Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

openSUSE 13.1: Security Update Important: Kernel Security Enhancements

opensuse
Calendar Grey December 6, 2016
Dist Opensuse Esm H88
An important patch for Fedora improves system resilience and resolves various vulnerabilities efficiently.
An update that solves 12 vulnerabilities and has 118 fixes An update that solves 12 vulnerabilities and has 118 fixes An update that solves 12 vulnerabilities and has 118 fixes is ...

Description

The openSUSE 13.1 kernel was updated to 3.12.67 to receive various

security and bugfixes.

The following security bugs were fixed:

- CVE-2013-5634: arch/arm/kvm/arm.c in the Linux kernel on the ARM

platform, when KVM is used, allowed host OS users to cause a denial of

service (NULL pointer dereference, OOPS, and host OS crash) or possibly

have unspecified other impact by omitting vCPU initialization before a

KVM_GET_REG_LIST ioctl call. (bsc#994758)

- CVE-2016-2069: Race condition in arch/x86/mm/tlb.c in the Linux kernel

allowed local users to gain privileges by triggering access to a paging

structure by a different CPU (bnc#963767).

- CVE-2016-7042: The proc_keys_show function in security/keys/proc.c in

the Linux kernel used an incorrect buffer size for certain timeout data,

which allowed local users to cause a denial of service (stack memory

corruption and panic) by reading the /proc/keys file (bnc#1004517).

-...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.1:

zypper in -t patch openSUSE-2016-1410=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.1 (i586 x86_64):

cloop-2.639-11.36.1

cloop-debuginfo-2.639-11.36.1

cloop-debugsource-2.639-11.36.1

cloop-kmp-default-2.639_k3.12.67_58-11.36.1

cloop-kmp-default-debuginfo-2.639_k3.12.67_58-11.36.1

cloop-kmp-desktop-2.639_k3.12.67_58-11.36.1

cloop-kmp-desktop-debuginfo-2.639_k3.12.67_58-11.36.1

cloop-kmp-xen-2.639_k3.12.67_58-11.36.1

cloop-kmp-xen-debuginfo-2.639_k3.12.67_58-11.36.1

crash-7.0.2-2.36.1

crash-debuginfo-7.0.2-2.36.1

crash-debugsource-7.0.2-2.36.1

crash-devel-7.0.2-2.36.1

crash-doc-7.0.2-2.36.1

crash-eppic-7.0.2-2.36.1

crash-eppic-debuginfo-7.0.2-2.36.1

crash-gcore-7.0.2-2.36.1

crash-gcore-debuginfo-7.0.2-2.36.1

crash-kmp-default-7.0.2_k3.12.67_58-2.36.1

crash-kmp-default-debuginfo-7.0.2_k3.12.67_58-2.36.1

crash-kmp-desktop-7.0.2_k3.12.67_58-2.36.1

crash-kmp-desktop-debuginfo-7.0.2_k3.12.67_58-2.36.1

crash-kmp-xen-7.0.2_k3.12.67_58-2.36.1

crash-kmp-xen-debuginfo-7.0.2_k3.12.67_58-2.36.1

hdjmod-debugsource-1.28-16.36.1

hdjmod-kmp-default-1.28_k3.12.67_58-16.36.1

hdjmod-kmp-default-debugi...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2013-5634.html

https://www.suse.com/security/cve/CVE-2015-8956.html

https://www.suse.com/security/cve/CVE-2016-2069.html

https://www.suse.com/security/cve/CVE-2016-5696.html

https://www.suse.com/security/cve/CVE-2016-6130.html

https://www.suse.com/security/cve/CVE-2016-6327.html

https://www.suse.com/security/cve/CVE-2016-6480.html

https://www.suse.com/security/cve/CVE-2016-6828.html

https://www.suse.com/security/cve/CVE-2016-7042.html

https://www.suse.com/security/cve/CVE-2016-7097.html

https://www.suse.com/security/cve/CVE-2016-7425.html

https://www.suse.com/security/cve/CVE-2016-8658.html

https://bugzilla.suse.com/1000189

https://bugzilla.suse.com/1000287

https://bugzilla.suse.com/1000304

https://bugzilla.suse.com/1000776

https://bugzilla.suse.com/1001419

https://bugzilla.suse.com/1001486

https://bugzilla.suse.com/1002165

https://bugzilla.suse.com/1003079

https://bugzilla.suse.com/1003153

https://bugzilla.suse.com/1003400

https://bugzilla.suse.com/1003568

https://bugzi...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:3021-1
Rating: important
Affected Products: openSUSE 13.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here