The SUSE Linux Enterprise 12 SP1 kernel was updated to 3.12.62 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2014-9904: The snd_compress_check_input function in sound/core/compress_offload.c in the ALSA subsystem in the Linux kernel did not properly check for an integer overflow, which allowed local users to cause a denial of service (insufficient memory allocation) or possibly have unspecified other impact via a crafted SNDRV_COMPRESS_SET_PARAMS ioctl call (bnc#986811). - CVE-2015-7833: The usbvision driver in the Linux kernel allowed physically proximate attackers to cause a denial of service (panic) via a nonzero bInterfaceNumber value in a USB device descriptor (bnc#950998). - CVE-2015-8551: The PCI backend driver in Xen, when running on an x86
#947337 #950998 #951844 #953048 #954847 #956491
#957990 #962742 #963655 #963762 #965087 #966245
#968667 #970114 #970506 #971770 #972933 #973378
#973499 #974165 #974308 #974620 #975531 #975533
#975772 #975788 #977417 #978401 #978469 #978822
#979074 #979213 #979419 #979485 #979489 #979521
#979548 #979681 #979867 #979879 #979922 #980348
#980363 #980371 #980856 #980883 #981038 #981143
#981344 #981597 #982282 #982354 #982544 #982698
#983143 #983213 #983318 #983721 #983904 #983977
#984148 #984456 #984755 #984764 #985232 #985978
#986362 #986365 #986569 #986572 #986573 #986811
#988215 #988498 #988552 #990058
Cross- CVE-2014-9904 CVE-2015-7833 CVE-2015-8551
CVE-2015-8552 CVE-2015-8845 CVE-2016-0758
CVE-2016-...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.