Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

SUSE: 2019:2263-1 Important: Linux Kernel Denial of Service Fix

suse
Calendar Grey September 2, 2019
Dist Suse Esm H88
The latest security patch from SUSE tackles 12 identified weaknesses within the Linux kernel, providing necessary corrections to improve overall system resilience.
An update that solves 12 vulnerabilities and has 24 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP3 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2019-1125: Enable Spectre v1 swapgs mitigations (bsc#1139358). - CVE-2018-20855: An issue was discovered in create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace (bsc#1143045). - CVE-2019-14284: The drivers/block/floppy.c allowed a denial of service by setup_format_params division-by-zero. Two consecutive ioctls can trigger the bug: the first one should set the drive geometry with .sect and .rate values that make F_SECT_PER_TRACK be zero. Next, the floppy format operation should be called. It can be triggered by an

References

#1106061 #1123161 #1125674 #1127034 #1128977

#1130972 #1133860 #1134399 #1135335 #1135365

#1137584 #1139358 #1139826 #1140652 #1140903

#1140945 #1141181 #1141401 #1141402 #1141452

#1141453 #1141454 #1142023 #1142254 #1142857

#1143045 #1143048 #1143189 #1143191 #1143333

#1144257 #1144273 #1144288 #1144920 #1145920

#1145922

Cross- CVE-2018-20855 CVE-2018-20856 CVE-2019-10207

CVE-2019-1125 CVE-2019-11810 CVE-2019-13631

CVE-2019-13648 CVE-2019-14283 CVE-2019-14284

CVE-2019-15117 CVE-2019-15118 CVE-2019-3819

Affected Products:

SUSE OpenStack Cloud Crowbar 8

SUSE OpenStack Cloud 8

SUSE Linux Enterprise Server for SAP 12-SP3

SUSE Linux Enterprise Server 12-SP3-LTSS

SUSE Linu...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:2263-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here