Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

SUSE: 2015:2194-1 Important: 8 Issues And Bug Fixes In Kernel

suse
Calendar Grey December 4, 2015
Dist Suse Esm H88
SUSE Security Patch addresses 10 vulnerabilities in the Linux Kernel, delivering critical bug corrections and necessary enhancements.
An update that solves 8 vulnerabilities and has 45 fixes is An update that solves 8 vulnerabilities and has 45 fixes is An update that solves 8 vulnerabilities and has 45 fixes is ...

Summary

The SUSE Linux Enterprise 12 kernel was updated to 3.12.51 to receive various security and bugfixes. Following security bugs were fixed: - CVE-2015-7799: The slhc_init function in drivers/net/slip/slhc.c in the Linux kernel did not ensure that certain slot numbers were valid, which allowed local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted PPPIOCSMAXCID ioctl call (bnc#949936). - CVE-2015-5283: The sctp_init function in net/sctp/protocol.c in the Linux kernel had an incorrect sequence of protocol-initialization steps, which allowed local users to cause a denial of service (panic or memory corruption) by creating SCTP sockets before all of the steps have finished (bnc#947155). - CVE-2015-2925: The prepend_path function in fs/dcache.c in the Linux

References

#814440 #867595 #904348 #921949 #924493 #930145

#933514 #935961 #936076 #936773 #939826 #939926

#940853 #941202 #941867 #942938 #944749 #945626

#946078 #947241 #947321 #947478 #948521 #948685

#948831 #949100 #949463 #949504 #949706 #949744

#950013 #950750 #950862 #950998 #951110 #951165

#951199 #951440 #951546 #952666 #952758 #953796

#953980 #954635 #955148 #955224 #955422 #955533

#955644 #956047 #956053 #956703 #956711

Cross- CVE-2015-0272 CVE-2015-2925 CVE-2015-5283

CVE-2015-5307 CVE-2015-7799 CVE-2015-7872

CVE-2015-7990 CVE-2015-8104

Affected Products:

SUSE Linux Enterprise Workstation Extension 12

SUSE Linux Enterprise Software Development Kit 12

SUSE Linux Enterprise Server 12

SUSE Linux Enterprise ...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:2194-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here