Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

SUSE Linux Enterprise 12-SP1 Security Advisory: 2016:1696-1 Critical DoS

suse
Calendar Grey June 28, 2016
Dist Suse Esm H88
Patch released to fix 16 security flaws and enhance kernel efficiency for SUSE Linux Enterprise platforms.
An update that solves 16 vulnerabilities and has 66 fixes An update that solves 16 vulnerabilities and has 66 fixes An update that solves 16 vulnerabilities and has 66 fixes is now...

Summary

The SUSE Linux Enterprise 12 SP1 kernel was updated to 3.12.59 to receive various security and bugfixes. Main feature additions: - Improved support for Clustered File System (CephFS, fate#318586). - Addition of kGraft patches now produces logging messages to simplify auditing (fate#317827). The following security bugs were fixed: - CVE-2016-1583: Prevent the usage of mmap when the lower file system does not allow it. This could have lead to local privilege escalation when ecryptfs-utils was installed and /sbin/mount.ecryptfs_private was setuid (bsc#983143). - CVE-2014-9717: fs/namespace.c in the Linux kernel processes MNT_DETACH umount2 system calls without verifying that the MNT_LOCKED flag is unset, which allowed local users to bypass intended access restrictions

References

#662458 #676471 #889207 #897662 #899908 #903279

#908151 #928547 #931448 #937086 #940413 #942262

#943989 #944309 #945345 #951844 #953233 #957805

#958390 #959514 #960857 #962336 #962846 #962872

#963572 #964461 #964727 #965319 #966054 #966573

#967640 #968497 #968687 #968812 #968813 #969016

#970604 #970609 #970892 #970911 #970948 #970955

#970956 #970958 #970970 #971049 #971124 #971126

#971159 #971170 #971600 #971628 #971793 #971947

#972003 #972068 #972174 #972780 #972844 #972891

#972951 #973378 #973556 #973855 #974418 #974646

#974692 #975371 #975488 #975772 #975945 #976739

#976821 #976868 #977582 #977685 #978401 #978527

#978822 #979213 #979347 #983143

Cross- CVE-2014-9717 CVE-2016-1583 CVE-2016-2185

CV...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:1696-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here