Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

openSUSE 13.2: 2016:2625-1 Important: Linux Kernel Security Fixes

opensuse
Calendar Grey October 25, 2016
Scroller Opensuse
Crucial Fedora security patch addresses 15 vulnerabilities within the Linux Kernel, improving overall system integrity and protection.
An update that solves 12 vulnerabilities and has 19 fixes An update that solves 12 vulnerabilities and has 19 fixes An update that solves 12 vulnerabilities and has 19 fixes is now...

Description

The openSUSE 13.2 kernel was updated to receive various security and

bugfixes.

The following security bugs were fixed:

- CVE-2015-8956: The rfcomm_sock_bind function in

net/bluetooth/rfcomm/sock.c in the Linux kernel allowed local users to

obtain sensitive information or cause a denial of service (NULL pointer

dereference) via vectors involving a bind system call on a Bluetooth

RFCOMM socket (bnc#1003925).

- CVE-2016-5195: A local privilege escalation using MAP_PRIVATE was fixed,

which is reportedly exploited in the wild (bsc#1004418).

- CVE-2016-8658: Stack-based buffer overflow in the

brcmf_cfg80211_start_ap function in

drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux

kernel allowed local users to cause a denial of service (system crash)

or possibly have unspecified other impact via a long SSID Information

Element in a command to a Netlink socket (bnc#1004462).

- CVE-2016-7117:...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.2:

zypper in -t patch openSUSE-2016-1227=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.2 (i686 x86_64):

kernel-debug-3.16.7-45.1

kernel-debug-base-3.16.7-45.1

kernel-debug-base-debuginfo-3.16.7-45.1

kernel-debug-debuginfo-3.16.7-45.1

kernel-debug-debugsource-3.16.7-45.1

kernel-debug-devel-3.16.7-45.1

kernel-debug-devel-debuginfo-3.16.7-45.1

kernel-desktop-3.16.7-45.1

kernel-desktop-base-3.16.7-45.1

kernel-desktop-base-debuginfo-3.16.7-45.1

kernel-desktop-debuginfo-3.16.7-45.1

kernel-desktop-debugsource-3.16.7-45.1

kernel-desktop-devel-3.16.7-45.1

kernel-ec2-base-debuginfo-3.16.7-45.1

kernel-ec2-debuginfo-3.16.7-45.1

kernel-ec2-debugsource-3.16.7-45.1

kernel-vanilla-3.16.7-45.1

kernel-vanilla-debuginfo-3.16.7-45.1

kernel-vanilla-debugsource-3.16.7-45.1

kernel-vanilla-devel-3.16.7-45.1

kernel-xen-3.16.7-45.1

kernel-xen-base-3.16.7-45.1

kernel-xen-base-debuginfo-3.16.7-45.1

kernel-xen-debuginfo-3.16.7-45.1

kernel-xen-debugsource-3.16.7-45.1

kernel-xen-devel-3.16.7-45.1

- openSUSE 13.2 (i586 x86_64):

bbswitch-0.8-3.22.1

bbswitch-debugsource-0.8-3.22.1

bbswitch-kmp-default-0.8_k3.16.7_45-3.2...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2015-7513.html

https://www.suse.com/security/cve/CVE-2015-8956.html

https://www.suse.com/security/cve/CVE-2016-0823.html

https://www.suse.com/security/cve/CVE-2016-1237.html

https://www.suse.com/security/cve/CVE-2016-5195.html

https://www.suse.com/security/cve/CVE-2016-5696.html

https://www.suse.com/security/cve/CVE-2016-6327.html

https://www.suse.com/security/cve/CVE-2016-6480.html

https://www.suse.com/security/cve/CVE-2016-6828.html

https://www.suse.com/security/cve/CVE-2016-7117.html

https://www.suse.com/security/cve/CVE-2016-7425.html

https://www.suse.com/security/cve/CVE-2016-8658.html

https://bugzilla.suse.com/1000287

https://bugzilla.suse.com/1001486

https://bugzilla.suse.com/1003077

https://bugzilla.suse.com/1003925

https://bugzilla.suse.com/1003931

https://bugzilla.suse.com/1004045

https://bugzilla.suse.com/1004418

https://bugzilla.suse.com/1004462

https://bugzilla.suse.com/881008

https://bugzilla.suse.com/909994

https://bugzilla.suse.com/911687

https://bugzilla...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:2625-1
Rating: important
Affected Products: openSUSE 13.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.