Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

SUSE: 2019:1882-1 Important: Kernel Patch Resolves DoS and Memory Issues

suse
Calendar Grey July 18, 2019
Dist Suse Esm H88
SUSE Security Update: Urgent Linux Kernel update addresses multiple flaws, including denial of service vulnerabilities and memory leaks.
An update that fixes three vulnerabilities is now available

Summary

This update for the Linux Kernel 4.12.14-150_14 fixes several issues. The following security issues were fixed: - CVE-2019-11477: Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. (bsc#1137586) - CVE-2019-11478: Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. (bsc#1137586) - CVE-2019-3846: A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module

References

#1136446 #1137597 #1140747

Cross- CVE-2019-11477 CVE-2019-11478 CVE-2019-3846

Affected Products:

SUSE Linux Enterprise Module for Live Patching 15

https://www.suse.com/security/cve/CVE-2019-11477.html

https://www.suse.com/security/cve/CVE-2019-11478.html

https://www.suse.com/security/cve/CVE-2019-3846.html

https://bugzilla.suse.com/1136446

https://bugzilla.suse.com/1137597

https://bugzilla.suse.com/1140747

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:1882-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here