SUSE-SU-2019:1882-1

    Dashboard / Vulnerabilities / SUSE-SU-2019:1882-1

    SUSE-SU-2019:1882-1

    Published: 18 Jul 2019Last Modified: 4 Feb 2026

    Summary: Security update for the Linux Kernel (Live Patch 10 for SLE 15)

    Details: This update for the Linux Kernel 4.12.14-150_17 fixes several issues. The following security issues were fixed: - CVE-2019-11477: Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. (bsc#1137586) - CVE-2019-11478: Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. (bsc#1137586) - CVE-2019-3846: A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malicious wireless network (bsc#1136424). This update contains a regression fix for CVE-2019-11477 and CVE-2019-11478 (bsc#1140747).

    Affected packages

    Package

    Name: kernel-livepatch-SLE15_Update_1

    Purl: pkg:rpm/suse/kernel-livepatch-SLE15_Update_1&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -11-2.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2019:1882-1 | CVE-DB