The SUSE Linux Enterprise 12 kernel was updated to 3.12.55 to receive various security and bugfixes. Features added: - A improved XEN blkfront module was added, which allows more I/O bandwidth. (FATE#320625) It is called xen-blkfront in PV, and xen-vbd-upstream in HVM mode. The following security bugs were fixed: - CVE-2013-7446: Use-after-free vulnerability in net/unix/af_unix.c in the Linux kernel allowed local users to bypass intended AF_UNIX socket permissions or cause a denial of service (panic) via crafted epoll_ctl calls (bnc#955654). - CVE-2015-5707: Integer overflow in the sg_start_req function in drivers/scsi/sg.c in the Linux kernel allowed local users to cause a denial of service or possibly have unspecified other impact via a large iov_count value in a write request (bnc#940338).
#812259 #816099 #855062 #867583 #884701 #899908
#922071 #937444 #940338 #940946 #941363 #943989
#945219 #947953 #949752 #950292 #951155 #955308
#955654 #956084 #956514 #957525 #957986 #959090
#959146 #959257 #959463 #959629 #959709 #960174
#960227 #960458 #960561 #960629 #961257 #961500
#961509 #961516 #961588 #961658 #961971 #962336
#962356 #962788 #962965 #963193 #963449 #963572
#963746 #963765 #963767 #963825 #963960 #964201
#964730 #965199 #965344 #965830 #965840 #965891
#966026 #966094 #966278 #966437 #966471 #966693
#966864 #966910 #967802 #968018 #968074 #968206
#968230 #968234 #968253 #969112
Cross- CVE-2013-7446 CVE-2015-5707 CVE-2015-8709
CVE-2015-8767 CVE-2015-8785 CVE-2015-8812
CVE-2016-...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.