Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

SUSE: 2019:2072-1 Important: Kernel Security Vulnerabilities Fixed

suse
Calendar Grey August 7, 2019
Dist Suse Esm H88
Debian Security Patch resolves serious kernel vulnerabilities and includes solutions for various security flaws. Discover further details.
An update that solves 7 vulnerabilities and has 70 fixes is now available

Summary

The SUSE Linux Enterprise 12 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-20855: An issue was discovered in the Linux kernel In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace(bsc#1143045). - CVE-2019-1125: Exclude ATOMs from speculation through SWAPGS (bsc#1139358). - CVE-2019-14283: In the Linux kernel, set_geometry in drivers/block/floppy.c did not validate the sect and head fields, as demonstrated by an integer overflow and out-of-bounds read. It could be triggered by an unprivileged local user when a floppy disk was inserted. NOTE: QEMU creates the floppy device by default. (bnc#1143191)

References

#1051510 #1055117 #1071995 #1083647 #1083710

#1102247 #1111666 #1119222 #1123080 #1127034

#1127315 #1129770 #1130972 #1133021 #1134097

#1134390 #1134399 #1135335 #1135642 #1136896

#1137458 #1137534 #1137535 #1137584 #1137609

#1137811 #1137827 #1139358 #1140133 #1140139

#1140322 #1140652 #1140887 #1140888 #1140889

#1140891 #1140893 #1140903 #1140945 #1140954

#1140955 #1140956 #1140957 #1140958 #1140959

#1140960 #1140961 #1140962 #1140964 #1140971

#1140972 #1140992 #1141401 #1141402 #1141452

#1141453 #1141454 #1141478 #1142023 #1142112

#1142220 #1142221 #1142254 #1142350 #1142351

#1142354 #1142359 #1142450 #1142701 #1142868

#1143003 #1143045 #1143105 #1143185 #1143189

#1143191 #114...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:2072-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here