Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

SUSE Linux Enterprise Live Patching 12: 2016:2174-1 Critical: DoS Risk

suse
Calendar Grey August 29, 2016
Dist Suse Esm H88
SUSE Security Bulletin: Addresses multiple security flaws in Linux Kernel Live Patch 0 for SLE 12 SP2. Discover the specifics today!
An update that fixes three vulnerabilities is now available

Summary

This update for the Linux Kernel 3.12.49-11 fixes several issues. The following security bugs were fixed: - CVE-2016-6480: Race condition in the ioctl_send_fib function in drivers/scsi/aacraid/commctrl.c in the Linux kernel allowed local users to cause a denial of service (out-of-bounds access or system crash) by changing a certain size value, aka a "double fetch" vulnerability (bsc#991667). - CVE-2016-5829: Multiple heap-based buffer overflows in the hiddev_ioctl_usage function in drivers/hid/usbhid/hiddev.c in the Linux kernel allowed local users to cause a denial of service or possibly have unspecified other impact via a crafted (1) HIDIOCGUSAGES or (2) HIDIOCSUSAGES ioctl call (bsc#986573). - CVE-2016-4997: The compat IPT_SO_SET_REPLACE setsockopt implementation

References

#986377 #986573 #991667

Cross- CVE-2016-4997 CVE-2016-5829 CVE-2016-6480

Affected Products:

SUSE Linux Enterprise Live Patching 12

https://www.suse.com/security/cve/CVE-2016-4997.html

https://www.suse.com/security/cve/CVE-2016-5829.html

https://www.suse.com/security/cve/CVE-2016-6480.html

https://bugzilla.suse.com/986377

https://bugzilla.suse.com/986573

https://bugzilla.suse.com/991667

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:2174-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here