Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

SUSE: 2016:2245-1 Important: Kernel DoS Security Advisory

suse
Calendar Grey September 6, 2016
Scroller Suse
The latest SUSE Security Update provides essential patches for the Linux Kernel, addressing a range of security issues impacting numerous offerings.
An update that solves 25 vulnerabilities and has 22 fixes An update that solves 25 vulnerabilities and has 22 fixes An update that solves 25 vulnerabilities and has 22 fixes is now...

Summary

The SUSE Linux Enterprise 11 SP3 LTSS kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2016-3955: The usbip_recv_xbuff function in drivers/usb/usbip/usbip_common.c in the Linux kernel allowed remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted length value in a USB/IP packet (bnc#975945). - CVE-2016-4998: The IPT_SO_SET_REPLACE setsockopt implementation in the netfilter subsystem in the Linux kernel allowed local users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from kernel heap memory by leveraging in-container root access to provide a crafted offset value that leads to crossing a ruleset blob boundary (bnc#986365).

References

#839104 #866130 #919351 #944309 #950998 #960689

#962404 #963655 #963762 #966460 #969149 #970114

#971126 #971360 #971446 #971729 #971944 #974428

#975945 #978401 #978821 #978822 #979213 #979274

#979548 #979681 #979867 #979879 #980371 #980725

#980788 #980931 #981267 #983143 #983213 #983535

#984107 #984755 #986362 #986365 #986445 #986572

#987709 #988065 #989152 #989401 #991608

Cross- CVE-2013-4312 CVE-2015-7513 CVE-2015-7833

CVE-2016-0758 CVE-2016-1583 CVE-2016-2053

CVE-2016-2187 CVE-2016-3134 CVE-2016-3955

CVE-2016-4470 CVE-2016-4482 CVE-2016-4485

CVE-2016-4486 CVE-2016-4565 CVE-2016-4569

CVE-2016-4578 CVE-2016-4580 CVE-2016-4805

CVE-2016-4913 CVE-2016-4997 CVE-2016-4998

CVE-2016-5244 CVE-2016-5696 CVE-2016...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:2245-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.