Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2019:1948-1 Important: Kernel Live Patch Addresses DoS Threats

suse
Calendar Grey July 23, 2019
Dist Suse Esm H88
Critical SUSE kernel security patch resolves various flaws, such as memory leak and denial of service vulnerabilities.
An update that fixes three vulnerabilities is now available

Summary

This update for the Linux Kernel 4.4.121-92_104 fixes several issues. The following security issues were fixed: - CVE-2019-11477: Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. (bsc#1137586) - CVE-2019-11478: Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. (bsc#1137586) - CVE-2019-3846: A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module

References

#1136446 #1137597 #1140747

Cross- CVE-2019-11477 CVE-2019-11478 CVE-2019-3846

Affected Products:

SUSE Linux Enterprise Server for SAP 12-SP3

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server 12-SP3-LTSS

SUSE Linux Enterprise Server 12-SP2-LTSS

SUSE Linux Enterprise Live Patching 12-SP4

https://www.suse.com/security/cve/CVE-2019-11477.html

https://www.suse.com/security/cve/CVE-2019-11478.html

https://www.suse.com/security/cve/CVE-2019-3846.html

https://bugzilla.suse.com/1136446

https://bugzilla.suse.com/1137597

https://bugzilla.suse.com/1140747

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:1948-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here