Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE 12: 2016:0168-1 Important Kernel Update For DoS Fixes

suse
Calendar Grey January 19, 2016
Scroller Suse
SUSE release tackles serious kernel vulnerabilities, providing essential patches to prevent local privilege escalation and denial-of-service attacks.
An update that solves 8 vulnerabilities and has 26 fixes is An update that solves 8 vulnerabilities and has 26 fixes is An update that solves 8 vulnerabilities and has 26 fixes is ...

Summary

The SUSE Linux Enterprise 12 kernel was updated to receive various security and bugfixes. Following security bugs were fixed: - CVE-2015-7550: A local user could have triggered a race between read and revoke in keyctl (bnc#958951). - CVE-2015-8539: A negatively instantiated user key could have been used by a local user to leverage privileges (bnc#958463). - CVE-2015-8543: The networking implementation in the Linux kernel did not validate protocol identifiers for certain protocol families, which allowed local users to cause a denial of service (NULL function pointer dereference and system crash) or possibly gain privileges by leveraging CLONE_NEWUSER support to execute a crafted SOCK_RAW application (bnc#958886).

References

#758040 #902606 #924919 #935087 #937261 #943959

#945649 #949440 #951155 #951199 #951392 #951615

#951638 #952579 #952976 #956708 #956801 #956876

#957395 #957546 #957988 #957990 #958463 #958504

#958510 #958647 #958886 #958951 #959190 #959364

#959399 #959436 #959705 #960300

Cross- CVE-2015-7550 CVE-2015-8539 CVE-2015-8543

CVE-2015-8550 CVE-2015-8551 CVE-2015-8552

CVE-2015-8569 CVE-2015-8575

Affected Products:

SUSE Linux Enterprise Workstation Extension 12

SUSE Linux Enterprise Software Development Kit 12

SUSE Linux Enterprise Server 12

SUSE Linux Enterprise Module for Public Cloud 12

SUSE Linux Enterprise Live Patching 12

SUSE Linux Enterprise Desktop 12

https://www.suse.com/security/cve/CVE-2015-7550.html

https://www.suse.c...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:0168-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.