Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

openSUSE Leap 42.1: 2016:1008-1 Important Denial Of Service Fix

opensuse
Calendar Grey April 12, 2016
Scroller Opensuse
openSUSE: Critical patch released correcting 20 vulnerabilities in the Linux Kernel, improving system integrity and protection.
An update that solves 15 vulnerabilities and has 26 fixes An update that solves 15 vulnerabilities and has 26 fixes An update that solves 15 vulnerabilities and has 26 fixes is now...

Description

The openSUSE Leap 42.1 kernel was updated to 4.1.20 to receive various

security and bugfixes.

The following security bugs were fixed:

- CVE-2015-1339: A memory leak in cuse could be used to exhaust kernel

memory. (bsc#969356).

- CVE-2015-7799: The slhc_init function in drivers/net/slip/slhc.c in the

Linux kernel did not ensure that certain slot numbers are valid, which

allowed local users to cause a denial of service (NULL pointer

dereference and system crash) via a crafted PPPIOCSMAXCID ioctl call

(bnc#949936 951638).

- CVE-2015-7872: The key_gc_unused_keys function in security/keys/gc.c in

the Linux kernel allowed local users to cause a denial of service (OOPS)

via crafted keyctl commands (bnc#951440).

- CVE-2015-7884: The vivid_fb_ioctl function in

drivers/media/platform/vivid/vivid-osd.c in the Linux kernel did not

initialize a certain structure member, which allowed local users to

obtain sensitive...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.1:

zypper in -t patch openSUSE-2016-445=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.1 (i586 x86_64):

kernel-default-4.1.20-11.1

kernel-default-base-4.1.20-11.1

kernel-default-base-debuginfo-4.1.20-11.1

kernel-default-debuginfo-4.1.20-11.1

kernel-default-debugsource-4.1.20-11.1

kernel-default-devel-4.1.20-11.1

kernel-obs-build-4.1.20-11.2

kernel-obs-build-debugsource-4.1.20-11.2

kernel-obs-qa-4.1.20-11.1

kernel-obs-qa-xen-4.1.20-11.1

kernel-syms-4.1.20-11.1

- openSUSE Leap 42.1 (i686 x86_64):

kernel-debug-4.1.20-11.1

kernel-debug-base-4.1.20-11.1

kernel-debug-base-debuginfo-4.1.20-11.1

kernel-debug-debuginfo-4.1.20-11.1

kernel-debug-debugsource-4.1.20-11.1

kernel-debug-devel-4.1.20-11.1

kernel-debug-devel-debuginfo-4.1.20-11.1

kernel-ec2-4.1.20-11.1

kernel-ec2-base-4.1.20-11.1

kernel-ec2-base-debuginfo-4.1.20-11.1

kernel-ec2-debuginfo-4.1.20-11.1

kernel-ec2-debugsource-4.1.20-11.1

kernel-ec2-devel-4.1.20-11.1

kernel-pv-4.1.20-11.1

kernel-pv-base-4.1.20-11.1

kernel-pv-base-debuginfo-4.1.20-11.1

kernel-pv-debuginfo-4.1.20-11.1

kernel-pv-debugsource-4.1.20-11.1

kernel-pv-devel-4.1.20...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2015-1339.html

https://www.suse.com/security/cve/CVE-2015-7799.html

https://www.suse.com/security/cve/CVE-2015-7872.html

https://www.suse.com/security/cve/CVE-2015-7884.html

https://www.suse.com/security/cve/CVE-2015-8104.html

https://www.suse.com/security/cve/CVE-2015-8709.html

https://www.suse.com/security/cve/CVE-2015-8767.html

https://www.suse.com/security/cve/CVE-2015-8785.html

https://www.suse.com/security/cve/CVE-2015-8787.html

https://www.suse.com/security/cve/CVE-2015-8812.html

https://www.suse.com/security/cve/CVE-2016-0723.html

https://www.suse.com/security/cve/CVE-2016-2069.html

https://www.suse.com/security/cve/CVE-2016-2184.html

https://www.suse.com/security/cve/CVE-2016-2383.html

https://www.suse.com/security/cve/CVE-2016-2384.html

https://bugzilla.suse.com/814440

https://bugzilla.suse.com/884701

https://bugzilla.suse.com/949936

https://bugzilla.suse.com/951440

https://bugzilla.suse.com/951542

https://bugzilla.suse.com/951626

https://bugzilla.suse.com/95...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:1008-1
Rating: important
Affected Products: openSUSE Leap 42.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.