Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

openSUSE 12.3: 2024:1015-2 Severe Kernel Access Vulnerability

opensuse
Calendar Grey August 1, 2014
Dist Opensuse Esm H88
A significant kernel security update for openSUSE has been released, targeting several serious vulnerabilities along with recommendations for system upgrades.
An update that fixes 15 vulnerabilities is now available

Description

The Linux Kernel was updated to fix various bugs and security issues.

CVE-2014-4699: The Linux kernel on Intel processors did not properly

restrict use of a non-canonical value for the saved RIP address in the

case of a system call that does not use IRET, which allowed local users to

leverage a race condition and gain privileges, or cause a denial of

service (double fault), via a crafted application that makes ptrace and

fork system calls.

CVE-2014-4667: The sctp_association_free function in net/sctp/associola.c

in the Linux kernel did not properly manage a certain backlog value, which

allowed remote attackers to cause a denial of service (socket

outage) via a crafted SCTP packet.

CVE-2014-4171: mm/shmem.c in the Linux kernel did not properly implement

the interaction between range notification and hole punching, which

allowed local users to cause a denial of service (i_mutex hold) by using

the mmap system call to access a hole, as...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 12.3:

zypper in -t patch openSUSE-2014-478

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 12.3 (i586 x86_64):

kernel-default-3.7.10-1.40.1

kernel-default-base-3.7.10-1.40.1

kernel-default-base-debuginfo-3.7.10-1.40.1

kernel-default-debuginfo-3.7.10-1.40.1

kernel-default-debugsource-3.7.10-1.40.1

kernel-default-devel-3.7.10-1.40.1

kernel-default-devel-debuginfo-3.7.10-1.40.1

kernel-syms-3.7.10-1.40.1

- openSUSE 12.3 (i686 x86_64):

kernel-debug-3.7.10-1.40.1

kernel-debug-base-3.7.10-1.40.1

kernel-debug-base-debuginfo-3.7.10-1.40.1

kernel-debug-debuginfo-3.7.10-1.40.1

kernel-debug-debugsource-3.7.10-1.40.1

kernel-debug-devel-3.7.10-1.40.1

kernel-debug-devel-debuginfo-3.7.10-1.40.1

kernel-desktop-3.7.10-1.40.1

kernel-desktop-base-3.7.10-1.40.1

kernel-desktop-base-debuginfo-3.7.10-1.40.1

kernel-desktop-debuginfo-3.7.10-1.40.1

kernel-desktop-debugsource-3.7.10-1.40.1

kernel-desktop-devel-3.7.10-1.40.1

kernel-desktop-devel-debuginfo-3.7.10-1.40.1

kernel-ec2-3.7.10-1.40.1

kernel-ec2-base-3.7.10-1.40.1

kernel-ec2-base-debuginfo-3.7.10-1.40.1

kernel-ec2-debuginfo-3.7.10-1.40.1

kernel-ec2-debugsource-...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2014-0131.html

https://www.suse.com/security/cve/CVE-2014-2309.html

https://www.suse.com/security/cve/CVE-2014-3144.html

https://www.suse.com/security/cve/CVE-2014-3145.html

https://www.suse.com/security/cve/CVE-2014-3917.html

https://www.suse.com/security/cve/CVE-2014-4014.html

https://www.suse.com/security/cve/CVE-2014-4171.html

https://www.suse.com/security/cve/CVE-2014-4508.html

https://www.suse.com/security/cve/CVE-2014-4652.html

https://www.suse.com/security/cve/CVE-2014-4653.html

https://www.suse.com/security/cve/CVE-2014-4654.html

https://www.suse.com/security/cve/CVE-2014-4655.html

https://www.suse.com/security/cve/CVE-2014-4656.html

https://www.suse.com/security/cve/CVE-2014-4667.html

https://www.suse.com/security/cve/CVE-2014-4699.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2014:0957-1
Rating: important
Affected Products: openSUSE 12.3 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here