Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

openSUSE 13.1: 2015:0714-1 Critical: Linux Kernel Fixes

opensuse
Calendar Grey April 13, 2015
Scroller Opensuse
The latest security patch from OpenSUSE tackles significant vulnerabilities identified in the Linux Kernel, offering various solutions for its users.
An update that solves 11 vulnerabilities and has 5 fixes is An update that solves 11 vulnerabilities and has 5 fixes is An update that solves 11 vulnerabilities and has 5 fixes is ...

Description

The Linux kernel was updated to fix various bugs and security issues.

Following security issues were fixed:

- CVE-2014-8173: A NULL pointer dereference flaw was found in the way the

Linux kernels madvise MADV_WILLNEED functionality handled page table

locking. A local, unprivileged user could have used this flaw to crash

the system.

- CVE-2015-1593: A integer overflow reduced the effectiveness of the stack

randomization on 64-bit systems.

- CVE-2014-7822: A flaw was found in the way the Linux kernels splice()

system call validated its parameters. On certain file systems, a local,

unprivileged user could have used this flaw to write past the maximum

file size, and thus crash the system.

- CVE-2014-9419: The __switch_to function in arch/x86/kernel/process_64.c

in the Linux kernel did not ensure that Thread Local Storage (TLS)

descriptors are loaded before proceeding with other steps, which made it

easier for local...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.1:

zypper in -t patch openSUSE-2015-301=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.1 (i686 x86_64):

kernel-debug-3.11.10-29.1

kernel-debug-base-3.11.10-29.1

kernel-debug-base-debuginfo-3.11.10-29.1

kernel-debug-debuginfo-3.11.10-29.1

kernel-debug-debugsource-3.11.10-29.1

kernel-debug-devel-3.11.10-29.1

kernel-debug-devel-debuginfo-3.11.10-29.1

kernel-desktop-3.11.10-29.1

kernel-desktop-base-3.11.10-29.1

kernel-desktop-base-debuginfo-3.11.10-29.1

kernel-desktop-debuginfo-3.11.10-29.1

kernel-desktop-debugsource-3.11.10-29.1

kernel-desktop-devel-3.11.10-29.1

kernel-desktop-devel-debuginfo-3.11.10-29.1

kernel-ec2-3.11.10-29.1

kernel-ec2-base-3.11.10-29.1

kernel-ec2-base-debuginfo-3.11.10-29.1

kernel-ec2-debuginfo-3.11.10-29.1

kernel-ec2-debugsource-3.11.10-29.1

kernel-ec2-devel-3.11.10-29.1

kernel-ec2-devel-debuginfo-3.11.10-29.1

kernel-trace-3.11.10-29.1

kernel-trace-base-3.11.10-29.1

kernel-trace-base-debuginfo-3.11.10-29.1

kernel-trace-debuginfo-3.11.10-29.1

kernel-trace-debugsource-3.11.10-29.1

kernel-trace-devel-3.11.10-29.1

kernel-trace-devel-debuginfo-3.11.10-29.1

kernel-vanilla...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2014-7822.html

https://www.suse.com/security/cve/CVE-2014-8134.html

https://www.suse.com/security/cve/CVE-2014-8160.html

https://www.suse.com/security/cve/CVE-2014-8173.html

https://www.suse.com/security/cve/CVE-2014-8559.html

https://www.suse.com/security/cve/CVE-2014-9419.html

https://www.suse.com/security/cve/CVE-2014-9420.html

https://www.suse.com/security/cve/CVE-2014-9529.html

https://www.suse.com/security/cve/CVE-2014-9584.html

https://www.suse.com/security/cve/CVE-2014-9585.html

https://www.suse.com/security/cve/CVE-2015-1593.html

https://bugzilla.suse.com/903640

https://bugzilla.suse.com/904899

https://bugzilla.suse.com/907988

https://bugzilla.suse.com/909078

https://bugzilla.suse.com/910150

https://bugzilla.suse.com/911325

https://bugzilla.suse.com/911326

https://bugzilla.suse.com/912202

https://bugzilla.suse.com/912654

https://bugzilla.suse.com/912705

https://bugzilla.suse.com/913059

https://bugzilla.suse.com/913695

https://bugzilla.suse.com/914175

https://bugz...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2015:0714-1
Rating: important
Affected Products: openSUSE 13.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.