Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE: 2015:1727-1 Important: Kernel-Source Security Update - DoS Issues

suse
Calendar Grey October 13, 2015
Scroller Suse
SUSE Kernel-source security patch resolves 8 vulnerabilities, implementing 51 enhancements for bolstered system security.
An update that solves 7 vulnerabilities and has 44 fixes is An update that solves 7 vulnerabilities and has 44 fixes is An update that solves 7 vulnerabilities and has 44 fixes is ...

Summary

The SUSE Linux Enterprise 12 kernel was updated to 3.12.48-52.27 to receive various security and bugfixes. Following security bugs were fixed: * CVE-2015-7613: A flaw was found in the Linux kernel IPC code that could lead to arbitrary code execution. The ipc_addid() function initialized a shared object that has unset uid/gid values. Since the fields are not initialized, the check can falsely succeed. (bsc#948536) * CVE-2015-5156: When a guests KVM network devices is in a bridge configuration the kernel can create a situation in which packets are fragmented in an unexpected fashion. The GRO functionality can create a situation in which multiple SKB's are chained together in a single packets fraglist (by design). (bsc#940776) * CVE-2015-5157: arch/x86/entry/entry_64.S in the Linux kernel before

References

#856382 #886785 #898159 #907973 #908950 #912183

#914818 #916543 #920016 #922071 #924722 #929092

#929871 #930813 #932285 #932350 #934430 #934942

#934962 #936556 #936773 #937609 #937612 #937613

#937616 #938550 #938706 #938891 #938892 #938893

#939145 #939266 #939716 #939834 #939994 #940398

#940545 #940679 #940776 #940912 #940925 #940965

#941098 #941305 #941908 #941951 #942160 #942204

#942307 #942367 #948536

Cross- CVE-2015-5156 CVE-2015-5157 CVE-2015-5283

CVE-2015-5697 CVE-2015-6252 CVE-2015-6937

CVE-2015-7613

Affected Products:

SUSE Linux Enterprise Workstation Extension 12

SUSE Linux Enterprise Software Development Kit 12

SUSE Linux Enterprise Server 12

SUSE Linux Enterprise Module for Public Cloud 12

...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:1727-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.