Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 508
Alerts This Week
Warning Icon 1 508

openSUSE Leap 42.1: 2016:1798-1 Important Kernel Security Update

opensuse
Calendar Grey July 14, 2016
Scroller Opensuse
openSUSE Security Patch: critical update for Linux Kernel resolving various vulnerabilities and corrections now ready for implementation.
An update that solves four vulnerabilities and has 5 fixes An update that solves four vulnerabilities and has 5 fixes An update that solves four vulnerabilities and has 5 fixes is ...

Description

The openSUSE Leap 42.1 was updated to 4.1.27 to receive various security

and bugfixes.

The following security bugs were fixed:

- CVE-2016-4997: A buffer overflow in 32bit compat_setsockopt iptables

handling could lead to a local privilege escalation. (bsc#986362)

- CVE-2016-5829: Multiple heap-based buffer overflows in the

hiddev_ioctl_usage function in drivers/hid/usbhid/hiddev.c in the Linux

kernel allow local users to cause a denial of service or possibly have

unspecified other impact via a crafted (1) HIDIOCGUSAGES or (2)

HIDIOCSUSAGES ioctl call (bnc#986572).

- CVE-2016-4470: The key_reject_and_link function in security/keys/key.c

in the Linux kernel did not ensure that a certain data structure is

initialized, which allowed local users to cause a denial of service

(system crash) via vectors involving a crafted keyctl request2 command

(bnc#984755).

- CVE-2016-4794: Use-after-free vulnerability in mm/percpu.c in...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.1:

zypper in -t patch openSUSE-2016-869=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.1 (i686 x86_64):

kernel-debug-4.1.27-24.1

kernel-debug-base-4.1.27-24.1

kernel-debug-base-debuginfo-4.1.27-24.1

kernel-debug-debuginfo-4.1.27-24.1

kernel-debug-debugsource-4.1.27-24.1

kernel-debug-devel-4.1.27-24.1

kernel-debug-devel-debuginfo-4.1.27-24.1

kernel-ec2-4.1.27-24.1

kernel-ec2-base-4.1.27-24.1

kernel-ec2-base-debuginfo-4.1.27-24.1

kernel-ec2-debuginfo-4.1.27-24.1

kernel-ec2-debugsource-4.1.27-24.1

kernel-ec2-devel-4.1.27-24.1

kernel-pv-4.1.27-24.1

kernel-pv-base-4.1.27-24.1

kernel-pv-base-debuginfo-4.1.27-24.1

kernel-pv-debuginfo-4.1.27-24.1

kernel-pv-debugsource-4.1.27-24.1

kernel-pv-devel-4.1.27-24.1

kernel-vanilla-4.1.27-24.1

kernel-vanilla-debuginfo-4.1.27-24.1

kernel-vanilla-debugsource-4.1.27-24.1

kernel-vanilla-devel-4.1.27-24.1

kernel-xen-4.1.27-24.1

kernel-xen-base-4.1.27-24.1

kernel-xen-base-debuginfo-4.1.27-24.1

kernel-xen-debuginfo-4.1.27-24.1

kernel-xen-debugsource-4.1.27-24.1

kernel-xen-devel-4.1.27-24.1

- openSUSE Leap 42.1 (i586 x86_64):

kernel-default-4.1.27-24.1

kernel...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2016-4470.html

https://www.suse.com/security/cve/CVE-2016-4794.html

https://www.suse.com/security/cve/CVE-2016-4997.html

https://www.suse.com/security/cve/CVE-2016-5829.html

https://bugzilla.suse.com/970114

https://bugzilla.suse.com/970275

https://bugzilla.suse.com/978469

https://bugzilla.suse.com/980265

https://bugzilla.suse.com/983977

https://bugzilla.suse.com/984755

https://bugzilla.suse.com/986362

https://bugzilla.suse.com/986530

https://bugzilla.suse.com/986572

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:1798-1
Rating: important
Affected Products: openSUSE Leap 42.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.