Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 438
Alerts This Week
Warning Icon 1 438

SUSE: 2014:0775-1 Critical: Privilege Escalation in Linux Kernel

suse
Calendar Grey June 11, 2014
Scroller Suse
SUSE Security Patch: Critical kernel correction addressing privilege elevation vulnerability across various SUSE operating systems.
An update that fixes one vulnerability is now available

Summary

The SUSE Linux Enterprise 11 Service Pack 3 kernel was updated to fix a critical privilege escalation security issue: * CVE-2014-3153: The futex acquisition code in kernel/futex.c can be used to gain ring0 access via the futex syscall. This could be used for privilege escalation by non-root users. (bnc#880892) Security Issue reference: * CVE-2014-3153 Indications: Everyone using the Linux Kernel on x86_64 architecture should update.

References

#880892

Cross- CVE-2014-3153

Affected Products:

SUSE Linux Enterprise Server 11 SP3 for VMware

SUSE Linux Enterprise Server 11 SP3

SUSE Linux Enterprise High Availability Extension 11 SP3

SUSE Linux Enterprise Desktop 11 SP3

SLE 11 SERVER Unsupported Extras

https://www.suse.com/security/cve/CVE-2014-3153.html

https://scc.suse.com:443/patches/

https://scc.suse.com:443/patches/

https://scc.suse.com:443/patches/

https://scc.suse.com:443/patches/

https://scc.suse.com:443/patches/

https://scc.suse.com:443/patches/

https://scc.suse.com:443/patches/

https://scc.suse.com:443/patches/

https://scc.suse.com:443/patches/

https://scc.suse.com:443/patches/

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0775-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.