Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

SUSE: 2019:1823-1 Important: Linux Kernel Information Exposure and DoS

suse
Calendar Grey July 12, 2019
Dist Suse Esm H88
SUSE Security Patch for Linux Kernel: 11 vulnerabilities resolved along with key modifications. Check full details and guidelines.
An update that solves 11 vulnerabilities and has two fixes is now available

Summary

The SUSE Linux Enterprise 12 SP 2 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2019-10638: In the Linux kernel, a device could be tracked by an attacker using the IP ID values the kernel produces for connection-less protocols (e.g., UDP and ICMP). When such traffic was sent to multiple destination IP addresses, it was possible to obtain hash collisions (of indices to the counter array) and thereby obtain the hashing key (via enumeration). An attack may be conducted by hosting a crafted web page that uses WebRTC or gQUIC to force UDP traffic to attacker-controlled IP addresses. (bnc#1140575) - CVE-2019-10639: The Linux kernel allowed Information Exposure (partial kernel address disclosure), leading to a KASLR bypass. Specifically, it

References

#1096254 #1108382 #1109137 #1127155 #1133190

#1133738 #1134395 #1134701 #1136922 #1136935

#1137194 #1138291 #1140575

Cross- CVE-2018-20836 CVE-2019-10126 CVE-2019-10638

CVE-2019-10639 CVE-2019-11487 CVE-2019-11599

CVE-2019-12380 CVE-2019-12456 CVE-2019-12614

CVE-2019-12818 CVE-2019-12819

Affected Products:

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server 12-SP2-LTSS

SUSE Linux Enterprise Server 12-SP2-BCL

SUSE Enterprise Storage 4

https://www.suse.com/security/cve/CVE-2018-20836.html

https://www.suse.com/security/cve/CVE-2019-10126.html

https://www.suse.com/security/cve/CVE-2019-10638.html

https://www.suse.com/security/cve/CVE-2019-10639.html

https://www.suse.com/security/cve/CVE-2019-11487.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:1823-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here