Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

SUSE: 2019:3389-1 Critical Kernel Update Addressing Denial of Service Risks

suse
Calendar Grey December 27, 2019
Dist Suse Esm H88
A vital security patch for SUSE tackles 24 flaws and incorporates 75 corrections for the Linux Kernel.
An update that solves 24 vulnerabilities and has 75 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP5 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2019-16746: There was an issue in net/wireless/nl80211.c where the kernel did not check the length of variable elements in a beacon head, leading to a buffer overflow (bnc#1152107). - CVE-2019-19066: Fixed memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c that allowed attackers to cause a denial of service (memory consumption) by triggering bfa_port_get_stats() failures (bnc#1157303). - CVE-2019-19051: Fixed memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c that allowed attackers to cause a denial of service (memory consumption) (bnc#1159024).

References

#1051510 #1071995 #1078248 #1083647 #1089644

#1090888 #1108043 #1111666 #1112178 #1113956

#1114279 #1115026 #1117169 #1119461 #1119465

#1120853 #1129770 #1137223 #1138039 #1138190

#1140948 #1142095 #1142635 #1144333 #1146519

#1146544 #1151067 #1151548 #1152107 #1152631

#1153811 #1154043 #1154355 #1154768 #1154905

#1154916 #1155689 #1155921 #1156462 #1156471

#1156928 #1157042 #1157115 #1157160 #1157169

#1157171 #1157303 #1157424 #1157463 #1157499

#1157698 #1157778 #1157895 #1157908 #1158049

#1158063 #1158064 #1158065 #1158066 #1158067

#1158068 #1158071 #1158082 #1158094 #1158132

#1158381 #1158394 #1158398 #1158407 #1158410

#1158413 #1158417 #1158427 #1158445 #1158533

#1158637 #115...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:3389-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here