Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

SUSE: 2019:14157-1 Important: Linux Kernel Denial of Service Mitigations

suse
Calendar Grey August 29, 2019
Dist Suse Esm H88
Ubuntu Security Patch provides essential updates for the Linux Kernel, improving overall system reliability and safeguarding against vulnerabilities.
An update that solves 7 vulnerabilities and has 9 fixes is now available

Summary

The SUSE Linux Enterprise 11 SP4 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2019-14284: The drivers/block/floppy.c allowed a denial of service by setup_format_params division-by-zero. Two consecutive ioctls can trigger the bug: the first one should set the drive geometry with .sect and .rate values that make F_SECT_PER_TRACK be zero. Next, the floppy format operation should be called. It can be triggered by an unprivileged local user even when a floppy disk has not been inserted. NOTE: QEMU creates the floppy device by default (bsc#1143189). - CVE-2019-14283: The function set_geometry in drivers/block/floppy.c did not validate the sect and head fields, as demonstrated by an integer

References

#1134390 #1134399 #1138744 #1139358 #1140945

#1140965 #1141401 #1141402 #1141452 #1141453

#1141454 #1142023 #1143045 #1143179 #1143189

#1143191

Cross- CVE-2015-9289 CVE-2018-20855 CVE-2019-1125

CVE-2019-11810 CVE-2019-13631 CVE-2019-14283

CVE-2019-14284

Affected Products:

SUSE Linux Enterprise Server 11-SP4-LTSS

SUSE Linux Enterprise Server 11-EXTRA

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2015-9289.html

https://www.suse.com/security/cve/CVE-2018-20855.html

https://www.suse.com/security/cve/CVE-2019-1125.html

https://www.suse.com/security/cve/CVE-2019-11810.html

https://www.suse.com/security/cve/CVE-2019-13631.html

https://www.suse.com/security/cve/CVE-2019-14283.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:14157-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here