Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

SUSE: 2017:0333-1 Important: Linux Kernel Denial Of Service

suse
Calendar Grey January 30, 2017
Dist Suse Esm H88
SUSE Security Enhancement for the Linux Core resolving essential vulnerabilities, improving overall system integrity with key updates.
An update that solves 46 vulnerabilities and has 31 fixes An update that solves 46 vulnerabilities and has 31 fixes An update that solves 46 vulnerabilities and has 31 fixes is now...

Summary

The SUSE Linux Enterprise 11 SP2 LTSS kernel was updated to receive various security and bugfixes. This is the last planned LTSS kernel update for the SUSE Linux Enterprise Server 11 SP2 LTSS. The following security bugs were fixed: - CVE-2016-10088: The sg implementation in the Linux kernel did not properly restrict write operations in situations where the KERNEL_DS option is set, which allowed local users to read or write to arbitrary kernel memory locations or cause a denial of service (use-after-free) by leveraging access to a /dev/sg device, related to block/bsg.c and drivers/scsi/sg.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-9576 (bnc#1017710). - CVE-2004-0230: TCP, when using a large Window Size, made it easier for

References

#1003077 #1003925 #1004517 #1007944 #1008645

#1008831 #1008833 #1009443 #1010150 #1010467

#1010501 #1010507 #1010711 #1010716 #1011482

#1011685 #1012422 #1012832 #1013038 #1013531

#1013542 #1014746 #1017710 #1021258 #835175

#839104 #863873 #874145 #896484 #908069 #914939

#922947 #927287 #940966 #950998 #954984 #956514

#958000 #960689 #963053 #967716 #968500 #969340

#971360 #971944 #978401 #978821 #979213 #979274

#979548 #979595 #979879 #979915 #980363 #980371

#980725 #981267 #983143 #983213 #984755 #986362

#986365 #986445 #986572 #989261 #991608 #991665

#992566 #993890 #993891 #994296 #994436 #994618

#994759 #995968 #997059 #999932

Cross- CVE-2004-0230 CVE-2012-6704 CVE-2013-4312

CVE-2015-1350 CVE-...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:0333-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here