Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

SUSE 2019:1744-1 Important: Linux Kernel Denial of Service Fix

suse
Calendar Grey July 4, 2019
Dist Suse Esm H88
Debian Security Patch targets critical kernel vulnerabilities, improving overall security and introducing support for ARM architecture.
An update that solves three vulnerabilities and has 26 fixes is now available

Summary

The SUSE Linux Enterprise 15 SP1 kernel was updated to receive various security and bugfixes. This update adds support for the Hygon Dhyana CPU (fate#327735). The following security bugs were fixed: - CVE-2019-12614: An issue was discovered in dlpar_parse_cc_property in arch/powerpc/platforms/pseries/dlpar.c. There was an unchecked kstrdup of prop->name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash) (bnc#1137194). - CVE-2018-16871: A NULL pointer dereference due to an anomalized NFS message sequence was fixed. (bnc#1137103). - CVE-2019-12817: On the PowerPC architecture, local attackers could access other users processes memory (bnc#1138263). The following non-security bugs were fixed: - 6lowpan: Off by one handling ->nexthdr (bsc#1051510).

References

#1051510 #1071995 #1094555 #1111666 #1112374

#1114279 #1128432 #1134730 #1134738 #1135153

#1135296 #1135642 #1136156 #1136157 #1136271

#1136333 #1137103 #1137194 #1137366 #1137884

#1137985 #1138263 #1138336 #1138374 #1138375

#1138589 #1138681 #1138719 #1138732

Cross- CVE-2018-16871 CVE-2019-12614 CVE-2019-12817

Affected Products:

SUSE Linux Enterprise Module for Live Patching 15-SP1

https://www.suse.com/security/cve/CVE-2018-16871.html

https://www.suse.com/security/cve/CVE-2019-12614.html

https://www.suse.com/security/cve/CVE-2019-12817.html

https://bugzilla.suse.com/1051510

https://bugzilla.suse.com/1071995

https://bugzilla.suse.com/1094555

https://bugzilla.suse.com/1111666

https://bugzilla.suse.com/1112374

https://bugzilla.suse.com/1114279

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:1744-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here