Revision Date: | 2020-12-01 | Version: | 1 |
Title: | Security update for the Linux Kernel (Live Patch 0 for SLE 15) (Important) |
Description: |
This update for the Linux Kernel 4.12.14-23 fixes several issues.
The following security issues were fixed:
- CVE-2018-5390: Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service (bsc#1102682). - CVE-2018-3646: Local attackers in virtualized guest systems could use speculative code patterns on hyperthreaded processors to read data present in the L1 Datacache used by other hyperthreads on the same CPU core, potentially leaking sensitive data, even from other virtual machines or the host system (bsc#1099306). - CVE-2017-18344: The timer_create syscall implementation in kernel/time/posix-timers.c didn't properly validate the sigevent->sigev_notify field, which lead to out-of-bounds access in the show_timer function (called when /proc/$PID/timers is read). This allowed userspace applications to read arbitrary kernel memory (on a kernel built with CONFIG_POSIX_TIMERS and CONFIG_CHECKPOINT_RESTORE) (bsc#1103203). before 4.14.8 - CVE-2018-12904: In arch/x86/kvm/vmx.c local attackers could cause L1 KVM guests to VMEXIT, potentially allowing privilege escalations and denial of service attacks due to lack of checking of CPL (bsc#1099258). - CVE-2018-10853: A flaw was found in kvm. In which certain instructions such as sgdt/sidt call segmented_write_std didn't propagate access correctly. As such, during userspace induced exception, the guest can incorrectly assume that the exception happened in the kernel and panic. (bsc#1097108).
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | 1097108 1099258 1099306 1102682 1103203 1149841 1151021 856386 913057 924208 934088 CVE-2008-1686 CVE-2008-4989 CVE-2009-0790 CVE-2009-2473 CVE-2009-2474 CVE-2011-4128 CVE-2012-0390 CVE-2012-1569 CVE-2012-1573 CVE-2012-2388 CVE-2012-5519 CVE-2013-2062 CVE-2013-2944 CVE-2013-5018 CVE-2013-6075 CVE-2013-6076 CVE-2013-6418 CVE-2014-0092 CVE-2014-0250 CVE-2014-0791 CVE-2014-1545 CVE-2014-1959 CVE-2014-2338 CVE-2014-3466 CVE-2014-8564 CVE-2014-9638 CVE-2014-9639 CVE-2014-9640 CVE-2015-0294 CVE-2015-0301 CVE-2015-0302 CVE-2015-0303 CVE-2015-0304 CVE-2015-0305 CVE-2015-0306 CVE-2015-0307 CVE-2015-0308 CVE-2015-0309 CVE-2015-1158 CVE-2015-1159 CVE-2015-3096 CVE-2015-3098 CVE-2015-3099 CVE-2015-3100 CVE-2015-3102 CVE-2015-3103 CVE-2015-3104 CVE-2015-3105 CVE-2015-3106 CVE-2015-3107 CVE-2015-3108 CVE-2015-3622 CVE-2015-5276 CVE-2015-6251 CVE-2015-6749 CVE-2015-7995 CVE-2015-9019 CVE-2016-1602 CVE-2016-4738 CVE-2016-7444 CVE-2016-8610 CVE-2017-10790 CVE-2017-18344 CVE-2017-5029 CVE-2017-5335 CVE-2017-5336 CVE-2017-5337 CVE-2018-10844 CVE-2018-10845 CVE-2018-10846 CVE-2018-10853 CVE-2018-12904 CVE-2018-3646 CVE-2018-5390 CVE-2019-14835 SUSE-SU-2015:1041-1 SUSE-SU-2015:1043-1 SUSE-SU-2018:2474-1
|
Platform(s): | openSUSE Leap 15.0 SUSE Linux Enterprise Desktop 11 SP3 SUSE Linux Enterprise Desktop 11 SP4 SUSE Linux Enterprise Desktop 12 SUSE Linux Enterprise Desktop 12 SP1 SUSE Linux Enterprise Desktop 12 SP2 SUSE Linux Enterprise Desktop 12 SP3 SUSE Linux Enterprise Desktop 12 SP4 SUSE Linux Enterprise Module for Live Patching 15 SUSE Linux Enterprise Server 12 SP1 SUSE Linux Enterprise Server 12 SP1-LTSS SUSE Linux Enterprise Server 12 SP2 SUSE Linux Enterprise Server 12 SP2-BCL SUSE Linux Enterprise Server 12 SP2-ESPOS SUSE Linux Enterprise Server 12 SP2-LTSS SUSE Linux Enterprise Server 12 SP3 SUSE Linux Enterprise Server 12 SP3-BCL SUSE Linux Enterprise Server 12 SP3-ESPOS SUSE Linux Enterprise Server 12 SP3-LTSS SUSE Linux Enterprise Server 12 SP3-TERADATA SUSE Linux Enterprise Server 12 SP4 SUSE OpenStack Cloud 6 SUSE OpenStack Cloud 7 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud Crowbar 8
