SUSE: 2019:2071-1 important: the Linux Kernel
Summary
The SUSE Linux Enterprise 15 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-20855: An issue was discovered in the Linux kernel In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace(bsc#1143045). - CVE-2019-1125: Exclude ATOMs from speculation through SWAPGS (bsc#1139358). - CVE-2019-14283: In the Linux kernel, set_geometry in drivers/block/floppy.c did not validate the sect and head fields, as demonstrated by an integer overflow and out-of-bounds read. It could be triggered by an unprivileged local user when a floppy disk was inserted. NOTE: QEMU creates the floppy device by default. (bnc#1143191) - CVE-2019-11810: An issue was discovered in the Linux kernel A NULL pointer dereference could occur when megasas_create_frame_pool() failed in megasas_...
Read the Full AdvisoryReferences
#1051510 #1055117 #1071995 #1083647 #1083710
#1102247 #1119222 #1123080 #1127034 #1127315
#1129770 #1130972 #1133021 #1134097 #1134390
#1134399 #1135335 #1135642 #1137458 #1137534
#1137535 #1137584 #1137609 #1137827 #1139358
#1140133 #1140322 #1140652 #1140903 #1140945
#1141401 #1141402 #1141452 #1141453 #1141454
#1141478 #1142023 #1142112 #1142220 #1142221
#1142254 #1142350 #1142351 #1142354 #1142359
#1142450 #1142701 #1142868 #1143003 #1143045
#1143105 #1143185 #1143189 #1143191 #1143507
Cross- CVE-2018-20855 CVE-2019-1125 CVE-2019-11810
CVE-2019-13631 CVE-2019-13648 CVE-2019-14283
CVE-2019-14284
Affected Products:
SUSE Linux Enterprise Module for Live Patching 15
https://www.suse.com/security/cve...
Read the Full Advisory