Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

SUSE: 2016:1102-1 Important: Linux Kernel DoS and Privilege Issues

suse
Calendar Grey April 19, 2016
Dist Suse Esm H88
Red Hat's release fixes 15 vulnerabilities in the OpenShift platform affecting reliability and security; install the update for enhanced protection.
An update that solves 23 vulnerabilities and has 43 fixes An update that solves 23 vulnerabilities and has 43 fixes An update that solves 23 vulnerabilities and has 43 fixes is now...

Summary

The SUSE Linux Enterprise 11 SP4 RT kernel was updated to receive various security and bugfixes. Following feature was added to kernel-xen: - A improved XEN blkfront module was added, which allows more I/O bandwidth. (FATE#320200) It is called xen-blkfront in PV, and xen-vbd-upstream in HVM mode. The following security bugs were fixed: - CVE-2013-7446: Use-after-free vulnerability in net/unix/af_unix.c in the Linux kernel allowed local users to bypass intended AF_UNIX socket permissions or cause a denial of service (panic) via crafted epoll_ctl calls (bnc#955654). - CVE-2015-7515: An out of bounds memory access in the aiptek USB driver could be used by physical local attackers to crash the kernel (bnc#956708). - CVE-2015-7550: The keyctl_read_key function in security/keys/keyctl.c in

References

#758040 #904035 #912738 #915183 #924919 #933782

#937444 #940017 #940946 #942082 #947128 #948330

#949298 #951392 #951815 #952976 #953369 #954992

#955308 #955654 #955837 #955925 #956084 #956375

#956514 #956708 #956949 #957986 #957988 #957990

#958000 #958463 #958886 #958906 #958912 #958951

#959190 #959312 #959399 #959649 #959705 #961500

#961509 #961516 #961658 #962965 #963276 #963561

#963765 #963767 #964201 #964818 #966094 #966137

#966437 #966693 #967042 #967972 #967973 #967974

#967975 #968011 #968012 #968013 #969307 #969571

Cross- CVE-2013-7446 CVE-2015-7515 CVE-2015-7550

CVE-2015-8539 CVE-2015-8543 CVE-2015-8550

CVE-2015-8551 CVE-2015-8552 CVE-2015-8569

CVE-2015-8575 CVE-2015-8767 CVE-2015-8785

...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:1102-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here