openSUSE Security Update: kernel update fixes local privilege escalation and a regression causing a crash if IPsec peer is unavailable
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2014:0878-1
Rating:             important
References:         #877775 #880892 
Cross-References:   CVE-2014-3153
Affected Products:
                    openSUSE 11.4
______________________________________________________________________________

   An update that solves one vulnerability and has one errata
   is now available.

Description:

   kernel update for Evergreen 11.4 fixes local privilege escalation in futex
   code (bnc#880892 / CVE-2014-3153) and a regression causing a crash if
   IPsec peer is unavailable


Patch Instructions:

   To install this openSUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - openSUSE 11.4:

      zypper in -t patch 2014-69

   To bring your system up-to-date, use "zypper patch".


Package List:

   - openSUSE 11.4 (i586 x86_64):

      kernel-debug-3.0.101-87.1
      kernel-debug-base-3.0.101-87.1
      kernel-debug-base-debuginfo-3.0.101-87.1
      kernel-debug-debuginfo-3.0.101-87.1
      kernel-debug-debugsource-3.0.101-87.1
      kernel-debug-devel-3.0.101-87.1
      kernel-debug-devel-debuginfo-3.0.101-87.1
      kernel-debug-hmac-3.0.101-87.1
      kernel-default-3.0.101-87.1
      kernel-default-base-3.0.101-87.1
      kernel-default-base-debuginfo-3.0.101-87.1
      kernel-default-debuginfo-3.0.101-87.1
      kernel-default-debugsource-3.0.101-87.1
      kernel-default-devel-3.0.101-87.1
      kernel-default-devel-debuginfo-3.0.101-87.1
      kernel-default-hmac-3.0.101-87.1
      kernel-desktop-3.0.101-87.1
      kernel-desktop-base-3.0.101-87.1
      kernel-desktop-base-debuginfo-3.0.101-87.1
      kernel-desktop-debuginfo-3.0.101-87.1
      kernel-desktop-debugsource-3.0.101-87.1
      kernel-desktop-devel-3.0.101-87.1
      kernel-desktop-devel-debuginfo-3.0.101-87.1
      kernel-desktop-hmac-3.0.101-87.1
      kernel-ec2-3.0.101-87.1
      kernel-ec2-base-3.0.101-87.1
      kernel-ec2-base-debuginfo-3.0.101-87.1
      kernel-ec2-debuginfo-3.0.101-87.1
      kernel-ec2-debugsource-3.0.101-87.1
      kernel-ec2-devel-3.0.101-87.1
      kernel-ec2-devel-debuginfo-3.0.101-87.1
      kernel-ec2-extra-3.0.101-87.1
      kernel-ec2-extra-debuginfo-3.0.101-87.1
      kernel-ec2-hmac-3.0.101-87.1
      kernel-source-3.0.101-87.1
      kernel-source-vanilla-3.0.101-87.1
      kernel-syms-3.0.101-87.1
      kernel-trace-3.0.101-87.1
      kernel-trace-base-3.0.101-87.1
      kernel-trace-base-debuginfo-3.0.101-87.1
      kernel-trace-debuginfo-3.0.101-87.1
      kernel-trace-debugsource-3.0.101-87.1
      kernel-trace-devel-3.0.101-87.1
      kernel-trace-devel-debuginfo-3.0.101-87.1
      kernel-trace-hmac-3.0.101-87.1
      kernel-vanilla-3.0.101-87.1
      kernel-vanilla-base-3.0.101-87.1
      kernel-vanilla-base-debuginfo-3.0.101-87.1
      kernel-vanilla-debuginfo-3.0.101-87.1
      kernel-vanilla-debugsource-3.0.101-87.1
      kernel-vanilla-devel-3.0.101-87.1
      kernel-vanilla-devel-debuginfo-3.0.101-87.1
      kernel-vanilla-hmac-3.0.101-87.1
      kernel-xen-3.0.101-87.1
      kernel-xen-base-3.0.101-87.1
      kernel-xen-base-debuginfo-3.0.101-87.1
      kernel-xen-debuginfo-3.0.101-87.1
      kernel-xen-debugsource-3.0.101-87.1
      kernel-xen-devel-3.0.101-87.1
      kernel-xen-devel-debuginfo-3.0.101-87.1
      kernel-xen-hmac-3.0.101-87.1
      preload-1.2-6.65.1
      preload-debuginfo-1.2-6.65.1
      preload-debugsource-1.2-6.65.1
      preload-kmp-default-1.2_3.0.101_87-6.65.1
      preload-kmp-default-debuginfo-1.2_3.0.101_87-6.65.1
      preload-kmp-desktop-1.2_3.0.101_87-6.65.1
      preload-kmp-desktop-debuginfo-1.2_3.0.101_87-6.65.1

