Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE: 2015:0178-1 critical: kernel denial-of-service patch

suse
Calendar Grey January 30, 2015
Dist Suse Esm H88
Tackling vulnerabilities in the Linux Kernel through essential patches and enhancements for openSUSE releases.
An update that solves 5 vulnerabilities and has 59 fixes is An update that solves 5 vulnerabilities and has 59 fixes is An update that solves 5 vulnerabilities and has 59 fixes is ...

Summary

The SUSE Linux Enterprise 12 kernel was updated to 3.12.36 to receive various security and bugfixes. Following security bugs were fixed: - CVE-2014-8559: The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 did not properly maintain the semantics of rename_lock, which allowed local users to cause a denial of service (deadlock and system hang) via a crafted application (bnc#903640). - CVE-2014-9420: The rock_continue function in fs/isofs/rock.c in the Linux kernel through 3.18.1 did not restrict the number of Rock Ridge continuation entries, which allowed local users to cause a denial of service (infinite loop, and system crash or hang) via a crafted iso9660 image (bnc#906545 911325). - CVE-2014-3690: arch/x86/kvm/vmx.c in the KVM subsystem in the Linux

References

#800255 #809493 #829110 #856659 #862374 #873252

#875220 #884407 #887108 #887597 #889192 #891086

#891277 #893428 #895387 #895814 #902232 #902346

#902349 #903279 #903640 #904053 #904177 #904659

#904969 #905087 #905100 #906027 #906140 #906545

#907069 #907325 #907536 #907593 #907714 #907818

#907969 #907970 #907971 #907973 #908057 #908163

#908198 #908803 #908825 #908904 #909077 #909092

#909095 #909829 #910249 #910697 #911181 #911325

#912129 #912278 #912281 #912290 #912514 #912705

#912946 #913233 #913387 #913466

Cross- CVE-2014-3687 CVE-2014-3690 CVE-2014-8559

CVE-2014-9420 CVE-2014-9585

Affected Products:

SUSE Linux Enterprise Workstation Extension 12

SUSE Linux Enterprise Software Development Kit 12

SUSE L...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:0178-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here