The SUSE Linux Enterprise 12 SP2 kernel was updated to 4.4.74 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2017-1000365: The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), but did not take the argument and environment pointers into account, which allowed attackers to bypass this limitation. (bnc#1039354). - CVE-2017-1000380: sound/core/timer.c in the Linux kernel is vulnerable to a data race in the ALSA /dev/snd/timer driver resulting in local users being able to read information belonging to other users, i.e., uninitialized memory contents may be disclosed when a read and an ioctl happen at the same time (bnc#1044125).
#1003581 #1004003 #1011044 #1012060 #1012382
#1012422 #1012452 #1012829 #1012910 #1012985
#1013561 #1013887 #1015342 #1015452 #1017461
#1018885 #1020412 #1021424 #1022266 #1022595
#1023287 #1025461 #1026570 #1027101 #1027512
#1027974 #1028217 #1028310 #1028340 #1028883
#1029607 #1030057 #1030070 #1031040 #1031142
#1031147 #1031470 #1031500 #1031512 #1031555
#1031717 #1031796 #1032141 #1032339 #1032345
#1032400 #1032581 #1032803 #1033117 #1033281
#1033336 #1033340 #1033885 #1034048 #1034419
#1034635 #1034670 #1034671 #1034762 #1034902
#1034995 #1035024 #1035866 #1035887 #1035920
#1035922 #1036214 #1036638 #1036752 #1036763
#1037177 #1037186 #1037384 #1037483 #1037669
#1037840 #103...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.