SUSE: 2019:2262-1 important: the Linux Kernel
Summary
The SUSE Linux Enterprise 12 SP1 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2019-1125: Enable Spectre v1 swapgs mitigations (bsc#1139358). - CVE-2018-20855: An issue was discovered in create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace (bsc#1143045). - CVE-2019-14284: The drivers/block/floppy.c allowed a denial of service by setup_format_params division-by-zero. Two consecutive ioctls can trigger the bug: the first one should set the drive geometry with .sect and .rate values that make F_SECT_PER_TRACK be zero. Next, the floppy format operation should be called. It can be triggered by an unprivileged local user even when a floppy disk has not been inserted. NOTE: QEMU creates the floppy device by default (bsc#1143189). - CVE-2019-14283: The function set_geo...
Read the Full AdvisoryReferences
#1130972 #1134399 #1138744 #1139358 #1140652
#1140945 #1141401 #1141402 #1141452 #1141453
#1141454 #1142023 #1142098 #1142254 #1143045
#1143189 #1143191 #1144257 #1144273 #1144288
Cross- CVE-2018-20855 CVE-2019-1125 CVE-2019-11810
CVE-2019-13631 CVE-2019-13648 CVE-2019-14283
CVE-2019-14284
Affected Products:
SUSE Linux Enterprise Server for SAP 12-SP1
SUSE Linux Enterprise Server 12-SP1-LTSS
SUSE Linux Enterprise Module for Public Cloud 12
https://www.suse.com/security/cve/CVE-2018-20855.html
https://www.suse.com/security/cve/CVE-2019-1125.html
https://www.suse.com/security/cve/CVE-2019-11810.html
https://www.suse.com/security/cve/CVE-2019-13631.html
https://www.suse.com/security/cve/CVE-2019-13648.html
https://www.suse.com/security/cve/CVE-2019-14283.html
https://www.suse.com/security/c...
Read the Full Advisory