Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

SUSE: 2019:14051-1 Important: Kernel Update Addresses Key Issues

suse
Calendar Grey May 16, 2019
Dist Suse Esm H88
SUSE announces urgent kernel patch addressing vulnerabilities related to data exposure and Denial of Service risks. Full advisory information available.
An update that solves 11 vulnerabilities and has 20 fixes is now available

Summary

The SUSE Linux Enterprise 11 SP4 kernel was updated to receive various security and bugfixes. Four new speculative execution information leak issues have been identified in Intel CPUs. (bsc#1111331) - CVE-2018-12126: Microarchitectural Store Buffer Data Sampling (MSBDS) - CVE-2018-12127: Microarchitectural Fill Buffer Data Sampling (MFBDS) - CVE-2018-12130: Microarchitectural Load Port Data Samling (MLPDS) - CVE-2019-11091: Microarchitectural Data Sampling Uncacheable Memory (MDSUM) This kernel update contains software mitigations for these issues, which also utilize CPU microcode updates shipped in parallel. For more information on this set of information leaks, check out https://support.scc.suse.com/s/kb?language=en_US The following security bugs were fixed:

References

#1082943 #1094244 #1103186 #1106886 #1110436

#1111331 #1112178 #1117515 #1119019 #1127082

#1127376 #1127445 #1127534 #1127738 #1128166

#1128383 #1129248 #1129437 #1129439 #1129770

#1130353 #1130384 #1131107 #1131587 #1132589

#773383 #774523 #797175 #800280 #801178 #816708

Cross- CVE-2012-3412 CVE-2012-3430 CVE-2013-0160

CVE-2013-0216 CVE-2013-0231 CVE-2013-1979

CVE-2018-12126 CVE-2018-12127 CVE-2018-12130

CVE-2019-11091 CVE-2019-9213

Affected Products:

SUSE Linux Enterprise Server 11-SP4-LTSS

SUSE Linux Enterprise Server 11-EXTRA

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2012-3412.html

https://www.suse.com/security/cve/CVE-2012-3430.html

https://www.suse.com/security/cve/CVE-2013-0160.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:14051-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here