Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

openSUSE 13.2: SU-2015:0713-1 Critical: Kernel Update And Fixes

opensuse
Calendar Grey April 13, 2015
Scroller Opensuse
Important openSUSE patch releases resolving several kernel security flaws and potential system stability issues. Update immediately!
An update that solves 13 vulnerabilities and has 52 fixes An update that solves 13 vulnerabilities and has 52 fixes An update that solves 13 vulnerabilities and has 52 fixes is now...

Description

The Linux kernel was updated to fix bugs and security issues:

Following security issues were fixed:

- CVE-2015-1421: Use-after-free vulnerability in the sctp_assoc_update

function in net/sctp/associola.c in the Linux kernel allowed remote

attackers to cause a denial of service (slab corruption and panic) or

possibly have unspecified other impact by triggering an INIT collision

that leads to improper handling of shared-key data.

- CVE-2015-2150: XSA-120: Guests were permitted to modify all bits of the

PCI command register of passed through cards, which could lead to Host

system crashes.

- CVE-2015-0777: The XEN usb backend could leak information to the guest

system due to copying uninitialized memory.

- CVE-2015-1593: A integer overflow reduced the effectiveness of the stack

randomization on 64-bit systems.

- CVE-2014-9419: The __switch_to function in arch/x86/kernel/process_64.c

in the Linux kernel did not ensure...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.2:

zypper in -t patch openSUSE-2015-302=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.2 (i686 x86_64):

kernel-debug-3.16.7-13.2

kernel-debug-base-3.16.7-13.2

kernel-debug-base-debuginfo-3.16.7-13.2

kernel-debug-debuginfo-3.16.7-13.2

kernel-debug-debugsource-3.16.7-13.2

kernel-debug-devel-3.16.7-13.2

kernel-debug-devel-debuginfo-3.16.7-13.2

kernel-desktop-3.16.7-13.2

kernel-desktop-base-3.16.7-13.2

kernel-desktop-base-debuginfo-3.16.7-13.2

kernel-desktop-debuginfo-3.16.7-13.2

kernel-desktop-debugsource-3.16.7-13.2

kernel-desktop-devel-3.16.7-13.2

kernel-ec2-3.16.7-13.2

kernel-ec2-base-3.16.7-13.2

kernel-ec2-base-debuginfo-3.16.7-13.2

kernel-ec2-debuginfo-3.16.7-13.2

kernel-ec2-debugsource-3.16.7-13.2

kernel-ec2-devel-3.16.7-13.2

kernel-vanilla-3.16.7-13.2

kernel-vanilla-debuginfo-3.16.7-13.2

kernel-vanilla-debugsource-3.16.7-13.2

kernel-vanilla-devel-3.16.7-13.2

kernel-xen-3.16.7-13.2

kernel-xen-base-3.16.7-13.2

kernel-xen-base-debuginfo-3.16.7-13.2

kernel-xen-debuginfo-3.16.7-13.2

kernel-xen-debugsource-3.16.7-13.2

kernel-xen-devel-3.16.7-13.2

- openSUSE 13.2 (i586 x86_64):

bbswitch-0.8...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2014-8134.html

https://www.suse.com/security/cve/CVE-2014-8160.html

https://www.suse.com/security/cve/CVE-2014-8559.html

https://www.suse.com/security/cve/CVE-2014-9419.html

https://www.suse.com/security/cve/CVE-2014-9420.html

https://www.suse.com/security/cve/CVE-2014-9428.html

https://www.suse.com/security/cve/CVE-2014-9529.html

https://www.suse.com/security/cve/CVE-2014-9584.html

https://www.suse.com/security/cve/CVE-2014-9585.html

https://www.suse.com/security/cve/CVE-2015-0777.html

https://www.suse.com/security/cve/CVE-2015-1421.html

https://www.suse.com/security/cve/CVE-2015-1593.html

https://www.suse.com/security/cve/CVE-2015-2150.html

https://bugzilla.suse.com/show_bug.cgi?id=867199

https://bugzilla.suse.com/893428

https://bugzilla.suse.com/895797

https://bugzilla.suse.com/900811

https://bugzilla.suse.com/901925

https://bugzilla.suse.com/903589

https://bugzilla.suse.com/show_bug.cgi?id=903640

https://bugzilla.suse.com/show_bug.cgi?id=904899

https://bugzilla.sus...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2015:0713-1
Rating: important
Affected Products: openSUSE 13.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.