The SUSE Linux Enterprise 11 Service Pack 3 RealTime Extension kernel was updated to fix various bugs and security issues. The following vulnerabilities have been fixed: CVE-2015-3636: A missing sk_nulls_node_init() in ping_unhash() inside the ipv4 stack can cause crashes if a disconnect is followed by another connect() attempt. (bnc#929525) CVE-2015-3339: Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows local users to gain privileges by executing a setuid program at a time instant when a chown to root is in progress, and the ownership is changed but the setuid bit is not yet stripped. (bnc#928130) CVE-2015-3331: The __driver_rfc4106_decrypt function in arch/x86/crypto/aesni-intel_glue.c in the Linux kernel before 3.19.3 does
#831029 #877456 #889221 #891212 #891641 #900881
#902286 #904242 #904883 #904901 #906027 #908706
#909309 #909312 #909477 #909684 #910517 #911326
#912202 #912741 #913080 #913598 #914726 #914742
#914818 #914987 #915045 #915200 #915577 #916521
#916848 #917093 #917120 #917648 #917684 #917830
#917839 #918333 #919007 #919018 #919357 #919463
#919589 #919682 #919808 #921769 #922583 #923344
#924142 #924271 #924333 #924340 #925012 #925370
#925443 #925567 #925729 #926016 #926240 #926439
#926767 #927190 #927257 #927262 #927338 #928122
#928130 #928142 #928333 #928970 #929145 #929148
#929283 #929525 #929647 #930145 #930171 #930226
#930284 #930401 #930669 #930786 #930788 #931014
#931015 #931850
Cross- CVE-2014-80...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.