Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

SUSE: 2016:1041-1 Critical: Kernel Vulnerabilities Addressed and Resolved

suse
Calendar Grey April 14, 2016
Dist Suse Esm H88
The latest release of Linux Kernel Live Patch 8 rectifies significant vulnerabilities impacting SUSE platforms.
An update that fixes four vulnerabilities is now available

Summary

This update for the Linux Kernel 3.12.48-52.27.1 fixes the following issues: - CVE-2016-2384: A malicious USB device could cause a kernel crash in the alsa usb-audio driver. (bsc#967773) - CVE-2015-8812: A flaw was found in the CXGB3 kernel driver when the network was considered congested. The kernel would incorrectly misinterpret the congestion as an error condition and incorrectly free/clean up the skb. When the device would then send the skb's queued, these structures would be referenced and may panic the system or allow an attacker to escalate privileges in a use-after-free scenario. (bsc#966683) - CVE-2016-0774: A pipe buffer state corruption after unsuccessful atomic read from pipe was fixed (bsc#964732). - CVE-2015-8709: kernel/ptrace.c in the Linux kernel mishandled uid and

References

#960563 #964732 #966683 #967773

Cross- CVE-2015-8709 CVE-2015-8812 CVE-2016-0774

CVE-2016-2384

Affected Products:

SUSE Linux Enterprise Live Patching 12

https://www.suse.com/security/cve/CVE-2015-8709.html

https://www.suse.com/security/cve/CVE-2015-8812.html

https://www.suse.com/security/cve/CVE-2016-0774.html

https://www.suse.com/security/cve/CVE-2016-2384.html

https://bugzilla.suse.com/960563

https://bugzilla.suse.com/964732

https://bugzilla.suse.com/966683

https://bugzilla.suse.com/967773

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:1041-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here