Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

SUSE: 2016:2674-1 Important: Two Critical Kernel Issues Fixed

suse
Calendar Grey October 31, 2016
Scroller Suse
The recent patch addresses two significant security flaws in the Linux Kernel Live Patch 8 for SUSE 12 SP1, enhancing both performance and protection.
An update that fixes two vulnerabilities is now available

Summary

This update for the Linux Kernel 3.12.62-60_64_8 fixes several issues. The following security bugs were fixed: - CVE-2016-8666: The IP stack in the Linux kernel allowed remote attackers to cause a denial of service (stack consumption and panic) or possibly have unspecified other impact by triggering use of the GRO path for packets with tunnel stacking, as demonstrated by interleaved IPv4 headers and GRE headers, a related issue to CVE-2016-7039 (bsc#1001487). - CVE-2016-6480: Race condition in the ioctl_send_fib function in drivers/scsi/aacraid/commctrl.c in the Linux kernel allowed local users to cause a denial of service (out-of-bounds access or system crash) by changing a certain size value, aka a "double fetch" vulnerability (bsc#991667). Patch Instructions:

References

#1001487 #991667

Cross- CVE-2016-6480 CVE-2016-8666

Affected Products:

SUSE Linux Enterprise Live Patching 12

https://www.suse.com/security/cve/CVE-2016-6480.html

https://www.suse.com/security/cve/CVE-2016-8666.html

https://bugzilla.suse.com/1001487

https://bugzilla.suse.com/991667

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:2674-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.