Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE: 2015:0529-1 Important: Kernel Security Fixes and Updates

suse
Calendar Grey March 18, 2015
Dist Suse Esm H88
Crucial SUSE Kernel upgrade addresses 8 security vulnerabilities and incorporates multiple bug corrections for improved reliability.
An update that solves 8 vulnerabilities and has 53 fixes is An update that solves 8 vulnerabilities and has 53 fixes is An update that solves 8 vulnerabilities and has 53 fixes is ...

Summary

The SUSE Linux Enterprise 12 kernel was updated to 3.12.38 to receive various security and bugfixes. This update contains the following feature enablements: - The remote block device (rbd) and ceph drivers have been enabled and are now supported. (FATE#318350) These can be used e.g. for accessing the SUSE Enterprise Storage product services. - Support for Intel Select Bay trail CPUs has been added. (FATE#316038) Following security issues were fixed: - CVE-2014-9419: The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel through 3.18.1 did not ensure that Thread Local Storage (TLS) descriptors were loaded before proceeding with other steps, which made it easier for local users to bypass the ASLR protection mechanism via a crafted application that reads a TLS base address (bnc#911326).

References

#799216 #800255 #860346 #875220 #877456 #884407

#895805 #896484 #897736 #898687 #900270 #902286

#902346 #902349 #903640 #904177 #904883 #904899

#904901 #905100 #905304 #905329 #905482 #905783

#906196 #907069 #908069 #908322 #908825 #908904

#909829 #910322 #911326 #912202 #912654 #912705

#913059 #914112 #914126 #914254 #914291 #914294

#914300 #914457 #914464 #914726 #915188 #915322

#915335 #915425 #915454 #915456 #915550 #915660

#916107 #916513 #916646 #917089 #917128 #918161

#918255

Cross- CVE-2014-3673 CVE-2014-3687 CVE-2014-7822

CVE-2014-7841 CVE-2014-8160 CVE-2014-8559

CVE-2014-9419 CVE-2014-9584

Affected Products:

SUSE Linux Enterprise Workstation Extension 12

SUSE Linux Enterprise Software Develop...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:0529-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here