The SUSE Linux Enterprise 12 kernel was updated to 3.12.51 to receive various security and bugfixes. Following security bugs were fixed: - CVE-2015-7799: The slhc_init function in drivers/net/slip/slhc.c in the Linux kernel did not ensure that certain slot numbers were valid, which allowed local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted PPPIOCSMAXCID ioctl call (bnc#949936). - CVE-2015-5283: The sctp_init function in net/sctp/protocol.c in the Linux kernel had an incorrect sequence of protocol-initialization steps, which allowed local users to cause a denial of service (panic or memory corruption) by creating SCTP sockets before all of the steps have finished (bnc#947155). - CVE-2015-2925: The prepend_path function in fs/dcache.c in the Linux
#814440 #867595 #904348 #921949 #924493 #930145
#933514 #935961 #936076 #936773 #939826 #939926
#940853 #941202 #941867 #942938 #944749 #945626
#946078 #947241 #947321 #947478 #948521 #948685
#948831 #949100 #949463 #949504 #949706 #949744
#950013 #950750 #950862 #950998 #951110 #951165
#951199 #951440 #951546 #952666 #952758 #953796
#953980 #954635 #955148 #955224 #955422 #955533
#955644 #956047 #956053 #956703 #956711
Cross- CVE-2015-0272 CVE-2015-2925 CVE-2015-5283
CVE-2015-5307 CVE-2015-7799 CVE-2015-7872
CVE-2015-7990 CVE-2015-8104
Affected Products:
SUSE Linux Enterprise Workstation Extension 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise ...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.