Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

openSUSE 12.3: 2014:0856-1 Critical Vulnerabilities in Kernel Services

opensuse
Calendar Grey July 1, 2014
Dist Opensuse Esm H88
This critical Fedora upgrade resolves kernel vulnerabilities and numerous bug corrections, guaranteeing operational reliability and security.
An update that solves 7 vulnerabilities and has one errata An update that solves 7 vulnerabilities and has one errata An update that solves 7 vulnerabilities and has one errata is ...

Description

The Linux kernel was updated to fix security issues and bugs:

Security issues fixed: CVE-2014-3153: The futex_requeue function in

kernel/futex.c in the Linux kernel did not ensure that calls have two

different futex addresses, which allowed local users to gain privileges

via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter

modification.

CVE-2014-0077: drivers/vhost/net.c in the Linux kernel, when mergeable

buffers are disabled, did not properly validate packet lengths, which

allowed guest OS users to cause a denial of service (memory corruption and

host OS crash) or possibly gain privileges on the host OS via crafted

packets, related to the handle_rx and get_rx_bufs functions.

CVE-2014-0055: The get_rx_bufs function in drivers/vhost/net.c in the

vhost-net subsystem in the Linux kernel package did not properly handle

vhost_get_vq_desc errors, which allowed guest OS users to cause a denial

of service (host OS crash) via...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 12.3:

zypper in -t patch openSUSE-2014-451

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 12.3 (i586 x86_64):

kernel-default-3.7.10-1.36.1

kernel-default-base-3.7.10-1.36.1

kernel-default-base-debuginfo-3.7.10-1.36.1

kernel-default-debuginfo-3.7.10-1.36.1

kernel-default-debugsource-3.7.10-1.36.1

kernel-default-devel-3.7.10-1.36.1

kernel-default-devel-debuginfo-3.7.10-1.36.1

kernel-syms-3.7.10-1.36.1

- openSUSE 12.3 (i686 x86_64):

kernel-debug-3.7.10-1.36.1

kernel-debug-base-3.7.10-1.36.1

kernel-debug-base-debuginfo-3.7.10-1.36.1

kernel-debug-debuginfo-3.7.10-1.36.1

kernel-debug-debugsource-3.7.10-1.36.1

kernel-debug-devel-3.7.10-1.36.1

kernel-debug-devel-debuginfo-3.7.10-1.36.1

kernel-desktop-3.7.10-1.36.1

kernel-desktop-base-3.7.10-1.36.1

kernel-desktop-base-debuginfo-3.7.10-1.36.1

kernel-desktop-debuginfo-3.7.10-1.36.1

kernel-desktop-debugsource-3.7.10-1.36.1

kernel-desktop-devel-3.7.10-1.36.1

kernel-desktop-devel-debuginfo-3.7.10-1.36.1

kernel-ec2-3.7.10-1.36.1

kernel-ec2-base-3.7.10-1.36.1

kernel-ec2-base-debuginfo-3.7.10-1.36.1

kernel-ec2-debuginfo-3.7.10-1.36.1

kernel-ec2-debugsource-...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2013-7339.html

https://www.suse.com/security/cve/CVE-2014-0055.html

https://www.suse.com/security/cve/CVE-2014-0077.html

https://www.suse.com/security/cve/CVE-2014-2678.html

https://www.suse.com/security/cve/CVE-2014-2851.html

https://www.suse.com/security/cve/CVE-2014-3122.html

https://www.suse.com/security/cve/CVE-2014-3153.html

https://login.microfocus.com/nidp/app/login?sid=0

https://login.microfocus.com/nidp/app/login?sid=0

https://login.microfocus.com/nidp/app/login?sid=0

https://login.microfocus.com/nidp/app/login?sid=0

https://login.microfocus.com/nidp/app/login?sid=0

https://login.microfocus.com/nidp/app/login?sid=0

https://login.microfocus.com/nidp/app/login?sid=0

https://login.microfocus.com/nidp/app/login?sid=0

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2014:0856-1
Rating: important
Affected Products: openSUSE 12.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here