Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

openSUSE 13.2: 2015:1842-1 Important Security Fixes for Kernel

opensuse
Calendar Grey October 29, 2015
Scroller Opensuse
Critical Security Notification for openSUSE Kernel: essential information regarding updates and defects addressed in openSUSE 13.2.
An update that solves 7 vulnerabilities and has 7 fixes is An update that solves 7 vulnerabilities and has 7 fixes is An update that solves 7 vulnerabilities and has 7 fixes is now...

Description

The openSUSE 13.2 kernel was updated to receive various security and

bugfixes.

Following security bugs were fixed:

* CVE-2015-3290: arch/x86/entry/entry_64.S in the Linux kernel on the

x86_64 platform improperly relied on espfix64 during nested NMI

processing, which allowed local users to gain privileges by triggering

an NMI within a certain instruction window (bnc#937969)

* CVE-2015-0272: It was reported that it's possible to craft a Router

Advertisement message which will bring the receiver in a state where new

IPv6 connections will not be accepted until correct Router Advertisement

message received. (bsc#944296).

* CVE-2015-5283: The sctp_init function in net/sctp/protocol.c in the

Linux kernel had an incorrect sequence of protocol-initialization steps,

which allowed local users to cause a denial of service (panic or memory

corruption) by creating SCTP sockets before all of the steps have

finished (bnc#947155).

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.2:

zypper in -t patch openSUSE-2015-686=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.2 (i586 x86_64):

bbswitch-0.8-3.13.2

bbswitch-debugsource-0.8-3.13.2

bbswitch-kmp-default-0.8_k3.16.7_29-3.13.2

bbswitch-kmp-default-debuginfo-0.8_k3.16.7_29-3.13.2

bbswitch-kmp-desktop-0.8_k3.16.7_29-3.13.2

bbswitch-kmp-desktop-debuginfo-0.8_k3.16.7_29-3.13.2

bbswitch-kmp-xen-0.8_k3.16.7_29-3.13.2

bbswitch-kmp-xen-debuginfo-0.8_k3.16.7_29-3.13.2

cloop-2.639-14.13.2

cloop-debuginfo-2.639-14.13.2

cloop-debugsource-2.639-14.13.2

cloop-kmp-default-2.639_k3.16.7_29-14.13.2

cloop-kmp-default-debuginfo-2.639_k3.16.7_29-14.13.2

cloop-kmp-desktop-2.639_k3.16.7_29-14.13.2

cloop-kmp-desktop-debuginfo-2.639_k3.16.7_29-14.13.2

cloop-kmp-xen-2.639_k3.16.7_29-14.13.2

cloop-kmp-xen-debuginfo-2.639_k3.16.7_29-14.13.2

crash-7.0.8-13.2

crash-debuginfo-7.0.8-13.2

crash-debugsource-7.0.8-13.2

crash-devel-7.0.8-13.2

crash-doc-7.0.8-13.2

crash-eppic-7.0.8-13.2

crash-eppic-debuginfo-7.0.8-13.2

crash-gcore-7.0.8-13.2

crash-gcore-debuginfo-7.0.8-13.2

crash-kmp-default-7.0.8_k3.16.7_29-13.2

crash-kmp-default-debuginfo-7.0.8_...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2015-0272.html

https://www.suse.com/security/cve/CVE-2015-1333.html

https://www.suse.com/security/cve/CVE-2015-2925.html

https://www.suse.com/security/cve/CVE-2015-3290.html

https://www.suse.com/security/cve/CVE-2015-5283.html

https://www.suse.com/security/cve/CVE-2015-5707.html

https://www.suse.com/security/cve/CVE-2015-7872.html

https://bugzilla.suse.com/show_bug.cgi?id=919154

https://bugzilla.suse.com/show_bug.cgi?id=926238

https://bugzilla.suse.com/show_bug.cgi?id=937969

https://bugzilla.suse.com/show_bug.cgi?id=938645

https://bugzilla.suse.com/show_bug.cgi?id=939834

https://bugzilla.suse.com/show_bug.cgi?id=940338

https://bugzilla.suse.com/show_bug.cgi?id=941104

https://bugzilla.suse.com/show_bug.cgi?id=941305

https://bugzilla.suse.com/show_bug.cgi?id=941867

https://bugzilla.suse.com/show_bug.cgi?id=942178

https://bugzilla.suse.com/show_bug.cgi?id=944296

https://bugzilla.suse.com/show_bug.cgi?id=947155

https://bugzilla.suse.com/show_bug.cgi?id=951195

https://bugz...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2015:1842-1
Rating: important
Affected Products: openSUSE 13.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.