| Product(s): | |
Definition Synopsis |
openSUSE Leap 15.0 is installed AND Package Information
bind-9.11.2-lp150.7 is installed
OR bind-chrootenv-9.11.2-lp150.7 is installed
OR bind-utils-9.11.2-lp150.7 is installed
OR libbind9-160-9.11.2-lp150.7 is installed
OR libdns169-9.11.2-lp150.7 is installed
OR libirs160-9.11.2-lp150.7 is installed
OR libisc166-9.11.2-lp150.7 is installed
OR libisccc160-9.11.2-lp150.7 is installed
OR libisccfg160-9.11.2-lp150.7 is installed
OR liblwres160-9.11.2-lp150.7 is installed
OR python3-bind-9.11.2-lp150.7 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 11 SP3 is installed
AND Package Information
MozillaFirefox-38.4.0esr-25 is installed
OR MozillaFirefox-branding-SLED-38-15 is installed
OR MozillaFirefox-translations-38.4.0esr-25 is installed
OR libfreebl3-3.19.2.1-19 is installed
OR libfreebl3-32bit-3.19.2.1-19 is installed
OR libsoftokn3-3.19.2.1-19 is installed
OR libsoftokn3-32bit-3.19.2.1-19 is installed
OR mozilla-nspr-4.10.10-16 is installed
OR mozilla-nspr-32bit-4.10.10-16 is installed
OR mozilla-nss-3.19.2.1-19 is installed
OR mozilla-nss-32bit-3.19.2.1-19 is installed
OR mozilla-nss-tools-3.19.2.1-19 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 11 SP4 is installed
AND Package Information
mozilla-nspr-4.10.9-11 is installed
OR mozilla-nspr-32bit-4.10.9-11 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 is installed
AND Package Information
libXp6-1.0.2-3 is installed
OR libXp6-32bit-1.0.2-3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 SP1 is installed
AND Package Information
freerdp-1.0.2-7 is installed
OR libfreerdp-1_0-1.0.2-7 is installed
OR libfreerdp-1_0-plugins-1.0.2-7 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 SP2 is installed
AND supportutils-3.0-85 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 SP3 is installed
AND Package Information
libasan2-5.3.1+r233831-12 is installed
OR libasan2-32bit-5.3.1+r233831-12 is installed
OR libffi4-5.3.1+r233831-12 is installed
OR libffi4-32bit-5.3.1+r233831-12 is installed
OR libmpx0-5.3.1+r233831-12 is installed
OR libmpx0-32bit-5.3.1+r233831-12 is installed
OR libmpxwrappers0-5.3.1+r233831-12 is installed
OR libmpxwrappers0-32bit-5.3.1+r233831-12 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 SP4 is installed
AND Package Information
gnutls-3.3.27-3.3 is installed
OR libgnutls28-3.3.27-3.3 is installed
OR libgnutls28-32bit-3.3.27-3.3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Live Patching 15 is installed
AND Package Information
kernel-livepatch-4_12_14-23-default-2-4 is installed
OR kernel-livepatch-SLE15_Update_0-2-4 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP1 is installed
AND Package Information
alsa-1.0.27.2-11 is installed
OR alsa-docs-1.0.27.2-11 is installed
OR libasound2-1.0.27.2-11 is installed
OR libasound2-32bit-1.0.27.2-11 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP1-LTSS is installed
AND Package Information
kgraft-patch-3_12_69-60_64_32-default-10-2 is installed
