Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

SUSE Linux Enterprise 11 SP2: 2013:0341-1 Important: Kernel Race Condition

suse
Calendar Grey February 25, 2013
Scroller Suse
Crucial SUSE patch resolves a critical vulnerability in the Linux kernel. Remember to restart your system post-installation.
An update that solves one vulnerability and has two fixes An update that solves one vulnerability and has two fixes An update that solves one vulnerability and has two fixes is now...

Summary

The SUSE Linux Enterprise 11 SP2 kernel has been updated to fix two issues: One severe security issue: * CVE-2013-0871: A race condition in ptrace(2) could be used by local attackers to crash the kernel and/or execute code in kernel context. One severe regression issue: * A regression in UNIX domain socket credential passing. The default disabling of passing credentials caused regression in some software packages that did not expect this. One major software package affected by this was the Open Enterprise Server stack. Security Issue reference: * CVE-2013-0871 Indications: Everyone using the Linux Kernel on x86_64 architecture should update.

References

#779577 #803056 #804154

Cross- CVE-2013-0871

Affected Products:

SUSE Linux Enterprise Server 11 SP2 for VMware

SUSE Linux Enterprise Server 11 SP2

SUSE Linux Enterprise High Availability Extension 11 SP2

SUSE Linux Enterprise Desktop 11 SP2

SLE 11 SERVER Unsupported Extras

https://www.suse.com/security/cve/CVE-2013-0871.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2013:0341-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.