Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

SUSE: 2014:0696-1 Important: Kernel Security Update for DoS Issues

suse
Calendar Grey May 22, 2014
Scroller Suse
Patch addresses 21 security flaws related to the Linux kernel in SUSE. Urgent steps advised to enhance protection.
An update that solves 21 vulnerabilities and has 32 fixes An update that solves 21 vulnerabilities and has 32 fixes An update that solves 21 vulnerabilities and has 32 fixes is now...

Summary

The SUSE Linux Enterprise Server 11 SP2 LTSS kernel received a roll-up update to fix security and non-security issues. The following security bugs have been fixed: * CVE-2013-4470: The Linux kernel before 3.12, when UDP Fragmentation Offload (UFO) is enabled, does not properly initialize certain data structures, which allows local users to cause a denial of service (memory corruption and system crash) or possibly gain privileges via a crafted application that uses the UDP_CORK option in a setsockopt system call and sends both short and long packets, related to the ip_ufo_append_data function in net/ipv4/ip_output.c and the ip6_ufo_append_data function in net/ipv6/ip6_output.c. (bnc#847672) * CVE-2013-4579: The ath9k_htc_set_bssid_mask function in

References

#708296 #736697 #746500 #814788 #819351 #831029

#836347 #843185 #844513 #847672 #849364 #851426

#852488 #852553 #852967 #853455 #854025 #855347

#855885 #856083 #857499 #857643 #858280 #858534

#858604 #858869 #858870 #858872 #862429 #863300

#863335 #864025 #864833 #865307 #865310 #865330

#865342 #865783 #866102 #867953 #868528 #868653

#869033 #869563 #870801 #871325 #871561 #871861

#873061 #874108 #875690 #875798 #876102

Cross- CVE-2013-4470 CVE-2013-4579 CVE-2013-6382

CVE-2013-6885 CVE-2013-7263 CVE-2013-7264

CVE-2013-7265 CVE-2013-7339 CVE-2014-0069

CVE-2014-0101 CVE-2014-0196 CVE-2014-1444

CVE-2014-1445 CVE-2014-1446 CVE-2014-1737

CVE-2014-1738 CVE-2014-1874 CVE-2014-2039

CVE-2014-2523 CVE-2014-2678 C...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0696-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.