FlawAtlas
Search the atlas
SUSE-SU-2018:1849-1 Not scored

Security update for the Linux Kernel

The SUSE Linux Enterprise 11 SP3 LTSS kernel was updated to receive various security and bugfixes. The following security bug was fixed: - CVE-2018-3665: Prevent disclosure of FPU registers (including XMM and AVX registers) between processes. These registers might contain encryption keys when doing SSE accelerated AES enc/decryption (bsc#1087086) The following non-security bugs were fixed: - KVM: x86: Sync back MSR_IA32_SPEC_CTRL to VCPU data structure (bsc#1096242, bsc#1096281). - Xen counterparts of eager FPU implementation. - x86/boot: Fix early command-line parsing when partial word matches (bsc#1096140). - x86/bugs: spec_ctrl must be cleared from cpu_caps_set when being disabled (bsc#1096140). - xen/x86/CPU: Check speculation control CPUID bit (bsc#1068032). - xen/x86/CPU: Sync CPU feature flags late (bsc#1075994 bsc#1075091). - xen/x86/cpu: Factor out application of forced CPU caps (bsc#1075994 bsc#1075091). - xen/x86/cpu: Fix bootup crashes by sanitizing the argument of the 'clearcpuid=' command-line option (bsc#1065600). - xen/x86/entry/64: Do not use IST entry for #BP stack (bsc#1087088). - xen/x86/entry: Use IBRS on entry to kernel space (bsc#1068032). - xen/x86/idle: Toggle IBRS when going idle (bsc#1068032). - xen/x86/kaiser: Move feature detection up (bsc#1068032).

Exploit probability Not scored
Published June 29, 2018
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Point of Sale 11 SP3 kernel-default
SUSE:Linux Enterprise Point of Sale 11 SP3 kernel-ec2
SUSE:Linux Enterprise Point of Sale 11 SP3 kernel-pae
SUSE:Linux Enterprise Point of Sale 11 SP3 kernel-source
SUSE:Linux Enterprise Point of Sale 11 SP3 kernel-syms
SUSE:Linux Enterprise Point of Sale 11 SP3 kernel-trace
SUSE:Linux Enterprise Point of Sale 11 SP3 kernel-xen
SUSE:Linux Enterprise Server 11 SP3-LTSS kernel-bigsmp
SUSE:Linux Enterprise Server 11 SP3-LTSS kernel-default
SUSE:Linux Enterprise Server 11 SP3-LTSS kernel-ec2
SUSE:Linux Enterprise Server 11 SP3-LTSS kernel-pae
SUSE:Linux Enterprise Server 11 SP3-LTSS kernel-source
SUSE:Linux Enterprise Server 11 SP3-LTSS kernel-syms
SUSE:Linux Enterprise Server 11 SP3-LTSS kernel-trace
SUSE:Linux Enterprise Server 11 SP3-LTSS kernel-xen

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2018:1849-1

The SUSE Linux Enterprise 11 SP3 LTSS kernel was updated to receive various security and bugfixes. The following security bug was fixed: - CVE-2018-3665: Prevent disclosure of FPU registers (including XMM and AVX registers) between processes. These registers might contain encryption keys when doing SSE accelerated AES enc/decryption (bsc#1087086) The following non-security bugs were fixed: - KVM: x86: Sync back MSR_IA32_SPEC_CTRL to VCPU data structure (bsc#1096242, bsc#1096281). - Xen counterparts of eager FPU implementation. - x86/boot: Fix early command-line parsing when partial word matches (bsc#1096140). - x86/bugs: spec_ctrl must be cleared from cpu_caps_set when being disabled (bsc#1096140). - xen/x86/CPU: Check speculation control CPUID bit (bsc#1068032). - xen/x86/CPU: Sync CPU feature flags late (bsc#1075994 bsc#1075091). - xen/x86/cpu: Factor out application of forced CPU caps (bsc#1075994 bsc#1075091). - xen/x86/cpu: Fix bootup crashes by sanitizing the argument of the 'clearcpuid=' command-line option (bsc#1065600). - xen/x86/entry/64: Do not use IST entry for #BP stack (bsc#1087088). - xen/x86/entry: Use IBRS on entry to kernel space (bsc#1068032). - xen/x86/idle: Toggle IBRS when going idle (bsc#1068032). - xen/x86/kaiser: Move feature detection up (bsc#1068032).

View original source

05 / REFERENCES

Further evidence