The SUSE Linux Enterprise 12 GA LTSS kernel was updated to 3.12.61 to receive various security and bugfixes. The following feature was implemented: - The ext2 filesystem got reenabled and supported to allow support for "XIP" (Execute In Place) (FATE#320805). The following security bugs were fixed: - CVE-2017-5551: The tmpfs filesystem implementation in the Linux kernel preserved the setgid bit during a setxattr call, which allowed local users to gain group privileges by leveraging the existence of a setgid program with restrictions on execute permissions (bsc#1021258). - CVE-2016-7097: The filesystem implementation in the Linux kernel preserved the setgid bit during a setxattr call, which allowed local users to gain group privileges by leveraging the existence of a setgid
#1003153 #1003925 #1004462 #1004517 #1005666
#1007197 #1008833 #1008979 #1009969 #1010040
#1010475 #1010478 #1010501 #1010502 #1010507
#1010612 #1010711 #1010716 #1011820 #1012422
#1013038 #1013531 #1013540 #1013542 #1014746
#1016482 #1017410 #1017589 #1017710 #1019300
#1019851 #1020602 #1021258 #881008 #915183
#958606 #961257 #970083 #971989 #976195 #978094
#980371 #980560 #981038 #981597 #981709 #982282
#982544 #983619 #983721 #983977 #984148 #984419
#984755 #985978 #986362 #986365 #986445 #986569
#986572 #986811 #986941 #987542 #987565 #987576
#989152 #990384 #991608 #991665 #993392 #993890
#993891 #994296 #994748 #994881 #995968 #997708
#998795 #999584 #999600 #999932 #999943
Cross- CVE-2014-9...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.