Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

SUSE 11-SP4: 2016:2018-1 Important: Kernel Denial Of Service Fixes

suse
Calendar Grey August 9, 2016
Dist Suse Esm H88
Red Hat patches resolve multiple vulnerabilities in the OpenShift platform, boosting reliability and safeguarding against threats for customers.
An update that solves three vulnerabilities and has 8 fixes An update that solves three vulnerabilities and has 8 fixes An update that solves three vulnerabilities and has 8 fixes ...

Summary

The SUSE Linux Enterprise 11 SP4 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2016-5829: Multiple heap-based buffer overflows in the hiddev_ioctl_usage function in drivers/hid/usbhid/hiddev.c in the Linux kernel allowed local users to cause a denial of service or possibly have unspecified other impact via a crafted (1) HIDIOCGUSAGES or (2) HIDIOCSUSAGES ioctl call (bnc#986572). - CVE-2016-4997: The compat IPT_SO_SET_REPLACE setsockopt implementation in the netfilter subsystem in the Linux kernel allowed local users to gain privileges or cause a denial of service (memory corruption) by leveraging in-container root access to provide a crafted offset value that triggers an unintended decrement (bnc#986362).

References

#909589 #954847 #971030 #974620 #979915 #982544

#983721 #984755 #986362 #986572 #988498

Cross- CVE-2016-4470 CVE-2016-4997 CVE-2016-5829

Affected Products:

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Server 11-EXTRA

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2016-4470.html

https://www.suse.com/security/cve/CVE-2016-4997.html

https://www.suse.com/security/cve/CVE-2016-5829.html

https://bugzilla.suse.com/909589

https://bugzilla.suse.com/954847

https://bugzilla.suse.com/971030

https://bugzilla.suse.com/974620

https://bugzilla.suse.com/979915

https://bugzilla.suse.com/982544

https://bugzilla.suse.com/983721

https://bugzilla.suse.com/984755

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:2018-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here