Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

SUSE 12-SP1: 2019:2262-1 Important: Denial Of Service Mitigations

suse
Calendar Grey September 2, 2019
Dist Suse Esm H88
Crucial security enhancements for SUSE Linux Kernel made public to tackle several vulnerabilities and deliver vital fixes.
An update that solves 7 vulnerabilities and has 13 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP1 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2019-1125: Enable Spectre v1 swapgs mitigations (bsc#1139358). - CVE-2018-20855: An issue was discovered in create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace (bsc#1143045). - CVE-2019-14284: The drivers/block/floppy.c allowed a denial of service by setup_format_params division-by-zero. Two consecutive ioctls can trigger the bug: the first one should set the drive geometry with .sect and .rate values that make F_SECT_PER_TRACK be zero. Next, the floppy format operation should be called. It can be triggered by an

References

#1130972 #1134399 #1138744 #1139358 #1140652

#1140945 #1141401 #1141402 #1141452 #1141453

#1141454 #1142023 #1142098 #1142254 #1143045

#1143189 #1143191 #1144257 #1144273 #1144288

Cross- CVE-2018-20855 CVE-2019-1125 CVE-2019-11810

CVE-2019-13631 CVE-2019-13648 CVE-2019-14283

CVE-2019-14284

Affected Products:

SUSE Linux Enterprise Server for SAP 12-SP1

SUSE Linux Enterprise Server 12-SP1-LTSS

SUSE Linux Enterprise Module for Public Cloud 12

https://www.suse.com/security/cve/CVE-2018-20855.html

https://www.suse.com/security/cve/CVE-2019-1125.html

https://www.suse.com/security/cve/CVE-2019-11810.html

https://www.suse.com/security/cve/CVE-2019-13631.html

https://www.suse.com/security/cve/CVE-2019-13648.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:2262-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here