Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

SUSE: 2014:0807-1 Important: Multiple Kernel Security Threats

suse
Calendar Grey June 18, 2014
Scroller Suse
SUSE reveals an urgent security patch for the Linux Kernel tackling various weaknesses and providing solutions.
An update that solves 17 vulnerabilities and has 9 fixes is An update that solves 17 vulnerabilities and has 9 fixes is An update that solves 17 vulnerabilities and has 9 fixes is ...

Summary

The SUSE Linux Enterprise Server 11 SP1 LTSS kernel received a roll-up update to fix security and non-security issues. The following security issues have been fixed: * CVE-2014-3153: The futex acquisition code in kernel/futex.c can be used to gain ring0 access via the futex syscall. This could be used for privilege escalation for non root users. (bnc#880892) * CVE-2012-6647: The futex_wait_requeue_pi function in kernel/futex.c in the Linux kernel before 3.5.1 does not ensure that calls have two different futex addresses, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted FUTEX_WAIT_REQUEUE_PI command. (bnc#878289) * CVE-2013-6382: Multiple buffer underflows in the XFS implementation

References

#630970 #661605 #663516 #761774 #792407 #852553

#852967 #854634 #854743 #856756 #857643 #863335

#865310 #866102 #868049 #868488 #868653 #869563

#871561 #873070 #874108 #875690 #875798 #876102

#878289 #880892

Cross- CVE-2012-6647 CVE-2013-6382 CVE-2013-6885

CVE-2013-7027 CVE-2013-7263 CVE-2013-7264

CVE-2013-7265 CVE-2013-7339 CVE-2014-0101

CVE-2014-0196 CVE-2014-1737 CVE-2014-1738

CVE-2014-1874 CVE-2014-2523 CVE-2014-2678

CVE-2014-3122 CVE-2014-3153

Affected Products:

SUSE Linux Enterprise Server 11 SP1 LTSS

SLE 11 SERVER Unsupported Extras

https://www.suse.com/security/cve/CVE-2012-6647.html

https://www.suse.com/security/cve/CVE-2013-6382.html

https://www.suse.com/security/cve/CVE-2013-6885.html

https://www.suse.com/security/cve/CVE-2013-7027.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0807-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.