Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

openSUSE Leap 42.3: 2017:2741-1 Important Kernel DoS Issues Fixed

opensuse
Calendar Grey October 17, 2017
Dist Opensuse Esm H88
Crucial patch released for Fedora resolves multiple vulnerabilities in the Linux kernel. Safeguard your system's integrity and performance!
An update that solves four vulnerabilities and has 33 fixes is now available.

Description

The openSUSE Leap 42.3 kernel was updated to 4.4.90 to receive various

security and bugfixes.

The following security bugs were fixed:

- CVE-2017-1000252: The KVM subsystem in the Linux kernel allowed guest OS

users to cause a denial of service (assertion failure, and hypervisor

hang or crash) via an out-of bounds guest_irq value, related to

arch/x86/kvm/vmx.c and virt/kvm/eventfd.c (bnc#1058038).

- CVE-2017-14489: The iscsi_if_rx function in

drivers/scsi/scsi_transport_iscsi.c in the Linux kernel allowed local

users to cause a denial of service (panic) by leveraging incorrect

length validation (bnc#1059051).

- CVE-2017-12153: A security flaw was discovered in the

nl80211_set_rekey_data() function in net/wireless/nl80211.c in the Linux

kernel This function did not check whether the required attributes are

present in a Netlink request. This request can be issued by a user with

the CAP_NET_ADMIN capability and may...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2017-1160=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.3 (noarch):

kernel-devel-4.4.90-28.1

kernel-docs-4.4.90-28.2

kernel-docs-html-4.4.90-28.2

kernel-docs-pdf-4.4.90-28.2

kernel-macros-4.4.90-28.1

kernel-source-4.4.90-28.1

kernel-source-vanilla-4.4.90-28.1

- openSUSE Leap 42.3 (x86_64):

kernel-debug-4.4.90-28.1

kernel-debug-base-4.4.90-28.1

kernel-debug-base-debuginfo-4.4.90-28.1

kernel-debug-debuginfo-4.4.90-28.1

kernel-debug-debugsource-4.4.90-28.1

kernel-debug-devel-4.4.90-28.1

kernel-debug-devel-debuginfo-4.4.90-28.1

kernel-default-4.4.90-28.1

kernel-default-base-4.4.90-28.1

kernel-default-base-debuginfo-4.4.90-28.1

kernel-default-debuginfo-4.4.90-28.1

kernel-default-debugsource-4.4.90-28.1

kernel-default-devel-4.4.90-28.1

kernel-obs-build-4.4.90-28.1

kernel-obs-build-debugsource-4.4.90-28.1

kernel-obs-qa-4.4.90-28.1

kernel-syms-4.4.90-28.1

kernel-vanilla-4.4.90-28.1

kernel-vanilla-base-4.4.90-28.1

kernel-vanilla-base-debuginfo-4.4.90-28.1

kernel-vanilla-debuginfo-4.4.90-28.1

kernel-vanilla-debugsource-4.4.90-28.1

kernel-vanilla-devel-4.4.90-28....

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2017-1000252.html

https://www.suse.com/security/cve/CVE-2017-12153.html

https://www.suse.com/security/cve/CVE-2017-12154.html

https://www.suse.com/security/cve/CVE-2017-14489.html

https://bugzilla.suse.com/1005778

https://bugzilla.suse.com/1005780

https://bugzilla.suse.com/1005781

https://bugzilla.suse.com/1012382

https://bugzilla.suse.com/1022967

https://bugzilla.suse.com/1036215

https://bugzilla.suse.com/1036737

https://bugzilla.suse.com/1037579

https://bugzilla.suse.com/1037890

https://bugzilla.suse.com/1043598

https://bugzilla.suse.com/1044503

https://bugzilla.suse.com/1047238

https://bugzilla.suse.com/1051987

https://bugzilla.suse.com/1052593

https://bugzilla.suse.com/1053043

https://bugzilla.suse.com/1055493

https://bugzilla.suse.com/1055755

https://bugzilla.suse.com/1056686

https://bugzilla.suse.com/1057383

https://bugzilla.suse.com/1057498

https://bugzilla.suse.com/1058038

https://bugzilla.suse.com/1058410

https://bugzilla.suse.com/1058507

https://bugzilla.suse.com/1...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2017:2741-1
Rating: important
Affected Products: openSUSE Leap 42.3 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here