The SUSE Linux Enterprise 12 SP3 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2019-10638: In the Linux kernel, a device could be tracked by an attacker using the IP ID values the kernel produces for connection-less protocols (e.g., UDP and ICMP). When such traffic was sent to multiple destination IP addresses, it was possible to obtain hash collisions (of indices to the counter array) and thereby obtain the hashing key (via enumeration). An attack may have been conducted by hosting a crafted web page that uses WebRTC or gQUIC to force UDP traffic to attacker-controlled IP addresses (bnc#1140575 1140577). - CVE-2019-10639: The Linux kernel allowed Information Exposure (partial kernel address disclosure), that lead to a KASLR bypass. Specifically,
#1053043 #1066223 #1094555 #1108382 #1109137
#1111188 #1119086 #1120902 #1121263 #1125580
#1126961 #1127155 #1129770 #1131335 #1131336
#1131645 #1132390 #1133140 #1133190 #1133191
#1133738 #1134395 #1135642 #1136598 #1136889
#1136922 #1136935 #1137004 #1137194 #1137739
#1137749 #1137752 #1137915 #1138291 #1138293
#1138374 #1138681 #1139751 #1140575 #1140577
Cross- CVE-2018-20836 CVE-2019-10126 CVE-2019-10638
CVE-2019-10639 CVE-2019-11487 CVE-2019-11599
CVE-2019-12380 CVE-2019-12456 CVE-2019-12614
CVE-2019-12818 CVE-2019-12819
Affected Products:
SUSE OpenStack Cloud 8
SUSE Linux Enterprise Server for SAP 12-SP3
SUSE Linux Enterprise Server 12-SP3-LTSS
SUSE Linux Enterprise High Availabi...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.