Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

SUSE: 2016:0750-1 Critical: Kernel Live Patch Addresses Privilege Risks

suse
Calendar Grey March 14, 2016
Dist Suse Esm H88
New security patch for SUSE kernel live update resolves significant vulnerabilities linked to local files. Key information on the patch included herein.
An update that fixes two vulnerabilities is now available

Summary

This kernel live patch for Linux Kernel 3.12.43-52.6.1 fixes two security issues: Fixes: - CVE-2016-0728: A reference leak in keyring handling with join_session_keyring() could lead to local attackers gain root privileges. (bsc#962078). - CVE-2013-7446: Use-after-free vulnerability in net/unix/af_unix.c in the Linux kernel allowed local users to bypass intended AF_UNIX socket permissions or cause a denial of service (panic) via crafted epoll_ctl calls. (bsc#955837) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Live Patching 12: zypper in -t patch SUSE-SLE-Live-Patching-12-2016-432=1 To bring your system up-to-date, use "zypper patch". Package List:

References

#955837 #962078

Cross- CVE-2013-7446 CVE-2016-0728

Affected Products:

SUSE Linux Enterprise Live Patching 12

https://www.suse.com/security/cve/CVE-2013-7446.html

https://www.suse.com/security/cve/CVE-2016-0728.html

https://bugzilla.suse.com/955837

https://bugzilla.suse.com/962078

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:0750-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here