OR kgraft-patch-3_12_69-60_64_32-xen-10-2 is installed
OR kgraft-patch-SLE12-SP1_Update_13-10-2 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP2 is installed
AND libimobiledevice6-1.2.0-7 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP2-BCL is installed
AND Package Information
openssh-7.2p2-74.25 is installed
OR openssh-askpass-gnome-7.2p2-74.25 is installed
OR openssh-fips-7.2p2-74.25 is installed
OR openssh-helpers-7.2p2-74.25 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
AND Package Information
kgraft-patch-4_4_114-92_64-default-10-2 is installed
OR kgraft-patch-SLE12-SP2_Update_18-10-2 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP2-LTSS is installed
AND Package Information
kgraft-patch-4_4_103-92_53-default-9-2 is installed
OR kgraft-patch-SLE12-SP2_Update_16-9-2 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3 is installed
AND binutils-2.26.1-9.12 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3-BCL is installed
AND Package Information
MozillaFirefox-60.8.0-109.83 is installed
OR MozillaFirefox-translations-common-60.8.0-109.83 is installed
OR libfreebl3-3.44.1-58.28 is installed
OR libfreebl3-32bit-3.44.1-58.28 is installed
OR libfreebl3-hmac-3.44.1-58.28 is installed
OR libfreebl3-hmac-32bit-3.44.1-58.28 is installed
OR libsoftokn3-3.44.1-58.28 is installed
OR libsoftokn3-32bit-3.44.1-58.28 is installed
OR libsoftokn3-hmac-3.44.1-58.28 is installed
OR libsoftokn3-hmac-32bit-3.44.1-58.28 is installed
OR mozilla-nss-3.44.1-58.28 is installed
OR mozilla-nss-32bit-3.44.1-58.28 is installed
OR mozilla-nss-certs-3.44.1-58.28 is installed
OR mozilla-nss-certs-32bit-3.44.1-58.28 is installed
OR mozilla-nss-sysinit-3.44.1-58.28 is installed
OR mozilla-nss-sysinit-32bit-3.44.1-58.28 is installed
OR mozilla-nss-tools-3.44.1-58.28 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
AND Package Information
perl-5.18.2-12.20 is installed
OR perl-32bit-5.18.2-12.20 is installed
OR perl-base-5.18.2-12.20 is installed
OR perl-doc-5.18.2-12.20 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3-LTSS is installed
AND Package Information
kgraft-patch-4_4_175-94_79-default-7-2 is installed
OR kgraft-patch-SLE12-SP3_Update_23-7-2 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
AND Package Information
apache2-2.4.23-29.21 is installed
OR apache2-doc-2.4.23-29.21 is installed
OR apache2-example-pages-2.4.23-29.21 is installed
OR apache2-prefork-2.4.23-29.21 is installed
OR apache2-utils-2.4.23-29.21 is installed
OR apache2-worker-2.4.23-29.21 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP4 is installed
AND apache2-mod_nss-1.0.14-19.3 is installed
|
Definition Synopsis |
SUSE OpenStack Cloud 6 is installed
AND python-PyYAML-3.10-15 is installed
|
Definition Synopsis |
SUSE OpenStack Cloud 7 is installed
AND Package Information
LibVNCServer-0.9.9-17.11 is installed
OR libvncclient0-0.9.9-17.11 is installed
OR libvncserver0-0.9.9-17.11 is installed
|
Definition Synopsis |
SUSE OpenStack Cloud 8 is installed
AND Package Information
ardana-monasca-8.0+git.1535031421.9262a47-3.12 is installed
OR ardana-spark-8.0+git.1534267176.a5f3a22-3.6 is installed
OR kafka-0.10.2.2-5.6 is installed
OR openstack-monasca-api-2.2.1~dev24-3.6 is installed
OR python-monasca-api-2.2.1~dev24-3.6 is installed
|
Definition Synopsis |
SUSE OpenStack Cloud Crowbar 8 is installed
AND python-urllib3-1.22-5.6 is installed
|