Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2018:2394-1

Опубликовано: 16 авг. 2018
Источник: suse-cvrf

Описание

Security update for kgraft

This update for kgraft fixes the following issues:

Add script for disabling SMT to help with the mitigation of the 'L1 Terminal Fault' issue (CVE-2018-3646 bsc#1099306)

The script is called 'klp-kvm-l1tf-ctrl-smt' and is used for enabling or disabling SMT to mitigate the issue when this administrative decision is taken.

Disabling SMT:

klp-kvm-l1tf-ctrl-smt -d

Enabling SMT:

klp-kvm-l1tf-ctrl-smt -e

Список пакетов

SUSE Linux Enterprise Live Patching 12
kgraft-1.0-23.9.1
kgraft-devel-1.0-23.9.1
SUSE Linux Enterprise Live Patching 12 SP3
kgraft-1.0-23.9.1

Описание

Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access with guest OS privilege via a terminal page fault and a side-channel analysis.


Затронутые продукты
SUSE Linux Enterprise Live Patching 12 SP3:kgraft-1.0-23.9.1
SUSE Linux Enterprise Live Patching 12:kgraft-1.0-23.9.1
SUSE Linux Enterprise Live Patching 12:kgraft-devel-1.0-23.9.1

Ссылки