Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

SUSE Linux Enterprise 11 SP3: 2014:0910-1 Critical: Linux Kernel Issues

suse
Calendar Grey July 17, 2014
Scroller Suse
Important update for the SUSE Linux kernel addressing multiple security flaws to enhance system safety. Restart required post-installation.
An update that solves 29 vulnerabilities and has 76 fixes An update that solves 29 vulnerabilities and has 76 fixes An update that solves 29 vulnerabilities and has 76 fixes is now...

Summary

The SUSE Linux Enterprise 11 Service Pack 3 kernel has been updated to fix various bugs and security issues. The following security bugs have been fixed: * CVE-2012-2372: The rds_ib_xmit function in net/rds/ib_send.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel 3.7.4 and earlier allows local users to cause a denial of service (BUG_ON and kernel panic) by establishing an RDS connection with the source IP address equal to the IPoIB interfaces own IP address, as demonstrated by rds-ping. (bnc#767610) * CVE-2013-2929: The Linux kernel before 3.12.2 does not properly use the get_dumpable function, which allows local users to bypass intended ptrace restrictions or obtain sensitive information from IA64 scratch registers via a crafted application, related to kernel/ptrace.c and

References

#767610 #786450 #792271 #821619 #832710 #837563

#840524 #846404 #846690 #847652 #850915 #851426

#851603 #852553 #855126 #857926 #858869 #858870

#858872 #859840 #861636 #861980 #862429 #862934

#863300 #863335 #863410 #863873 #864404 #864464

#865310 #865330 #865882 #866081 #866102 #866615

#866800 #866864 #867362 #867517 #867531 #867723

#867953 #868488 #868528 #868653 #868748 #869033

#869414 #869563 #869934 #870173 #870335 #870450

#870496 #870498 #870576 #870591 #870618 #870877

#870958 #871561 #871634 #871676 #871728 #871854

#871861 #871899 #872188 #872540 #872634 #873061

#873374 #873463 #874108 #874145 #874440 #874577

#875386 #876102 #876114 #876176 #876463 #877013

#877257 #877497 #877775 #878115 #878...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0910-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.