Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2019:1924-1 Critical Update for Kernel Live Patch Denial of Service

suse
Calendar Grey July 23, 2019
Dist Suse Esm H88
The recent SUSE Security Update tackles critical vulnerabilities within the kernel for SLE 12 SP1, enhancing both the security posture and reliability of the system.
An update that fixes two vulnerabilities is now available

Summary

This update for the Linux Kernel 3.12.74-60_64_104 fixes several issues. The following security issues were fixed: - CVE-2019-11477: Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. (bsc#1137586) - CVE-2019-11478: Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. (bsc#1137586) This update contains a regression fix for CVE-2019-11477 and CVE-2019-11478 (bsc#1140747). Patch Instructions:

References

#1137597 #1140747

Cross- CVE-2019-11477 CVE-2019-11478

Affected Products:

SUSE Linux Enterprise Server for SAP 12-SP1

SUSE Linux Enterprise Server 12-SP1-LTSS

https://www.suse.com/security/cve/CVE-2019-11477.html

https://www.suse.com/security/cve/CVE-2019-11478.html

https://bugzilla.suse.com/1137597

https://bugzilla.suse.com/1140747

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:1924-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here