Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

openSUSE: 2017:2905-1 Important: Linux Kernel Fixes Must Update

opensuse
Calendar Grey October 29, 2017
Dist Opensuse Esm H88
This Fedora Security alert addresses revisions for the Linux Kernel aimed at resolving urgent system vulnerabilities and enhancing overall system stability.
An update that solves three vulnerabilities and has 32 An update that solves three vulnerabilities and has 32 An update that solves three vulnerabilities and has 32 fixes is now av...

Description

The openSUSE Leap 42.2 kernel was updated to 4.4.92 to receive various

security and bugfixes.

The following security bugs were fixed:

- CVE-2017-13080: Wi-Fi Protected Access (WPA and WPA2) allowed

reinstallation of the Group Temporal Key (GTK) during the group key

handshake, allowing an attacker within radio range to replay frames from

access points to clients (bnc#1063667).

- CVE-2017-15265: Race condition in the ALSA subsystem in the Linux kernel

allowed local users to cause a denial of service (use-after-free) or

possibly have unspecified other impact via crafted /dev/snd/seq ioctl

calls, related to sound/core/seq/seq_clientmgr.c and

sound/core/seq/seq_ports.c (bnc#1062520).

- CVE-2017-15649: net/packet/af_packet.c in the Linux kernel allowed local

users to gain privileges via crafted system calls that trigger

mishandling of packet_fanout data structures, because of a race

condition (involving fanout_add and...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.2:

zypper in -t patch openSUSE-2017-1224=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.2 (noarch):

kernel-devel-4.4.92-18.36.1

kernel-docs-4.4.92-18.36.2

kernel-docs-html-4.4.92-18.36.2

kernel-docs-pdf-4.4.92-18.36.2

kernel-macros-4.4.92-18.36.1

kernel-source-4.4.92-18.36.1

kernel-source-vanilla-4.4.92-18.36.1

- openSUSE Leap 42.2 (x86_64):

kernel-debug-4.4.92-18.36.1

kernel-debug-base-4.4.92-18.36.1

kernel-debug-base-debuginfo-4.4.92-18.36.1

kernel-debug-debuginfo-4.4.92-18.36.1

kernel-debug-debugsource-4.4.92-18.36.1

kernel-debug-devel-4.4.92-18.36.1

kernel-debug-devel-debuginfo-4.4.92-18.36.1

kernel-default-4.4.92-18.36.1

kernel-default-base-4.4.92-18.36.1

kernel-default-base-debuginfo-4.4.92-18.36.1

kernel-default-debuginfo-4.4.92-18.36.1

kernel-default-debugsource-4.4.92-18.36.1

kernel-default-devel-4.4.92-18.36.1

kernel-obs-build-4.4.92-18.36.1

kernel-obs-build-debugsource-4.4.92-18.36.1

kernel-obs-qa-4.4.92-18.36.1

kernel-syms-4.4.92-18.36.1

kernel-vanilla-4.4.92-18.36.1

kernel-vanilla-base-4.4.92-18.36.1

kernel-vanilla-base-debuginfo-4.4.92-18.36.1

kernel-vanilla-debuginfo...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2017-13080.html

https://www.suse.com/security/cve/CVE-2017-15265.html

https://www.suse.com/security/cve/CVE-2017-15649.html

https://bugzilla.suse.com/1012382

https://bugzilla.suse.com/1020645

https://bugzilla.suse.com/1022595

https://bugzilla.suse.com/1022600

https://bugzilla.suse.com/1025461

https://bugzilla.suse.com/1028971

https://bugzilla.suse.com/1034048

https://bugzilla.suse.com/1055567

https://bugzilla.suse.com/1056427

https://bugzilla.suse.com/1059863

https://bugzilla.suse.com/1060985

https://bugzilla.suse.com/1061451

https://bugzilla.suse.com/1062520

https://bugzilla.suse.com/1062962

https://bugzilla.suse.com/1063460

https://bugzilla.suse.com/1063475

https://bugzilla.suse.com/1063501

https://bugzilla.suse.com/1063509

https://bugzilla.suse.com/1063520

https://bugzilla.suse.com/1063667

https://bugzilla.suse.com/1063695

https://bugzilla.suse.com/1064206

https://bugzilla.suse.com/1064388

https://bugzilla.suse.com/964944

https://bugzilla.suse.com/966170

https://bugzilla.s...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2017:2905-1
Rating: important
Affected Products: openSUSE Leap 42.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here