The SUSE Linux Enterprise 12 SP1 Realtime kernel was updated to 3.12.58 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2015-7566: The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel allowed physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a (1) bulk-in or (2) interrupt-in endpoint (bnc#961512). - CVE-2015-8550: Xen, when used on a system providing PV backends, allowed local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability (bsc#957988).
#880007 #889207 #899908 #903279 #908151 #931448
#937086 #940413 #942262 #943645 #943989 #945219
#956084 #956852 #957986 #957988 #957990 #959146
#959514 #959709 #960174 #960561 #960629 #961500
#961512 #961658 #962336 #962872 #963193 #963572
#963746 #963765 #963827 #963960 #964201 #964461
#965087 #965153 #965199 #965319 #965830 #965924
#966054 #966094 #966437 #966471 #966573 #966693
#966831 #966864 #966910 #967047 #967251 #967292
#967299 #967650 #967651 #967802 #967903 #968010
#968018 #968074 #968141 #968206 #968230 #968234
#968253 #968448 #968497 #968512 #968643 #968670
#968687 #968812 #968813 #969112 #969439 #969571
#969655 #969690 #969735 #969992 #969993 #970062
#970160 #970504 #970604 #970609 #970...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.