Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE Linux: 2016:0747-1 Important: Kernel Patch for Root Escalation and DoS

suse
Calendar Grey March 14, 2016
Dist Suse Esm H88
Essential SUSE patch resolves dual major vulnerabilities concerning kernel live patching, boosting overall security measures.
An update that fixes two vulnerabilities is now available

Summary

This kernel live patch for Linux Kernel 3.12.51-52.31.1 fixes two security issues: Fixes: - CVE-2016-0728: A reference leak in keyring handling with join_session_keyring() could lead to local attackers gain root privileges. (bsc#962078). - CVE-2013-7446: Use-after-free vulnerability in net/unix/af_unix.c in the Linux kernel allowed local users to bypass intended AF_UNIX socket permissions or cause a denial of service (panic) via crafted epoll_ctl calls. (bsc#955837) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Live Patching 12: zypper in -t patch SUSE-SLE-Live-Patching-12-2016-436=1 To bring your system up-to-date, use "zypper patch". Package List:

References

#955837 #962078

Cross- CVE-2013-7446 CVE-2016-0728

Affected Products:

SUSE Linux Enterprise Live Patching 12

https://www.suse.com/security/cve/CVE-2013-7446.html

https://www.suse.com/security/cve/CVE-2016-0728.html

https://bugzilla.suse.com/955837

https://bugzilla.suse.com/962078

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:0747-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here