Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

SUSE: 2019:3379-1 Important: Linux Kernel Security Update Detailed Report

suse
Calendar Grey December 21, 2019
Dist Suse Esm H88
SUSE Security Notification for the Linux Kernel: 30 security vulnerabilities addressed in SUSE-SU-2020:1987-1.
An update that solves 26 vulnerabilities and has 14 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP 3 LTSS kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2019-14895: A heap-based buffer overflow was discovered in the Linux kernel in Marvell WiFi chip driver. The flaw could occur when the station attempts a connection negotiation during the handling of the remote devices country settings. This could have allowed the remote device to cause a denial of service (system crash) or possibly execute arbitrary code (bnc#1157158). - CVE-2019-18660: The Linux kernel on powerpc allowed Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs. This is related to arch/powerpc/kernel/entry_64.S and arch/powerpc/kernel/security.c (bnc#1157038).

References

#1091041 #1119461 #1119465 #1131107 #1138190

#1146544 #1146612 #1150466 #1150483 #1152631

#1153811 #1154905 #1155689 #1155897 #1155898

#1156187 #1157038 #1157042 #1157070 #1157143

#1157158 #1157191 #1157324 #1157333 #1157464

#1158132 #1158394 #1158398 #1158410 #1158413

#1158417 #1158445 #1158823 #1158824 #1158827

#1158834 #1158900 #1158903 #1158904 #1158954

Cross- CVE-2019-14895 CVE-2019-15213 CVE-2019-16231

CVE-2019-18660 CVE-2019-18680 CVE-2019-18683

CVE-2019-18805 CVE-2019-19052 CVE-2019-19062

CVE-2019-19065 CVE-2019-19073 CVE-2019-19074

CVE-2019-19332 CVE-2019-19338 CVE-2019-19523

CVE-2019-19524 CVE-2019-19525 CVE-2019-19527

CVE-2019-19530 CVE-2019-19531 CVE-2019-19532

CVE-2019-19...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:3379-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here