Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

SUSE: 2015:1487-1 Important: Kernel Patch for Security Fixes

suse
Calendar Grey September 4, 2015
Scroller Suse
Update resolves 10 vulnerabilities in Ubuntu Linux Kernel with significant real-time refresh for improved protection and reliability.
An update that fixes 8 vulnerabilities is now available

Summary

This update contains a kernel live patch for the 3.12.38-44 SUSE Linux Enterprise Server 12 Kernel, fixing following security issues. - CVE-2015-3339: A race condition in the prepare_binprm function in fs/exec.c in the Linux kernel allowed local users to gain privileges by executing a setuid program at a time instant when a chown to root is in progress, and the ownership is changed but the setuid bit is not yet stripped. (bsc#939263 bsc#939044) - CVE-2015-3636: The ping_unhash function in net/ipv4/ping.c in the Linux kernel did not initialize a certain list data structure during an unhash operation, which allowed local users to gain privileges or cause a denial of service (use-after-free and system crash) by leveraging the ability to make a SOCK_DGRAM socket system call for the IPPROTO_ICMP

References

#939044 #939241 #939262 #939263 #939270 #939273

#939276 #939277

Cross- CVE-2014-8159 CVE-2015-1805 CVE-2015-3331

CVE-2015-3339 CVE-2015-3636 CVE-2015-4700

CVE-2015-5364 CVE-2015-5366

Affected Products:

SUSE Linux Enterprise Live Patching 12

https://www.suse.com/security/cve/CVE-2014-8159.html

https://www.suse.com/security/cve/CVE-2015-1805.html

https://www.suse.com/security/cve/CVE-2015-3331.html

https://www.suse.com/security/cve/CVE-2015-3339.html

https://www.suse.com/security/cve/CVE-2015-3636.html

https://www.suse.com/security/cve/CVE-2015-4700.html

https://www.suse.com/security/cve/CVE-2015-5364.html

https://www.suse.com/security/cve/CVE-2015-5366.html

https://bugzilla.suse.com/939044

https://bugzilla.suse.com/939241

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:1487-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.