Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

openSUSE Leap 42.2 Security Advisory: Important Kernel DoS Issues

opensuse
Calendar Grey April 1, 2017
Dist Opensuse Esm H88
Essential openSUSE patch addresses 11 kernel vulnerabilities, including potential denial of service attacks.
An update that solves 11 vulnerabilities and has 41 fixes An update that solves 11 vulnerabilities and has 41 fixes An update that solves 11 vulnerabilities and has 41 fixes is now...

Description

The openSUSE Leap 42.2 kernel was updated to 4.4.56 fix various security

issues and bugs.

The following security bugs were fixed:

- CVE-2017-7184: The xfrm_replay_verify_len function in

net/xfrm/xfrm_user.c in the Linux kernel did not validate certain size

data after an XFRM_MSG_NEWAE update, which allowed local users to obtain

root privileges or cause a denial of service (heap-based out-of-bounds

access) by leveraging the CAP_NET_ADMIN capability, as demonstrated

during a Pwn2Own competition at CanSecWest 2017 for the Ubuntu 16.10

linux-image-* package 4.8.0.41.52 (bnc#1030573).

- CVE-2016-10200: Race condition in the L2TPv3 IP Encapsulation feature in

the Linux kernel allowed local users to gain privileges or cause a

denial of service (use-after-free) by making multiple bind system calls

without properly ascertaining whether a socket has the SOCK_ZAPPED

status, related to net/l2tp/l2tp_ip.c and net/l2tp/l2tp_ip6.c

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.2:

zypper in -t patch openSUSE-2017-418=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.2 (noarch):

kernel-devel-4.4.57-18.3.1

kernel-docs-4.4.57-18.3.2

kernel-docs-html-4.4.57-18.3.2

kernel-docs-pdf-4.4.57-18.3.2

kernel-macros-4.4.57-18.3.1

kernel-source-4.4.57-18.3.1

kernel-source-vanilla-4.4.57-18.3.1

- openSUSE Leap 42.2 (x86_64):

kernel-debug-4.4.57-18.3.1

kernel-debug-base-4.4.57-18.3.1

kernel-debug-base-debuginfo-4.4.57-18.3.1

kernel-debug-debuginfo-4.4.57-18.3.1

kernel-debug-debugsource-4.4.57-18.3.1

kernel-debug-devel-4.4.57-18.3.1

kernel-debug-devel-debuginfo-4.4.57-18.3.1

kernel-default-4.4.57-18.3.1

kernel-default-base-4.4.57-18.3.1

kernel-default-base-debuginfo-4.4.57-18.3.1

kernel-default-debuginfo-4.4.57-18.3.1

kernel-default-debugsource-4.4.57-18.3.1

kernel-default-devel-4.4.57-18.3.1

kernel-obs-build-4.4.57-18.3.1

kernel-obs-build-debugsource-4.4.57-18.3.1

kernel-obs-qa-4.4.57-18.3.1

kernel-syms-4.4.57-18.3.1

kernel-vanilla-4.4.57-18.3.1

kernel-vanilla-base-4.4.57-18.3.1

kernel-vanilla-base-debuginfo-4.4.57-18.3.1

kernel-vanilla-debuginfo-4.4.57-18.3.1

kernel-vanill...

Read the Full Advisory

References

bsc#998106,bsc#1020048,bsc#982783).

- md/raid1: fix a use-after-free bug (bsc#998106,bsc#1020048,bsc#982783).

- md/raid1: handle flush request correctly

(bsc#998106,bsc#1020048,bsc#982783).

- md/raid1: Refactor raid1_make_request

(bsc#998106,bsc#1020048,bsc#982783).

- mm: fix set pageblock migratetype in deferred struct page init

(bnc#1027195).

- mm/page_alloc: Remove useless parameter of __free_pages_boot_core

(bnc#1027195).

- module: move add_taint_module() to a header file (fate#313296).

- net/ena: change condition for host attribute configuration (bsc#1026509).

- net/ena: change driver's default timeouts (bsc#1026509).

- net: ena: change the return type of ena_set_push_mode() to be void

(bsc#1026509).

- net: ena: Fix error return code in ena_device_init() (bsc#1026509).

- net/ena: fix ethtool RSS flow configuration (bsc#1026509).

- net/ena: fix NULL dereference when removing the driver after device

reset failed (bsc#1026509).

- net/ena: fix potential access to freed memory during device reset

(bsc#102...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2017:0907-1
Rating: important
Affected Products: openSUSE Leap 42.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here