Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

SUSE: 2015:2292-1 Critical: Kernel Denial of Service Fixes Details

suse
Calendar Grey December 17, 2015
Dist Suse Esm H88
CentOS Security Release: Addressing 5 severe vulnerabilities in the Unix Kernel along with 40 significant upgrades. Ensure your safety!
An update that solves 7 vulnerabilities and has 54 fixes is An update that solves 7 vulnerabilities and has 54 fixes is An update that solves 7 vulnerabilities and has 54 fixes is ...

Summary

The SUSE Linux Enterprise 12 SP1 kernel was updated to 3.12.51 to receive various security and bugfixes. Following features were added: - hwrng: Add a driver for the hwrng found in power7+ systems (fate#315784). Following security bugs were fixed: - CVE-2015-8215: net/ipv6/addrconf.c in the IPv6 stack in the Linux kernel did not validate attempted changes to the MTU value, which allowed context-dependent attackers to cause a denial of service (packet loss) via a value that is (1) smaller than the minimum compliant value or (2) larger than the MTU of an interface, as demonstrated by a Router Advertisement (RA) message that is not validated by a daemon, a different vulnerability than CVE-2015-0272. (bsc#955354) - CVE-2015-5156: The virtnet_probe function in drivers/net/virtio_net.c in

References

#758040 #814440 #904348 #921949 #924493 #926238

#933514 #936773 #939826 #939926 #940776 #941113

#941202 #943959 #944296 #947241 #947478 #949100

#949192 #949706 #949744 #949936 #950013 #950580

#950750 #950998 #951110 #951165 #951440 #951638

#951864 #952384 #952666 #953717 #953826 #953830

#953971 #953980 #954635 #954986 #955136 #955148

#955224 #955354 #955422 #955533 #955644 #956047

#956053 #956147 #956284 #956703 #956711 #956717

#956801 #956876 #957395 #957546 #958504 #958510

#958647

Cross- CVE-2015-0272 CVE-2015-2925 CVE-2015-5156

CVE-2015-7799 CVE-2015-7872 CVE-2015-7990

CVE-2015-8215

Affected Products:

SUSE Linux Enterprise Workstation Extension 12-SP1

SUSE Linux Enterprise Software Development Kit 1...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:2292-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here