Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

SUSE: 2015:1490-1 Important: Live Kernel Patch Against DoS Attacks

suse
Calendar Grey September 4, 2015
Scroller Suse
Addresses several vulnerabilities in the Linux kernel through a critical update from SUSE. Discover additional details regarding the recent enhancements.
An update that fixes four vulnerabilities is now available

Summary

This update contains a kernel live patch for the 3.12.43-52.6 SUSE Linux Enterprise Server 12 Kernel, fixing following security issues. - CVE-2015-5364/CVE-2015-5366: Two denial of service attacks via a flood of UDP packets with invalid checksums were fixed that could be used by remote attackers to delay execution. (bsc#939276) - CVE-2015-1805: The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel did not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allowed local users to cause a denial of service (system crash) or possibly gain privileges via a crafted application, aka an "I/O vector array overrun." (bsc#939270) - CVE-2015-4700: A BPF Jit optimization flaw could allow local users to

References

#939044 #939270 #939273 #939276

Cross- CVE-2015-1805 CVE-2015-4700 CVE-2015-5364

CVE-2015-5366

Affected Products:

SUSE Linux Enterprise Live Patching 12

https://www.suse.com/security/cve/CVE-2015-1805.html

https://www.suse.com/security/cve/CVE-2015-4700.html

https://www.suse.com/security/cve/CVE-2015-5364.html

https://www.suse.com/security/cve/CVE-2015-5366.html

https://bugzilla.suse.com/939044

https://bugzilla.suse.com/939270

https://bugzilla.suse.com/939273

https://bugzilla.suse.com/939276

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:1490-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.