc#1090435). - block: do not use bio->bi_vcnt to figure out segment number (bsc#1128893).
#1012382 #1020413 #1065600 #1070767 #1075697
#1082943 #1087092 #1090435 #1102959 #1103429
#1106929 #1109137 #1109248 #1119019 #1119843
#1120691 #1120902 #1121713 #1121805 #1124235
#1125315 #1125446 #1126389 #1126772 #1126773
#1126805 #1127082 #1127155 #1127561 #1127725
#1127731 #1127961 #1128166 #1128452 #1128565
#1128696 #1128756 #1128893 #1129080 #1129179
#1129237 #1129238 #1129239 #1129240 #1129241
#1129413 #1129414 #1129415 #1129416 #1129417
#1129418 #1129419 #1129581 #1129770 #1129923
Cross- CVE-2019-2024 CVE-2019-9213
Affected Products:
SUSE Linux Enterprise Live Patching 12-SP3
https://www.suse.com/security/cve/CVE-2019-2024.html
https://www.suse.com/security/cve/CVE-2019-9213.html
https://bugzilla.suse.com/1012382
https://...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.