Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE: 2019:1287-1 Important: Kernel Security Patch Update

suse
Calendar Grey May 17, 2019
Dist Suse Esm H88
Crucial SUSE patch rectifies several security flaws within the Linux kernel, providing solutions for serious vulnerabilities.
An update that solves 16 vulnerabilities and has 19 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP2 kernel was updated to receive various security and bugfixes. Four new speculative execution information leak issues have been identified in Intel CPUs. (bsc#1111331) - CVE-2018-12126: Microarchitectural Store Buffer Data Sampling (MSBDS) - CVE-2018-12127: Microarchitectural Fill Buffer Data Sampling (MFBDS) - CVE-2018-12130: Microarchitectural Load Port Data Samling (MLPDS) - CVE-2019-11091: Microarchitectural Data Sampling Uncacheable Memory (MDSUM) This kernel update contains software mitigations for these issues, which also utilize CPU microcode updates shipped in parallel. For more information on this set of information leaks, check out https://support.scc.suse.com/s/kb?language=en_US The following security bugs were fixed:

References

#1012382 #1024908 #1034113 #1043485 #1068032

#1073311 #1080157 #1080533 #1082632 #1087231

#1087659 #1087906 #1093158 #1094268 #1096748

#1100152 #1103186 #1106913 #1109772 #1111331

#1112178 #1113399 #1116841 #1118338 #1119019

#1122822 #1124832 #1125580 #1129279 #1131416

#1131427 #1131587 #1132673 #1132828 #1133188

Cross- CVE-2016-8636 CVE-2017-17741 CVE-2017-18174

CVE-2018-1091 CVE-2018-1120 CVE-2018-1128

CVE-2018-1129 CVE-2018-12126 CVE-2018-12127

CVE-2018-12130 CVE-2018-19407 CVE-2019-11091

CVE-2019-11486 CVE-2019-3882 CVE-2019-8564

CVE-2019-9503

Affected Products:

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server 12-SP2-LTSS

...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:1287-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here