Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

SUSE Linux 12-SP3 Advisory: 2019-0901-1 Important Kernel Security Fixes

suse
Calendar Grey April 8, 2019
Dist Suse Esm H88
This Debian patch resolves 9 vulnerabilities, improves system reliability, and mitigates possible DDoS and remote failure threats.
An update that solves 8 vulnerabilities and has 102 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP3 Azure kernel was updated to 4.4.176 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2019-2024: A use-after-free when disconnecting a source was fixed which could lead to crashes. bnc#1129179). - CVE-2019-9213: expand_downwards in mm/mmap.c lacked a check for the mmap minimum address, which made it easier for attackers to exploit kernel NULL pointer dereferences on non-SMAP platforms. This is related to a capability check for the wrong task (bnc#1128166). - CVE-2019-6974: kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandled reference counting because of a race condition, leading to a use-after-free. (bnc#1124728) - CVE-2019-3459, CVE-2019-3460: The Bluetooth stack suffered from two

References

#1012382 #1020413 #1023175 #1031492 #1042286

#1050549 #1065600 #1070767 #1075697 #1078355

#1082943 #1086095 #1086652 #1087036 #1087092

#1090435 #1094823 #1099810 #1102875 #1102877

#1102879 #1102882 #1102896 #1102959 #1103429

#1105428 #1106061 #1106105 #1106929 #1107866

#1109137 #1109248 #1109695 #1114893 #1116345

#1116653 #1117108 #1117645 #1117744 #1119019

#1119680 #1119843 #1120017 #1120691 #1120722

#1120758 #1120902 #1121713 #1121726 #1121805

#1122650 #1122651 #1122779 #1122885 #1123321

#1123323 #1123357 #1123933 #1124166 #1124235

#1124728 #1124732 #1124735 #1124775 #1124777

#1124780 #1124811 #1125000 #1125014 #1125315

#1125446 #1125794 #1125796 #1125808 #1125809

#1125810 #112...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:0901-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here