Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

SUSE: 2016:0751-1 Important: Kernel Live Patch for Security Issues

suse
Calendar Grey March 14, 2016
Dist Suse Esm H88
SUSE Security Update tackles urgent kernel vulnerabilities, enhancing overall protection for Linux 12 users through essential updates.
An update that fixes three vulnerabilities is now available

Summary

This kernel live patch for Linux Kernel 3.12.49-11.1 fixes three security issues: Fixes: - CVE-2016-0728: A reference leak in keyring handling with join_session_keyring() could lead to local attackers gain root privileges. (bsc#962078). - CVE-2015-8660: The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application. (bsc#960329) - CVE-2013-7446: Use-after-free vulnerability in net/unix/af_unix.c in the Linux kernel allowed local users to bypass intended AF_UNIX socket permissions or cause a denial of service (panic) via crafted epoll_ctl calls. (bsc#955837) Patch Instructions:

References

#955837 #960329 #962078

Cross- CVE-2013-7446 CVE-2015-8660 CVE-2016-0728

Affected Products:

SUSE Linux Enterprise Live Patching 12

https://www.suse.com/security/cve/CVE-2013-7446.html

https://www.suse.com/security/cve/CVE-2015-8660.html

https://www.suse.com/security/cve/CVE-2016-0728.html

https://bugzilla.suse.com/955837

https://bugzilla.suse.com/960329

https://bugzilla.suse.com/962078

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:0751-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here