Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 510
Alerts This Week
Warning Icon 1 510

SUSE: 2015:0658-1 Important: Command Buffer Overflow and DoS Risk

suse
Calendar Grey April 2, 2015
Scroller Suse
Crucial security patch for SUSE Linux kernel tackling a pair of vulnerabilities and enhancing overall system reliability and efficiency.
An update that solves two vulnerabilities and has 28 fixes An update that solves two vulnerabilities and has 28 fixes An update that solves two vulnerabilities and has 28 fixes is ...

Summary

The SUSE Linux Enterprise Server 12 kernel was updated to 3.12.39 to receive various security and bugfixes. Following security bugs were fixed: - CVE-2015-0777: The XEN usb backend could leak information to the guest system due to copying uninitialized memory. - CVE-2015-2150: Xen and the Linux kernel did not properly restrict access to PCI command registers, which might have allowed local guest users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response. The following non-security bugs were fixed: - Added Little Endian support to vtpm module (bsc#918620). - Add support for pnfs block layout. Patches not included by default yet

References

#898675 #903997 #904242 #909309 #909477 #909684

#910517 #913080 #914818 #915200 #915660 #917830

#918584 #918615 #918620 #918644 #919463 #919719

#919939 #920615 #920805 #920839 #921313 #921527

#921990 #922272 #922275 #922278 #922284 #924460

Cross- CVE-2015-0777 CVE-2015-2150

Affected Products:

SUSE Linux Enterprise Workstation Extension 12

SUSE Linux Enterprise Software Development Kit 12

SUSE Linux Enterprise Server 12

SUSE Linux Enterprise Module for Public Cloud 12

SUSE Linux Enterprise Live Patching 12

SUSE Linux Enterprise Desktop 12

https://www.suse.com/security/cve/CVE-2015-0777.html

https://www.suse.com/security/cve/CVE-2015-2150.html

https://bugzilla.suse.com/show_bug.cgi?id=898675

https://bugzilla.suse.com/show_bug.cgi?id=903997

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:0658-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.