SUSE Security Update: Security update for dpdk
______________________________________________________________________________

Announcement ID:    SUSE-SU-2019:3032-1
Rating:             moderate
References:         #1156146 
Cross-References:   CVE-2019-14818
Affected Products:
                    SUSE Linux Enterprise Software Development Kit 12-SP4
                    SUSE Linux Enterprise Server 12-SP4
______________________________________________________________________________

   An update that fixes one vulnerability is now available.

Description:

   This update for dpdk to version 17.11.7 fixes the following issues:

   - CVE-2019-14818: Fixed a memory leak vulnerability caused by a malicious
     container may lead to to denial of service (bsc#1156146).


Patch Instructions:

   To install this SUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Software Development Kit 12-SP4:

      zypper in -t patch SUSE-SLE-SDK-12-SP4-2019-3032=1

   - SUSE Linux Enterprise Server 12-SP4:

      zypper in -t patch SUSE-SLE-SERVER-12-SP4-2019-3032=1



Package List:

   - SUSE Linux Enterprise Software Development Kit 12-SP4 (aarch64 ppc64le x86_64):

      dpdk-debuginfo-17.11.7-5.3.2
      dpdk-debugsource-17.11.7-5.3.2
      dpdk-devel-17.11.7-5.3.2
      dpdk-devel-debuginfo-17.11.7-5.3.2

   - SUSE Linux Enterprise Software Development Kit 12-SP4 (aarch64):

      dpdk-thunderx-debuginfo-17.11.7-5.3.2
      dpdk-thunderx-debugsource-17.11.7-5.3.2
      dpdk-thunderx-devel-17.11.7-5.3.2
      dpdk-thunderx-devel-debuginfo-17.11.7-5.3.2

   - SUSE Linux Enterprise Server 12-SP4 (aarch64 ppc64le x86_64):

      dpdk-17.11.7-5.3.2
      dpdk-debuginfo-17.11.7-5.3.2
      dpdk-debugsource-17.11.7-5.3.2
      dpdk-tools-17.11.7-5.3.2
      dpdk-tools-debuginfo-17.11.7-5.3.2
      libdpdk-17_11-17.11.7-5.3.2
      libdpdk-17_11-debuginfo-17.11.7-5.3.2

   - SUSE Linux Enterprise Server 12-SP4 (aarch64):

      dpdk-thunderx-17.11.7-5.3.2
      dpdk-thunderx-debuginfo-17.11.7-5.3.2
      dpdk-thunderx-debugsource-17.11.7-5.3.2
      dpdk-thunderx-kmp-default-17.11.7_k4.12.14_95.37-5.3.2
      dpdk-thunderx-kmp-default-debuginfo-17.11.7_k4.12.14_95.37-5.3.2

   - SUSE Linux Enterprise Server 12-SP4 (x86_64):

      dpdk-kmp-default-17.11.7_k4.12.14_95.37-5.3.2
      dpdk-kmp-default-debuginfo-17.11.7_k4.12.14_95.37-5.3.2


References:

   https://www.suse.com/security/cve/CVE-2019-14818.html
   https://bugzilla.suse.com/1156146

_______________________________________________
sle-security-updates mailing list
sle-security-updates@lists.suse.com
http://lists.suse.com/mailman/listinfo/sle-security-updates

SUSE: 2019:3032-1 moderate: dpdk

November 21, 2019
An update that fixes one vulnerability is now available

Summary

This update for dpdk to version 17.11.7 fixes the following issues: - CVE-2019-14818: Fixed a memory leak vulnerability caused by a malicious container may lead to to denial of service (bsc#1156146). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP4: zypper in -t patch SUSE-SLE-SDK-12-SP4-2019-3032=1 - SUSE Linux Enterprise Server 12-SP4: zypper in -t patch SUSE-SLE-SERVER-12-SP4-2019-3032=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP4 (aarch64 ppc64le x86_64): dpdk-debuginfo-17.11.7-5.3.2 dpdk-debugsource-17.11.7-5.3.2 dpdk-devel-17.11.7-5.3.2 dpdk-devel-debuginfo-17.11.7-5.3.2 - SUSE Linux Enterprise Software Development Kit 12-SP4 (aarch64): dpdk-thunderx-debuginfo-17.11.7-5.3.2 dpdk-thunderx-debugsource-17.11.7-5.3.2 dpdk-thunderx-devel-17.11.7-5.3.2 dpdk-thunderx-devel-debuginfo-17.11.7-5.3.2 - SUSE Linux Enterprise Server 12-SP4 (aarch64 ppc64le x86_64): dpdk-17.11.7-5.3.2 dpdk-debuginfo-17.11.7-5.3.2 dpdk-debugsource-17.11.7-5.3.2 dpdk-tools-17.11.7-5.3.2 dpdk-tools-debuginfo-17.11.7-5.3.2 libdpdk-17_11-17.11.7-5.3.2 libdpdk-17_11-debuginfo-17.11.7-5.3.2 - SUSE Linux Enterprise Server 12-SP4 (aarch64): dpdk-thunderx-17.11.7-5.3.2 dpdk-thunderx-debuginfo-17.11.7-5.3.2 dpdk-thunderx-debugsource-17.11.7-5.3.2 dpdk-thunderx-kmp-default-17.11.7_k4.12.14_95.37-5.3.2 dpdk-thunderx-kmp-default-debuginfo-17.11.7_k4.12.14_95.37-5.3.2 - SUSE Linux Enterprise Server 12-SP4 (x86_64): dpdk-kmp-default-17.11.7_k4.12.14_95.37-5.3.2 dpdk-kmp-default-debuginfo-17.11.7_k4.12.14_95.37-5.3.2

References

#1156146

Cross- CVE-2019-14818

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP4

SUSE Linux Enterprise Server 12-SP4

https://www.suse.com/security/cve/CVE-2019-14818.html

https://bugzilla.suse.com/1156146

Severity
Announcement ID: SUSE-SU-2019:3032-1
Rating: moderate

Related News