Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE: 2014:0536-1 Important: 42 Kernel Fixes And Security Issues

suse
Calendar Grey April 16, 2014
Scroller Suse
This Fedora upgrade resolves 37 vulnerabilities in the OS core, improving overall system integrity with essential patches.
An update that solves 42 vulnerabilities and has 8 fixes is An update that solves 42 vulnerabilities and has 8 fixes is An update that solves 42 vulnerabilities and has 8 fixes is ...

Summary

The SUSE Linux Enterprise Server 10 Service Pack 4 LTSS kernel has been updated to fix various security issues and several bugs. The following security issues have been addressed: * CVE-2011-2492: The bluetooth subsystem in the Linux kernel before 3.0-rc4 does not properly initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel memory via a crafted getsockopt system call, related to (1) the l2cap_sock_getsockopt_old function in net/bluetooth/l2cap_sock.c and (2) the rfcomm_sock_getsockopt_old function in net/bluetooth/rfcomm/sock.c. (bnc#702014) * CVE-2011-2494: kernel/taskstats.c in the Linux kernel before 3.1 allows local users to obtain sensitive I/O statistics by sending taskstats commands to a netlink

References

#702014 #703156 #790920 #798050 #805226 #806219

#808827 #809889 #809891 #809892 #809893 #809894

#809898 #809899 #809900 #809901 #809903 #811354

#816668 #820338 #822722 #823267 #824295 #825052

#826102 #826551 #827362 #827749 #827750 #827855

#827983 #828119 #830344 #831058 #832603 #835839

#842239 #843430 #845028 #847672 #848321 #849765

#850241 #851095 #852558 #853501 #857597 #858869

#858870 #858872

Cross- CVE-2011-2492 CVE-2011-2494 CVE-2012-6537

CVE-2012-6539 CVE-2012-6540 CVE-2012-6541

CVE-2012-6542 CVE-2012-6544 CVE-2012-6545

CVE-2012-6546 CVE-2012-6547 CVE-2012-6549

CVE-2013-0343 CVE-2013-0914 CVE-2013-1827

CVE-2013-2141 CVE-2013-2164 CVE-2013-2206

CVE-2013-2232 CVE-2013-2234 CVE-2013-2237

...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0536-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.