The SUSE Linux Enterprise 11 SP2 LTSS kernel was updated to receive various security and bugfixes. This is the last planned LTSS kernel update for the SUSE Linux Enterprise Server 11 SP2 LTSS. The following security bugs were fixed: - CVE-2016-10088: The sg implementation in the Linux kernel did not properly restrict write operations in situations where the KERNEL_DS option is set, which allowed local users to read or write to arbitrary kernel memory locations or cause a denial of service (use-after-free) by leveraging access to a /dev/sg device, related to block/bsg.c and drivers/scsi/sg.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-9576 (bnc#1017710). - CVE-2004-0230: TCP, when using a large Window Size, made it easier for
#1003077 #1003925 #1004517 #1007944 #1008645
#1008831 #1008833 #1009443 #1010150 #1010467
#1010501 #1010507 #1010711 #1010716 #1011482
#1011685 #1012422 #1012832 #1013038 #1013531
#1013542 #1014746 #1017710 #1021258 #835175
#839104 #863873 #874145 #896484 #908069 #914939
#922947 #927287 #940966 #950998 #954984 #956514
#958000 #960689 #963053 #967716 #968500 #969340
#971360 #971944 #978401 #978821 #979213 #979274
#979548 #979595 #979879 #979915 #980363 #980371
#980725 #981267 #983143 #983213 #984755 #986362
#986365 #986445 #986572 #989261 #991608 #991665
#992566 #993890 #993891 #994296 #994436 #994618
#994759 #995968 #997059 #999932
Cross- CVE-2004-0230 CVE-2012-6704 CVE-2013-4312
CVE-2015-1350 CVE-...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.