Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

SUSE: 2019:1852-1 Important: Linux Kernel DoS and Exploits

suse
Calendar Grey July 15, 2019
Dist Suse Esm H88
SUSE reveals a crucial Security Patch for the Linux Kernel, tackling multiple vulnerabilities, encompassing service disruptions and confidential information exposure.
An update that solves 11 vulnerabilities and has 29 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP3 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2019-10638: In the Linux kernel, a device could be tracked by an attacker using the IP ID values the kernel produces for connection-less protocols (e.g., UDP and ICMP). When such traffic was sent to multiple destination IP addresses, it was possible to obtain hash collisions (of indices to the counter array) and thereby obtain the hashing key (via enumeration). An attack may have been conducted by hosting a crafted web page that uses WebRTC or gQUIC to force UDP traffic to attacker-controlled IP addresses (bnc#1140575 1140577). - CVE-2019-10639: The Linux kernel allowed Information Exposure (partial kernel address disclosure), that lead to a KASLR bypass. Specifically,

References

#1053043 #1066223 #1094555 #1108382 #1109137

#1111188 #1119086 #1120902 #1121263 #1125580

#1126961 #1127155 #1129770 #1131335 #1131336

#1131645 #1132390 #1133140 #1133190 #1133191

#1133738 #1134395 #1135642 #1136598 #1136889

#1136922 #1136935 #1137004 #1137194 #1137739

#1137749 #1137752 #1137915 #1138291 #1138293

#1138374 #1138681 #1139751 #1140575 #1140577

Cross- CVE-2018-20836 CVE-2019-10126 CVE-2019-10638

CVE-2019-10639 CVE-2019-11487 CVE-2019-11599

CVE-2019-12380 CVE-2019-12456 CVE-2019-12614

CVE-2019-12818 CVE-2019-12819

Affected Products:

SUSE OpenStack Cloud 8

SUSE Linux Enterprise Server for SAP 12-SP3

SUSE Linux Enterprise Server 12-SP3-LTSS

SUSE Linux Enterprise High Availabi...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:1852-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here