The openSUSE Leap 42.2 kernel was updated to 4.4.56 fix various security
issues and bugs.
The following security bugs were fixed:
- CVE-2017-7184: The xfrm_replay_verify_len function in
net/xfrm/xfrm_user.c in the Linux kernel did not validate certain size
data after an XFRM_MSG_NEWAE update, which allowed local users to obtain
root privileges or cause a denial of service (heap-based out-of-bounds
access) by leveraging the CAP_NET_ADMIN capability, as demonstrated
during a Pwn2Own competition at CanSecWest 2017 for the Ubuntu 16.10
linux-image-* package 4.8.0.41.52 (bnc#1030573).
- CVE-2016-10200: Race condition in the L2TPv3 IP Encapsulation feature in
the Linux kernel allowed local users to gain privileges or cause a
denial of service (use-after-free) by making multiple bind system calls
without properly ascertaining whether a socket has the SOCK_ZAPPED
status, related to net/l2tp/l2tp_ip.c and net/l2tp/l2tp_ip6.c
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.2:
zypper in -t patch openSUSE-2017-418=1
To bring your system up-to-date, use "zypper patch".
- openSUSE Leap 42.2 (noarch):
kernel-devel-4.4.57-18.3.1
kernel-docs-4.4.57-18.3.2
kernel-docs-html-4.4.57-18.3.2
kernel-docs-pdf-4.4.57-18.3.2
kernel-macros-4.4.57-18.3.1
kernel-source-4.4.57-18.3.1
kernel-source-vanilla-4.4.57-18.3.1
- openSUSE Leap 42.2 (x86_64):
kernel-debug-4.4.57-18.3.1
kernel-debug-base-4.4.57-18.3.1
kernel-debug-base-debuginfo-4.4.57-18.3.1
kernel-debug-debuginfo-4.4.57-18.3.1
kernel-debug-debugsource-4.4.57-18.3.1
kernel-debug-devel-4.4.57-18.3.1
kernel-debug-devel-debuginfo-4.4.57-18.3.1
kernel-default-4.4.57-18.3.1
kernel-default-base-4.4.57-18.3.1
kernel-default-base-debuginfo-4.4.57-18.3.1
kernel-default-debuginfo-4.4.57-18.3.1
kernel-default-debugsource-4.4.57-18.3.1
kernel-default-devel-4.4.57-18.3.1
kernel-obs-build-4.4.57-18.3.1
kernel-obs-build-debugsource-4.4.57-18.3.1
kernel-obs-qa-4.4.57-18.3.1
kernel-syms-4.4.57-18.3.1
kernel-vanilla-4.4.57-18.3.1
kernel-vanilla-base-4.4.57-18.3.1
kernel-vanilla-base-debuginfo-4.4.57-18.3.1
kernel-vanilla-debuginfo-4.4.57-18.3.1
kernel-vanill...
Read the Full Advisorybsc#998106,bsc#1020048,bsc#982783).
- md/raid1: fix a use-after-free bug (bsc#998106,bsc#1020048,bsc#982783).
- md/raid1: handle flush request correctly
(bsc#998106,bsc#1020048,bsc#982783).
- md/raid1: Refactor raid1_make_request
(bsc#998106,bsc#1020048,bsc#982783).
- mm: fix set pageblock migratetype in deferred struct page init
(bnc#1027195).
- mm/page_alloc: Remove useless parameter of __free_pages_boot_core
(bnc#1027195).
- module: move add_taint_module() to a header file (fate#313296).
- net/ena: change condition for host attribute configuration (bsc#1026509).
- net/ena: change driver's default timeouts (bsc#1026509).
- net: ena: change the return type of ena_set_push_mode() to be void
(bsc#1026509).
- net: ena: Fix error return code in ena_device_init() (bsc#1026509).
- net/ena: fix ethtool RSS flow configuration (bsc#1026509).
- net/ena: fix NULL dereference when removing the driver after device
reset failed (bsc#1026509).
- net/ena: fix potential access to freed memory during device reset
(bsc#102...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.