   - openSUSE 11.4 (noarch):

      kernel-docs-3.0.101-87.2

   - openSUSE 11.4 (i586):

      kernel-pae-3.0.101-87.1
      kernel-pae-base-3.0.101-87.1
      kernel-pae-base-debuginfo-3.0.101-87.1
      kernel-pae-debuginfo-3.0.101-87.1
      kernel-pae-debugsource-3.0.101-87.1
      kernel-pae-devel-3.0.101-87.1
      kernel-pae-devel-debuginfo-3.0.101-87.1
      kernel-pae-hmac-3.0.101-87.1
      kernel-vmi-3.0.101-87.1
      kernel-vmi-base-3.0.101-87.1
      kernel-vmi-base-debuginfo-3.0.101-87.1
      kernel-vmi-debuginfo-3.0.101-87.1
      kernel-vmi-debugsource-3.0.101-87.1
      kernel-vmi-devel-3.0.101-87.1
      kernel-vmi-devel-debuginfo-3.0.101-87.1
      kernel-vmi-hmac-3.0.101-87.1


References:

   http://support.novell.com/security/cve/CVE-2014-3153.html
   https://bugzilla.novell.com/877775
   https://bugzilla.novell.com/880892

-- 

openSUSE: 2014:0878-1: important: kernel update fixes local privilege escalation and a regression causing a crash if IPsec peer is unavailable

July 8, 2014
An update that solves one vulnerability and has one errata is now available.

Description

kernel update for Evergreen 11.4 fixes local privilege escalation in futex code (bnc#880892 / CVE-2014-3153) and a regression causing a crash if IPsec peer is unavailable

 

Patch

Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 11.4: zypper in -t patch 2014-69 To bring your system up-to-date, use "zypper patch".


