Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

SUSE 11 SP3: 2015:1376-1 Critical Kernel Crash Vulnerability Resolved

suse
Calendar Grey August 12, 2015
Dist Suse Esm H88
The latest SUSE Real Time Kernel update addresses 15 vulnerabilities, notably including severe crash scenarios and potential elevation of privileges.
An update that solves 15 vulnerabilities and has 71 fixes An update that solves 15 vulnerabilities and has 71 fixes An update that solves 15 vulnerabilities and has 71 fixes is now...

Summary

The SUSE Linux Enterprise 11 Service Pack 3 RealTime Extension kernel was updated to fix various bugs and security issues. The following vulnerabilities have been fixed: CVE-2015-3636: A missing sk_nulls_node_init() in ping_unhash() inside the ipv4 stack can cause crashes if a disconnect is followed by another connect() attempt. (bnc#929525) CVE-2015-3339: Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows local users to gain privileges by executing a setuid program at a time instant when a chown to root is in progress, and the ownership is changed but the setuid bit is not yet stripped. (bnc#928130) CVE-2015-3331: The __driver_rfc4106_decrypt function in arch/x86/crypto/aesni-intel_glue.c in the Linux kernel before 3.19.3 does

References

#831029 #877456 #889221 #891212 #891641 #900881

#902286 #904242 #904883 #904901 #906027 #908706

#909309 #909312 #909477 #909684 #910517 #911326

#912202 #912741 #913080 #913598 #914726 #914742

#914818 #914987 #915045 #915200 #915577 #916521

#916848 #917093 #917120 #917648 #917684 #917830

#917839 #918333 #919007 #919018 #919357 #919463

#919589 #919682 #919808 #921769 #922583 #923344

#924142 #924271 #924333 #924340 #925012 #925370

#925443 #925567 #925729 #926016 #926240 #926439

#926767 #927190 #927257 #927262 #927338 #928122

#928130 #928142 #928333 #928970 #929145 #929148

#929283 #929525 #929647 #930145 #930171 #930226

#930284 #930401 #930669 #930786 #930788 #931014

#931015 #931850

Cross- CVE-2014-80...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:1376-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here