Security update for the Linux Kernel
The SUSE Linux Enterprise 12 SP2 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-20784: Fixed a denial of service (infinite loop in update_blocked_averages) by mishandled leaf cfs_rq in kernel/sched/fair.c (bsc#1126703). - CVE-2018-3639: Fixed Speculative Store Bypass aka 'Memory Disambiguation' (bsc#1087082). - CVE-2022-40982: Fixed transient execution attack called 'Gather Data Sampling' (bsc#1206418). - CVE-2023-0459: Fixed information leak in __uaccess_begin_nospec (bsc#1211738). - CVE-2023-1637: Fixed vulnerability that could lead to unauthorized access to CPU memory after resuming CPU from suspend-to-RAM (bsc#1209779). - CVE-2023-20569: Fixed side channel attack ‘Inception’ or ‘RAS Poisoning’ (bsc#1213287). - CVE-2023-20593: Fixed a ZenBleed issue in 'Zen 2' CPUs that could allow an attacker to potentially access sensitive information (bsc#1213286). - CVE-2023-2985: Fixed an use-after-free vulnerability in hfsplus_put_super in fs/hfsplus/super.c that could allow a local user to cause a denial of service (bsc#1211867). - CVE-2023-3106: Fixed crash in XFRM_MSG_GETSA netlink handler (bsc#1213251). - CVE-2023-3268: Fixed an out of bounds memory access flaw in relay_file_read_start_pos in the relayfs (bsc#1212502). - CVE-2023-35001: Fixed an out-of-bounds memory access flaw in nft_byteorder that could allow a local attacker to escalate their privilege (bsc#1213059). - CVE-2023-3567: Fixed a use-after-free in vcs_read in drivers/tty/vt/vc_screen.c (bsc#1213167). - CVE-2023-3611: Fixed an out-of-bounds write in net/sched sch_qfq(bsc#1213585). - CVE-2023-3776: Fixed improper refcount update in cls_fw leads to use-after-free (bsc#1213588). The following non-security bugs were fixed: - net/sched: sch_qfq: refactor parsing of netlink parameters (bsc#1213585). - ubi: Fix failure attaching when vid_hdr offset equals to (sub)page size (bsc#1210584). - ubi: ensure that VID header offset + VID header size <= alloc, size (bsc#1210584). - x86: Treat R_X86_64_PLT32 as R_X86_64_PC32 (git-fixes) No it's not git-fixes it's used to make sle12-sp2 compile with newer toolchain to make the life of all the poor souls maintaining this ancient kernel on their modern machines, a little bit easier....
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The SUSE Linux Enterprise 12 SP2 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-20784: Fixed a denial of service (infinite loop in update_blocked_averages) by mishandled leaf cfs_rq in kernel/sched/fair.c (bsc#1126703). - CVE-2018-3639: Fixed Speculative Store Bypass aka 'Memory Disambiguation' (bsc#1087082). - CVE-2022-40982: Fixed transient execution attack called 'Gather Data Sampling' (bsc#1206418). - CVE-2023-0459: Fixed information leak in __uaccess_begin_nospec (bsc#1211738). - CVE-2023-1637: Fixed vulnerability that could lead to unauthorized access to CPU memory after resuming CPU from suspend-to-RAM (bsc#1209779). - CVE-2023-20569: Fixed side channel attack ‘Inception’ or ‘RAS Poisoning’ (bsc#1213287). - CVE-2023-20593: Fixed a ZenBleed issue in 'Zen 2' CPUs that could allow an attacker to potentially access sensitive information (bsc#1213286). - CVE-2023-2985: Fixed an use-after-free vulnerability in hfsplus_put_super in fs/hfsplus/super.c that could allow a local user to cause a denial of service (bsc#1211867). - CVE-2023-3106: Fixed crash in XFRM_MSG_GETSA netlink handler (bsc#1213251). - CVE-2023-3268: Fixed an out of bounds memory access flaw in relay_file_read_start_pos in the relayfs (bsc#1212502). - CVE-2023-35001: Fixed an out-of-bounds memory access flaw in nft_byteorder that could allow a local attacker to escalate their privilege (bsc#1213059). - CVE-2023-3567: Fixed a use-after-free in vcs_read in drivers/tty/vt/vc_screen.c (bsc#1213167). - CVE-2023-3611: Fixed an out-of-bounds write in net/sched sch_qfq(bsc#1213585). - CVE-2023-3776: Fixed improper refcount update in cls_fw leads to use-after-free (bsc#1213588). The following non-security bugs were fixed: - net/sched: sch_qfq: refactor parsing of netlink parameters (bsc#1213585). - ubi: Fix failure attaching when vid_hdr offset equals to (sub)page size (bsc#1210584). - ubi: ensure that VID header offset + VID header size <= alloc, size (bsc#1210584). - x86: Treat R_X86_64_PLT32 as R_X86_64_PC32 (git-fixes) No it's not git-fixes it's used to make sle12-sp2 compile with newer toolchain to make the life of all the poor souls maintaining this ancient kernel on their modern machines, a little bit easier....
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1087082
- https://bugzilla.suse.com/1126703
- https://bugzilla.suse.com/1206418
- https://bugzilla.suse.com/1207561
- https://bugzilla.suse.com/1209779
- https://bugzilla.suse.com/1210584
- https://bugzilla.suse.com/1211738
- https://bugzilla.suse.com/1211867
- https://bugzilla.suse.com/1212502
- https://bugzilla.suse.com/1213059
- https://bugzilla.suse.com/1213167
- https://bugzilla.suse.com/1213251
- https://bugzilla.suse.com/1213286
- https://bugzilla.suse.com/1213287
- https://bugzilla.suse.com/1213585
- https://bugzilla.suse.com/1213588
- https://www.suse.com/security/cve/CVE-2018-20784
- https://www.suse.com/security/cve/CVE-2018-3639
- https://www.suse.com/security/cve/CVE-2022-40982
- https://www.suse.com/security/cve/CVE-2023-0459
- https://www.suse.com/security/cve/CVE-2023-1637
- https://www.suse.com/security/cve/CVE-2023-20569
- https://www.suse.com/security/cve/CVE-2023-20593
- https://www.suse.com/security/cve/CVE-2023-2985
- https://www.suse.com/security/cve/CVE-2023-3106
- https://www.suse.com/security/cve/CVE-2023-3268
- https://www.suse.com/security/cve/CVE-2023-35001
- https://www.suse.com/security/cve/CVE-2023-3567
- https://www.suse.com/security/cve/CVE-2023-3611
- https://www.suse.com/security/cve/CVE-2023-3776
- https://www.suse.com/support/update/announcement/2023/suse-su-20233324-1/