Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

SUSE: 2019:2949-1 Important: Linux Kernel Denial of Service Risk

suse
Calendar Grey November 12, 2019
Dist Suse Esm H88
Fedora introduced a significant patch for the Linux Operating System addressing 35 vulnerabilities and enhancing overall system stability.
An update that solves 49 vulnerabilities and has 18 fixes is now available

Summary

The SUSE Linux Enterprise 12-SP3 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-12207: Untrusted virtual machines on Intel CPUs could exploit a race condition in the Instruction Fetch Unit of the Intel CPU to cause a Machine Exception during Page Size Change, causing the CPU core to be non-functional. The Linux Kernel kvm hypervisor was adjusted to avoid page size changes in executable pages by splitting / merging huge pages into small pages as needed. More information can be found on https://support.scc.suse.com/s/kb?language=en_US - CVE-2019-16995: Fix a memory leak in hsr_dev_finalize() if hsr_add_port failed to add a port, which may have caused denial of service (bsc#1152685).

References

#1051510 #1084878 #1117665 #1131107 #1133140

#1135966 #1135967 #1136261 #1137865 #1139073

#1140671 #1141013 #1141054 #1142458 #1143187

#1144123 #1144903 #1145477 #1146042 #1146163

#1146285 #1146361 #1146378 #1146391 #1146413

#1146425 #1146512 #1146514 #1146516 #1146519

#1146524 #1146526 #1146529 #1146540 #1146543

#1146547 #1146550 #1146584 #1146589 #1147022

#1147122 #1148394 #1148938 #1149083 #1149376

#1149522 #1149527 #1149555 #1149612 #1150025

#1150112 #1150452 #1150457 #1150465 #1150727

#1150942 #1151347 #1151350 #1152685 #1152782

#1152788 #1153158 #1153263 #1154103 #1154372

#1155131 #1155671

Cross- CVE-2016-10906 CVE-2017-18379 CVE-2017-18509

CVE-2017-18551 CVE-2017-18595 CVE-2018-12207

...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:2949-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here