Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

SUSE: 2016:0749-1 Important: Kernel Live Patch for DoS Risk

suse
Calendar Grey March 14, 2016
Dist Suse Esm H88
SUSE Security Alert reveals kernel live patch 10, tackling essential vulnerabilities to bolster system security.
An update that fixes one vulnerability is now available

Summary

This kernel live patch for Linux Kernel 3.12.51-52.34.1 fixes two security issues: Fixes: - CVE-2013-7446: Use-after-free vulnerability in net/unix/af_unix.c in the Linux kernel allowed local users to bypass intended AF_UNIX socket permissions or cause a denial of service (panic) via crafted epoll_ctl calls. (bsc#955837) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Live Patching 12: zypper in -t patch SUSE-SLE-Live-Patching-12-2016-437=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Live Patching 12 (x86_64): kgraft-patch-3_12_51-52_34-default-3-2.1 kgraft-patch-3_12_51-52_34-xen-3-2.1

References

#955837

Cross- CVE-2013-7446

Affected Products:

SUSE Linux Enterprise Live Patching 12

https://www.suse.com/security/cve/CVE-2013-7446.html

https://bugzilla.suse.com/955837

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:0749-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here