Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

SUSE: 2016:2011-1 Important: Linux Kernel Live Patch DoS Issues

suse
Calendar Grey August 9, 2016
Scroller Suse
Critical enhancement resolves various vulnerabilities in Linux Kernel Live Patch for SLE 12 SP1 to improve overall system safety.
An update that fixes 5 vulnerabilities is now available

Summary

This update for the Linux Kernel 3.12.59-60_45 fixes the several issues. These security issues were fixed: - CVE-2016-4470: The key_reject_and_link function in security/keys/key.c in the Linux kernel did not ensure that a certain data structure is initialized, which allowed local users to cause a denial of service (system crash) via vectors involving a crafted keyctl request2 command (bsc#984764). - CVE-2016-4565: The InfiniBand (aka IB) stack in the Linux kernel incorrectly relied on the write system call, which allowed local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI interface (bsc#980883). - CVE-2016-0758: Integer overflow in lib/asn1_decoder.c in the Linux kernel allowed local users to gain privileges via crafted ASN.1 data

References

#979074 #980856 #980883 #984764

Cross- CVE-2013-7446 CVE-2016-0758 CVE-2016-2053

CVE-2016-4470 CVE-2016-4565

Affected Products:

SUSE Linux Enterprise Live Patching 12

https://www.suse.com/security/cve/CVE-2013-7446.html

https://www.suse.com/security/cve/CVE-2016-0758.html

https://www.suse.com/security/cve/CVE-2016-2053.html

https://www.suse.com/security/cve/CVE-2016-4470.html

https://www.suse.com/security/cve/CVE-2016-4565.html

https://bugzilla.suse.com/979074

https://bugzilla.suse.com/980856

https://bugzilla.suse.com/980883

https://bugzilla.suse.com/984764

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:2011-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.