Package List

- openSUSE 11.4 (i586 x86_64): kernel-debug-3.0.101-87.1 kernel-debug-base-3.0.101-87.1 kernel-debug-base-debuginfo-3.0.101-87.1 kernel-debug-debuginfo-3.0.101-87.1 kernel-debug-debugsource-3.0.101-87.1 kernel-debug-devel-3.0.101-87.1 kernel-debug-devel-debuginfo-3.0.101-87.1 kernel-debug-hmac-3.0.101-87.1 kernel-default-3.0.101-87.1 kernel-default-base-3.0.101-87.1 kernel-default-base-debuginfo-3.0.101-87.1 kernel-default-debuginfo-3.0.101-87.1 kernel-default-debugsource-3.0.101-87.1 kernel-default-devel-3.0.101-87.1 kernel-default-devel-debuginfo-3.0.101-87.1 kernel-default-hmac-3.0.101-87.1 kernel-desktop-3.0.101-87.1 kernel-desktop-base-3.0.101-87.1 kernel-desktop-base-debuginfo-3.0.101-87.1 kernel-desktop-debuginfo-3.0.101-87.1 kernel-desktop-debugsource-3.0.101-87.1 kernel-desktop-devel-3.0.101-87.1 kernel-desktop-devel-debuginfo-3.0.101-87.1 kernel-desktop-hmac-3.0.101-87.1 kernel-ec2-3.0.101-87.1 kernel-ec2-base-3.0.101-87.1 kernel-ec2-base-debuginfo-3.0.101-87.1 kernel-ec2-debuginfo-3.0.101-87.1 kernel-ec2-debugsource-3.0.101-87.1 kernel-ec2-devel-3.0.101-87.1 kernel-ec2-devel-debuginfo-3.0.101-87.1 kernel-ec2-extra-3.0.101-87.1 kernel-ec2-extra-debuginfo-3.0.101-87.1 kernel-ec2-hmac-3.0.101-87.1 kernel-source-3.0.101-87.1 kernel-source-vanilla-3.0.101-87.1 kernel-syms-3.0.101-87.1 kernel-trace-3.0.101-87.1 kernel-trace-base-3.0.101-87.1 kernel-trace-base-debuginfo-3.0.101-87.1 kernel-trace-debuginfo-3.0.101-87.1 kernel-trace-debugsource-3.0.101-87.1 kernel-trace-devel-3.0.101-87.1 kernel-trace-devel-debuginfo-3.0.101-87.1 kernel-trace-hmac-3.0.101-87.1 kernel-vanilla-3.0.101-87.1 kernel-vanilla-base-3.0.101-87.1 kernel-vanilla-base-debuginfo-3.0.101-87.1 kernel-vanilla-debuginfo-3.0.101-87.1 kernel-vanilla-debugsource-3.0.101-87.1 kernel-vanilla-devel-3.0.101-87.1 kernel-vanilla-devel-debuginfo-3.0.101-87.1 kernel-vanilla-hmac-3.0.101-87.1 kernel-xen-3.0.101-87.1 kernel-xen-base-3.0.101-87.1 kernel-xen-base-debuginfo-3.0.101-87.1 kernel-xen-debuginfo-3.0.101-87.1 kernel-xen-debugsource-3.0.101-87.1 kernel-xen-devel-3.0.101-87.1 kernel-xen-devel-debuginfo-3.0.101-87.1 kernel-xen-hmac-3.0.101-87.1 preload-1.2-6.65.1 preload-debuginfo-1.2-6.65.1 preload-debugsource-1.2-6.65.1 preload-kmp-default-1.2_3.0.101_87-6.65.1 preload-kmp-default-debuginfo-1.2_3.0.101_87-6.65.1 preload-kmp-desktop-1.2_3.0.101_87-6.65.1 preload-kmp-desktop-debuginfo-1.2_3.0.101_87-6.65.1 - openSUSE 11.4 (noarch): kernel-docs-3.0.101-87.2 - openSUSE 11.4 (i586): kernel-pae-3.0.101-87.1 kernel-pae-base-3.0.101-87.1 kernel-pae-base-debuginfo-3.0.101-87.1 kernel-pae-debuginfo-3.0.101-87.1 kernel-pae-debugsource-3.0.101-87.1 kernel-pae-devel-3.0.101-87.1 kernel-pae-devel-debuginfo-3.0.101-87.1 kernel-pae-hmac-3.0.101-87.1 kernel-vmi-3.0.101-87.1 kernel-vmi-base-3.0.101-87.1 kernel-vmi-base-debuginfo-3.0.101-87.1 kernel-vmi-debuginfo-3.0.101-87.1 kernel-vmi-debugsource-3.0.101-87.1 kernel-vmi-devel-3.0.101-87.1 kernel-vmi-devel-debuginfo-3.0.101-87.1 kernel-vmi-hmac-3.0.101-87.1


References

http://support.novell.com/security/cve/CVE-2014-3153.html https://bugzilla.novell.com/877775 https://bugzilla.novell.com/880892--


Severity
Announcement ID: openSUSE-SU-2014:0878-1
Rating: important
Affected Products: openSUSE 11.4 le.