Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

SUSE: 2015:2350-1 Important: Kernel Updates Cause Local DoS

suse
Calendar Grey December 23, 2015
Dist Suse Esm H88
SUSE has released a crucial security patch addressing 10 vulnerabilities within the Linux kernel, featuring several enhancements and corrections. Act promptly!
An update that solves 10 vulnerabilities and has 62 fixes An update that solves 10 vulnerabilities and has 62 fixes An update that solves 10 vulnerabilities and has 62 fixes is now...

Summary

The SUSE Linux Enterprise 11 SP4 Realtime kernel was updated to receive various security and bugfixes. Following security bugs were fixed: - CVE-2015-7509: Mounting a prepared ext2 filesystem as ext4 could lead to a local denial of service (crash) (bsc#956709). - CVE-2015-7799: The slhc_init function in drivers/net/slip/slhc.c in the Linux kernel did not ensure that certain slot numbers are valid, which allowed local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted PPPIOCSMAXCID ioctl call (bnc#949936). - CVE-2015-8104: The KVM subsystem in the Linux kernel allowed guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c (bnc#954404).

References

#814440 #879378 #879381 #900610 #904348 #904965

#921081 #926709 #926774 #930145 #930770 #930788

#930835 #932805 #935053 #935123 #935757 #937256

#937444 #937969 #937970 #938706 #939207 #939826

#939926 #939955 #940017 #940913 #940946 #941202

#942938 #943786 #944677 #944831 #944837 #944989

#944993 #945691 #945825 #945827 #946078 #946214

#946309 #947957 #948330 #948347 #948521 #949100

#949298 #949502 #949706 #949744 #949936 #949981

#950298 #950750 #950998 #951440 #952084 #952384

#952579 #952976 #953527 #953799 #953980 #954404

#954628 #954950 #954984 #955354 #955673 #956709

Cross- CVE-2015-0272 CVE-2015-5157 CVE-2015-5307

CVE-2015-6937 CVE-2015-7509 CVE-2015-7799

CVE-2015-7872 CVE-2015-7990 CVE-2015-8104

...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:2350-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here