Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2018:2473-1

Опубликовано: 21 авг. 2018
Источник: suse-cvrf

Описание

Security update for the Linux Kernel (Live Patch 2 for SLE 15)

This update for the Linux Kernel 4.12.14-25_6 fixes one issue.

The following security issue was fixed:

  • CVE-2018-3646: Local attackers in virtualized guest systems could use speculative code patterns on hyperthreaded processors to read data present in the L1 Datacache used by other hyperthreads on the same CPU core, potentially leaking sensitive data, even from other virtual machines or the host system (bsc#1099306).

Список пакетов

SUSE Linux Enterprise Live Patching 15
kernel-livepatch-4_12_14-25_6-default-2-2.1

Описание

Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access with guest OS privilege via a terminal page fault and a side-channel analysis.


Затронутые продукты
SUSE Linux Enterprise Live Patching 15:kernel-livepatch-4_12_14-25_6-default-2-2.1

Ссылки
Уязвимость SUSE-SU-2018:2473-1