The SUSE Linux Enterprise 12 SP2 kernel was updated to 4.4.38 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2015-1350: The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allowed local users to cause a denial of service (capability stripping) via a failed invocation of a system call, as demonstrated by using chown to remove a capability from the ping or Wireshark dumpcap program (bnc#914939). - CVE-2015-8964: The tty_set_termios_ldisc function in drivers/tty/tty_ldisc.c in the Linux kernel allowed local users to obtain sensitive information from kernel memory by reading a tty data structure (bnc#1010507).
#1000118 #1000189 #1000287 #1000304 #1000433
#1000776 #1001169 #1001171 #1001310 #1001462
#1001486 #1001888 #1002322 #1002770 #1002786
#1003068 #1003566 #1003581 #1003606 #1003813
#1003866 #1003964 #1004048 #1004052 #1004252
#1004365 #1004517 #1005169 #1005327 #1005545
#1005666 #1005745 #1005895 #1005917 #1005921
#1005923 #1005925 #1005929 #1006103 #1006175
#1006267 #1006528 #1006576 #1006804 #1006809
#1006827 #1006915 #1006918 #1007197 #1007615
#1007653 #1007955 #1008557 #1008979 #1009062
#1009969 #1010040 #1010158 #1010444 #1010478
#1010507 #1010665 #1010690 #1010970 #1011176
#1011250 #1011913 #1012060 #1012094 #1012452
#1012767 #1012829 #1012992 #1013001 #1013479
#1013531 #101...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.