Description: | Summary: The remote host is missing an update for the 'kernel' package(s) announced via the openSUSE-SU-2018:2242-1 advisory.
Vulnerability Insight: The openSUSE Leap 15.0 kernel was updated to receive various security and bugfixes.
The following security bugs were fixed:
- CVE-2018-5390 aka 'SegmentSmack': A remote attacker even with relatively low bandwidth could have caused lots of CPU usage by triggering the worst case scenario during IP and/or TCP fragment reassembly (bsc#1102340)
- CVE-2017-18344: The timer_create syscall implementation in kernel/time/posix-timers.c in the Linux kernel doesn't properly validate the sigevent- sigev_notify field, which leads to out-of-bounds access in the show_timer function (called when /proc/$PID/timers is read). This allowed userspace applications to read arbitrary kernel memory (on a kernel built with CONFIG_POSIX_TIMERS and CONFIG_CHECKPOINT_RESTORE) (bnc#1102851).
The following non-security bugs were fixed:
- acpi, APEI, EINJ: Subtract any matching Register Region from Trigger resources (bsc#1051510).
- acpi/nfit: fix cmd_rc for acpi_nfit_ctl to always return a value (bsc#1051510).
- acpi, nfit: Fix scrub idle detection (bsc#1094119).
- acpi / processor: Finish making acpi_processor_ppc_has_changed() void (bsc#1051510).
- ahci: Disable LPM on Lenovo 50 series laptops with a too old BIOS (bsc#1051510).
- alsa: emu10k1: add error handling for snd_ctl_add (bsc#1051510).
- alsa: emu10k1: Rate-limit error messages about page errors (bsc#1051510).
- alsa: fm801: add error handling for snd_ctl_add (bsc#1051510).
- alsa: hda: add mute led support for HP ProBook 455 G5 (bsc#1051510).
- alsa: hda - Handle pm failure during hotplug (bsc#1051510).
- alsa: hda/realtek - Add Panasonic CF-SZ6 headset jack quirk (bsc#1051510).
- alsa: hda/realtek - two more lenovo models need fixup of MIC_LOCATION (bsc#1051510).
- alsa: hda/realtek - Yet another Clevo P950 quirk entry (bsc#1101143).
- alsa: rawmidi: Change resized buffers atomically (bsc#1051510).
- alsa: usb-audio: Apply rate limit to warning messages in URB complete callback (bsc#1051510).
- alx: take rtnl before calling __alx_open from resume (bsc#1051510).
- arm64: Correct type for PUD macros (bsc#1103723).
- arm64: Disable unhandled signal log messages by default (bsc#1103724).
- arm64: kpti: Use early_param for kpti= command-line option (bsc#1103220).
- arm64: KVM: fix VTTBR_BADDR_MASK BUG_ON off-by-one (bsc#1103725).
- arm64: mm: Fix set_memory_valid() declaration (bsc#1103726).
- arm64: perf: correct PMUVer probing (bsc#1103727).
- arm64: ptrace: Avoid setting compat FPR to garbage if get_user fails (bsc#1103728).
- arm64: spinlock: Fix theoretical tryl ...
Description truncated, please see the referenced URL(s) for more information.
Affected Software/OS: the on openSUSE Leap 15.0.
Solution: Please install the updated package(s).
CVSS Score: 7.8
CVSS Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C
|