Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

openSUSE: 2014:0985-1 Important: Kernel Update Addresses Security Issues

opensuse
Calendar Grey August 11, 2014
Dist Opensuse Esm H88
Crucial kernel upgrade for openSUSE resolves security flaws and malfunctions, tackling 14 vulnerabilities in total.
An update that solves 14 vulnerabilities and has two fixes An update that solves 14 vulnerabilities and has two fixes An update that solves 14 vulnerabilities and has two fixes is ...

Description

The Linux kernel was updated to fix security issues and bugs:

Security issues fixed: CVE-2014-4699: The Linux kernel on Intel processors did not properly restrict use of a non-canonical value for the saved RIP

address in the case of a system call that does not use IRET, which allowed

local users to leverage a race condition and gain privileges, or cause a

denial of service (double fault), via a crafted application that makes

ptrace and fork system calls.

CVE-2014-4667: The sctp_association_free function in net/sctp/associola.c

in the Linux kernel did not properly manage a certain backlog value, which

allowed remote attackers to cause a denial of service (socket

outage) via a crafted SCTP packet.

CVE-2014-4171: mm/shmem.c in the Linux kernel did not properly implement

the interaction between range notification and hole punching, which

allowed local users to cause a denial of service (i_mutex hold) by using

the mmap system call to access...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.1:

zypper in -t patch openSUSE-2014-493

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.1 (i686 x86_64):

kernel-debug-3.11.10-21.1

kernel-debug-base-3.11.10-21.1

kernel-debug-base-debuginfo-3.11.10-21.1

kernel-debug-debuginfo-3.11.10-21.1

kernel-debug-debugsource-3.11.10-21.1

kernel-debug-devel-3.11.10-21.1

kernel-debug-devel-debuginfo-3.11.10-21.1

kernel-desktop-3.11.10-21.1

kernel-desktop-base-3.11.10-21.1

kernel-desktop-base-debuginfo-3.11.10-21.1

kernel-desktop-debuginfo-3.11.10-21.1

kernel-desktop-debugsource-3.11.10-21.1

kernel-desktop-devel-3.11.10-21.1

kernel-desktop-devel-debuginfo-3.11.10-21.1

kernel-ec2-3.11.10-21.1

kernel-ec2-base-3.11.10-21.1

kernel-ec2-base-debuginfo-3.11.10-21.1

kernel-ec2-debuginfo-3.11.10-21.1

kernel-ec2-debugsource-3.11.10-21.1

kernel-ec2-devel-3.11.10-21.1

kernel-ec2-devel-debuginfo-3.11.10-21.1

kernel-trace-3.11.10-21.1

kernel-trace-base-3.11.10-21.1

kernel-trace-base-debuginfo-3.11.10-21.1

kernel-trace-debuginfo-3.11.10-21.1

kernel-trace-debugsource-3.11.10-21.1

kernel-trace-devel-3.11.10-21.1

kernel-trace-devel-debuginfo-3.11.10-21.1

kernel-vanilla...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2014-0100.html

https://www.suse.com/security/cve/CVE-2014-0131.html

https://www.suse.com/security/cve/CVE-2014-2309.html

https://www.suse.com/security/cve/CVE-2014-3917.html

https://www.suse.com/security/cve/CVE-2014-4014.html

https://www.suse.com/security/cve/CVE-2014-4171.html

https://www.suse.com/security/cve/CVE-2014-4508.html

https://www.suse.com/security/cve/CVE-2014-4652.html

https://www.suse.com/security/cve/CVE-2014-4653.html

https://www.suse.com/security/cve/CVE-2014-4654.html

https://www.suse.com/security/cve/CVE-2014-4655.html

https://www.suse.com/security/cve/CVE-2014-4656.html

https://www.suse.com/security/cve/CVE-2014-4667.html

https://www.suse.com/security/cve/CVE-2014-4699.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2014:0985-1
Rating: important
Affected Products: openSUSE 13.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here