Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 439
Alerts This Week
Warning Icon 1 439

SUSE: 2012:0364-1 Important: Real Time Kernel Security Fix

suse
Calendar Grey March 14, 2012
Scroller Suse
SUSE Security Bulletin: Real-Time Kernel update, tackling multiple vulnerabilities and delivering critical enhancements.
An update that solves 12 vulnerabilities and has 7 fixes is An update that solves 12 vulnerabilities and has 7 fixes is An update that solves 12 vulnerabilities and has 7 fixes is ...

Summary

The SUSE Linux Enterprise Server 11 SP1 Realtime kernel was updated to 2.6.33.20 to fix various bugs and security issues. The following security issues have been fixed: * CVE-2011-4110: KEYS: Fix a NULL pointer deref in the user-defined key type, which allowed local attackers to Oops the kernel. * CVE-2011-4081: Avoid potential NULL pointer deref in ghash, which allowed local attackers to Oops the kernel. * CVE-2010-3873: When using X.25 communication a malicious sender could corrupt data structures, causing crashes or potential code execution. Please note that X.25 needs to be setup to make this effective, which these days is usually not the case. * CVE-2011-2203: A NULL ptr dereference on mounting corrupt hfs filesystems was fixed which could be used by local attackers to crash the kernel.

References

#590980 #591293 #651219 #653260 #698450 #699709

#707096 #707288 #708877 #711203 #711539 #712366

#714001 #716901 #722406 #726788 #732021 #734056

#745881

Cross- CVE-2010-3873 CVE-2011-1576 CVE-2011-1577

CVE-2011-1833 CVE-2011-2203 CVE-2011-2918

CVE-2011-2928 CVE-2011-3191 CVE-2011-3353

CVE-2011-4081 CVE-2011-4110 CVE-2011-4326

Affected Products:

SUSE Linux Enterprise Real Time 11 SP1

https://www.suse.com/security/cve/CVE-2010-3873.html

https://www.suse.com/security/cve/CVE-2011-1576.html

https://www.suse.com/security/cve/CVE-2011-1577.html

https://www.suse.com/security/cve/CVE-2011-1833.html

https://www.suse.com/security/cve/CVE-2011-2203.html

https://www.suse.com/security/cve/CVE-2011-2918.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2012:0364-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.