Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

SUSE: 2019:2299-1 Important: Linux Kernel Fixes for Denial of Service

suse
Calendar Grey September 5, 2019
Dist Suse Esm H88
SUSE Security Update for Linux Kernel brings vital improvements, focusing on performance boosts and critical vulnerabilities remediation.
An update that solves 12 vulnerabilities and has 19 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP2 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2019-3819: A flaw was fixed in the function hid_debug_events_read() in drivers/hid/hid-debug.c file which may have enter an infinite loop with certain parameters passed from a userspace. A local privileged user ("root") could have caused a system lock up and a denial of service (bnc#1123161). - CVE-2019-15118: Fixed kernel stack exhaustion in check_input_term in sound/usb/mixer.c via mishandled recursion (bnc#1145922). - CVE-2019-15117: Fixed out-of-bounds memory access in parse_audio_mixer_unit in sound/usb/mixer.c via mishandled short descriptor (bnc#1145920). - CVE-2019-14284: The drivers/block/floppy.c allowed a denial of service

References

#1045640 #1076033 #1107256 #1123161 #1130972

#1134399 #1139358 #1140012 #1140652 #1140903

#1140945 #1141401 #1141402 #1141452 #1141453

#1141454 #1141628 #1142023 #1142098 #1142857

#1143045 #1143048 #1143189 #1143191 #1144257

#1144273 #1144288 #1144920 #1145920 #1145922

#1146163

Cross- CVE-2017-18551 CVE-2018-20855 CVE-2018-20856

CVE-2019-10207 CVE-2019-1125 CVE-2019-11810

CVE-2019-13631 CVE-2019-14283 CVE-2019-14284

CVE-2019-15117 CVE-2019-15118 CVE-2019-3819

Affected Products:

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server 12-SP2-LTSS

SUSE Linux Enterprise Server 12-SP2-BCL

SUSE Linux Enterprise High Availability 12-SP2

...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:2299-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here