Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

openSUSE 13.1: 2016:0301-1 Important: Linux Kernel DoS Risks

opensuse
Calendar Grey February 1, 2016
Dist Opensuse Esm H88
A crucial release for Fedora tackling 42 security flaws in the system's kernel has been issued. Discover the details.
An update that solves 57 vulnerabilities and has 21 fixes An update that solves 57 vulnerabilities and has 21 fixes An update that solves 57 vulnerabilities and has 21 fixes is now...

Description

The openSUSE 13.1 kernel was updated to receive various security and

bugfixes.

Following security bugs were fixed:

- CVE-2016-0728: A reference leak in keyring handling with

join_session_keyring() could lead to local attackers gain root

privileges. (bsc#962075).

- CVE-2015-7550: A local user could have triggered a race between read and

revoke in keyctl (bnc#958951).

- CVE-2015-8569: The (1) pptp_bind and (2) pptp_connect functions in

drivers/net/ppp/pptp.c in the Linux kernel did not verify an address

length, which allowed local users to obtain sensitive information from

kernel memory and bypass the KASLR protection mechanism via a crafted

application (bnc#959190).

- CVE-2015-8543: The networking implementation in the Linux kernel did not

validate protocol identifiers for certain protocol families, which

allowed local users to cause a denial of service (NULL function pointer

dereference and system crash) or...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.1:

zypper in -t patch openSUSE-2016-124=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.1 (i686 x86_64):

kernel-debug-3.11.10-32.1

kernel-debug-base-3.11.10-32.1

kernel-debug-base-debuginfo-3.11.10-32.1

kernel-debug-debuginfo-3.11.10-32.1

kernel-debug-debugsource-3.11.10-32.1

kernel-debug-devel-3.11.10-32.1

kernel-debug-devel-debuginfo-3.11.10-32.1

kernel-desktop-3.11.10-32.1

kernel-desktop-base-3.11.10-32.1

kernel-desktop-base-debuginfo-3.11.10-32.1

kernel-desktop-debuginfo-3.11.10-32.1

kernel-desktop-debugsource-3.11.10-32.1

kernel-desktop-devel-3.11.10-32.1

kernel-desktop-devel-debuginfo-3.11.10-32.1

kernel-ec2-3.11.10-32.1

kernel-ec2-base-3.11.10-32.1

kernel-ec2-base-debuginfo-3.11.10-32.1

kernel-ec2-debuginfo-3.11.10-32.1

kernel-ec2-debugsource-3.11.10-32.1

kernel-ec2-devel-3.11.10-32.1

kernel-ec2-devel-debuginfo-3.11.10-32.1

kernel-trace-3.11.10-32.1

kernel-trace-base-3.11.10-32.1

kernel-trace-base-debuginfo-3.11.10-32.1

kernel-trace-debuginfo-3.11.10-32.1

kernel-trace-debugsource-3.11.10-32.1

kernel-trace-devel-3.11.10-32.1

kernel-trace-devel-debuginfo-3.11.10-32.1

kernel-vanilla...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2014-2568.html

https://www.suse.com/security/cve/CVE-2014-8133.html

https://www.suse.com/security/cve/CVE-2014-8989.html

https://www.suse.com/security/cve/CVE-2014-9090.html

https://www.suse.com/security/cve/CVE-2014-9419.html

https://www.suse.com/security/cve/CVE-2014-9529.html

https://www.suse.com/security/cve/CVE-2014-9683.html

https://www.suse.com/security/cve/CVE-2014-9715.html

https://www.suse.com/security/cve/CVE-2014-9728.html

https://www.suse.com/security/cve/CVE-2014-9729.html

https://www.suse.com/security/cve/CVE-2014-9730.html

https://www.suse.com/security/cve/CVE-2014-9731.html

https://www.suse.com/security/cve/CVE-2015-0272.html

https://www.suse.com/security/cve/CVE-2015-0777.html

https://www.suse.com/security/cve/CVE-2015-1420.html

https://www.suse.com/security/cve/CVE-2015-1421.html

https://www.suse.com/security/cve/CVE-2015-2041.html

https://www.suse.com/security/cve/CVE-2015-2042.html

https://www.suse.com/security/cve/CVE-2015-2150.html

https://www....

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:0301-1
Rating: important
Affected Products: openSUSE 13.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here