Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The SUSE Linux Enterprise 12 kernel was updated to 3.12.67 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2016-7042: The proc_keys_show function in security/keys/proc.c in the Linux kernel used an incorrect buffer size for certain timeout data, which allowed local users to cause a denial of service (stack memory corruption and panic) by reading the /proc/keys file (bsc#1004517). - CVE-2016-7097: The filesystem implementation in the Linux kernel preserved the setgid bit during a setxattr call, which allowed local users to gain group privileges by leveraging the existence of a setgid program with restrictions on execute permissions (bsc#995968). - CVE-2015-8956: The rfcomm_sock_bind function in net/bluetooth/rfcomm/sock.c in the Linux kernel allowed local users to
#1000189 #1000287 #1000304 #1000776 #1001419
#1001486 #1002165 #1003079 #1003153 #1003400
#1003568 #1003866 #1003925 #1003964 #1004252
#1004462 #1004517 #1004520 #1005666 #1006691
#1007615 #1007886 #744692 #772786 #789311
#857397 #860441 #865545 #866130 #868923 #874131
#876463 #898675 #904489 #909994 #911687 #915183
#921338 #921784 #922064 #922634 #924381 #924384
#930399 #931454 #934067 #937086 #937888 #940545
#941420 #946309 #955446 #956514 #959463 #961257
#962846 #966864 #967640 #970943 #971975 #971989
#974406 #974620 #975596 #975772 #976195 #977687
#978094 #979451 #979928 #982783 #983619 #984194
#984419 #984779 #984992 #985562 #986445 #987192
#987333 #987542 #987565 #987621 #987805 #988440
...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.