Anfälligkeitssuche        Suche in 211766 CVE Beschreibungen
und 97459 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:
Kategorie:SuSE Local Security Checks
Titel:SUSE: Security Advisory (SUSE-SU-2019:1244-1)
Zusammenfassung:The remote host is missing an update for the 'Linux Kernel' package(s) announced via the SUSE-SU-2019:1244-1 advisory.
The remote host is missing an update for the 'Linux Kernel' package(s) announced via the SUSE-SU-2019:1244-1 advisory.

Vulnerability Insight:
The SUSE Linux Enterprise 15 kernel was updated to receive various security and bugfixes.

Four new speculative execution information leak issues have been identified in Intel CPUs. (bsc#1111331)

CVE-2018-12126: Microarchitectural Store Buffer Data Sampling (MSBDS)

CVE-2018-12127: Microarchitectural Fill Buffer Data Sampling (MFBDS)

CVE-2018-12130: Microarchitectural Load Port Data Samling (MLPDS)

CVE-2019-11091: Microarchitectural Data Sampling Uncacheable Memory

This kernel update contains software mitigations for these issues, which also utilize CPU microcode updates shipped in parallel.

For more information on this set of vulnerabilities, check out [link moved to references]

The following security issues were fixed:

CVE-2018-16880: A flaw was found in the handle_rx() function in the
vhost_net driver. A malicious virtual guest, under specific conditions,
could trigger an out-of-bounds write in a kmalloc-8 slab on a virtual
host which may lead to a kernel memory corruption and a system panic.
Due to the nature of the flaw, privilege escalation cannot be fully
ruled out. (bnc#1122767).

CVE-2019-3882: A flaw was found in the vfio interface implementation
that permitted violation of the user's locked memory limit. If a device
is bound to a vfio driver, such as vfio-pci, and the local attacker is
administratively granted ownership of the device, it may cause a system
memory exhaustion and thus a denial of service (DoS). (bnc#1131416

CVE-2019-9003: Attackers could trigger a
drivers/char/ipmi/ipmi_msghandler.c use-after-free and OOPS by arranging
for certain simultaneous execution of the code, as demonstrated by a
'service ipmievd restart' loop (bnc#1126704).

CVE-2019-9500: A brcmfmac heap buffer overflow in brcmf_wowl_nd_results
was fixed. (bnc#1132681).

CVE-2019-9503: A brcmfmac frame validation bypass was fixed.

The following non-security bugs were fixed:

9p: do not trust pdu content for stat item size (bsc#1051510).

acpi: acpi_pad: Do not launch acpi_pad threads on idle cpus

acpi, nfit: Prefer _DSM over _LSR for namespace label reads

acpi / SBS: Fix GPE storm on recent MacBookPro's (bsc#1051510).

alsa: core: Fix card races between register and disconnect (bsc#1051510).

alsa: echoaudio: add a check for ioremap_nocache (bsc#1051510).

alsa: firewire: add const qualifier to identifiers for read-only symbols

alsa: firewire-motu: add a flag for AES/EBU on XLR interface

alsa: firewire-motu: add specification flag for position of flag for
MIDI messages (bsc#1051510).

alsa: firewire-motu: add support for MOTU Audio Express (bsc#1051510).

alsa: firewire-motu: add support for Motu Traveler (bsc#1051510).

alsa: firewire-motu: use 'version' field of unit directory to identify
model (bsc#1051510).

alsa: hda - add Lenovo I... [Please see the references for more information on the vulnerabilities]

Affected Software/OS:
'Linux Kernel' package(s) on SUSE Linux Enterprise Workstation Extension 15, SUSE Linux Enterprise Module for Open Buildservice Development Tools 15, SUSE Linux Enterprise Module for Live Patching 15, SUSE Linux Enterprise Module for Legacy Software 15, SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Module for Basesystem 15, SUSE Linux Enterprise High Availability 15

Please install the updated package(s).

CVSS Score:

CVSS Vector:

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2019-3882
Bugtraq: 20190813 [SECURITY] [DSA 4497-1] linux security update (Google Search)
Debian Security Information: DSA-4497 (Google Search)
RedHat Security Advisories: RHSA-2019:2029
RedHat Security Advisories: RHSA-2019:2043
RedHat Security Advisories: RHSA-2019:3309
RedHat Security Advisories: RHSA-2019:3517
SuSE Security Announcement: openSUSE-SU-2019:1404 (Google Search)
SuSE Security Announcement: openSUSE-SU-2019:1407 (Google Search)
SuSE Security Announcement: openSUSE-SU-2019:1479 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2019-9003
BugTraq ID: 107145
Common Vulnerability Exposure (CVE) ID: CVE-2019-9500
Common Vulnerability Exposure (CVE) ID: CVE-2019-9503
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

Dies ist nur einer von 97459 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.

© 1998-2021 E-Soft Inc. Alle Rechte vorbehalten.