The SUSE Linux Enterprise 12 kernel was updated to 3.12.60 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2014-9717: fs/namespace.c in the Linux kernel processes MNT_DETACH umount2 system called without verifying that the MNT_LOCKED flag is unset, which allowed local users to bypass intended access restrictions and navigate to filesystem locations beneath a mount by calling umount2 within a user namespace (bnc#928547). - CVE-2015-8816: The hub_activate function in drivers/usb/core/hub.c in the Linux kernel did not properly maintain a hub-interface data structure, which allowed physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB hub device (bnc#968010).
#676471 #880007 #889207 #899908 #903279 #928547
#931448 #940413 #943989 #944309 #945345 #947337
#953233 #954847 #956491 #956852 #957805 #957986
#960857 #962336 #962846 #962872 #963193 #963572
#963762 #964461 #964727 #965319 #966054 #966245
#966573 #966831 #967251 #967292 #967299 #967903
#968010 #968141 #968448 #968512 #968667 #968670
#968687 #968812 #968813 #969439 #969571 #969655
#969690 #969735 #969992 #969993 #970062 #970114
#970504 #970506 #970604 #970892 #970909 #970911
#970948 #970955 #970956 #970958 #970970 #971049
#971124 #971125 #971126 #971159 #971170 #971360
#971600 #971628 #971947 #972003 #972174 #972844
#972891 #972933 #972951 #973378 #973556 #973570
#973855 #974165 #974308 #974406 #974...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.