Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

SUSE: 2017:2062-1 Important Severe Denial Of Service Kernel Update

suse
Calendar Grey August 7, 2017
Dist Suse Esm H88
Important notification for openSUSE regarding vital kernel updates and the mitigation of several vulnerabilities.
An update that solves 7 vulnerabilities and has one errata An update that solves 7 vulnerabilities and has one errata An update that solves 7 vulnerabilities and has one errata is ...

Summary

This update for the Linux Kernel 4.4.21-69 fixes several issues. The following security bugs were fixed: - CVE-2017-7533: A bug in inotify code allowed local users to escalate privilege (bsc#1050751). - CVE-2017-8797: The NFSv4 server in the Linux kernel did not properly validate the layout type when processing the NFSv4 pNFS GETDEVICEINFO or LAYOUTGET operand in a UDP packet from a remote attacker. This type value is uninitialized upon encountering certain error conditions. This value is used as an array index for dereferencing, which leads to an OOPS and eventually a DoS of knfsd and a soft-lockup of the whole system (bsc#1046202) - CVE-2017-7645: The NFSv2/NFSv3 server in the nfsd subsystem in the Linux kernel allowed remote attackers to cause a denial of service (system

References

#1027575 #1038564 #1042364 #1042892 #1046191

#1046202 #1046206 #1050751

Cross- CVE-2017-2636 CVE-2017-7533 CVE-2017-7645

CVE-2017-8797 CVE-2017-8890 CVE-2017-9077

CVE-2017-9242

Affected Products:

SUSE Linux Enterprise Live Patching 12

https://www.suse.com/security/cve/CVE-2017-2636.html

https://www.suse.com/security/cve/CVE-2017-7533.html

https://www.suse.com/security/cve/CVE-2017-7645.html

https://www.suse.com/security/cve/CVE-2017-8797.html

https://www.suse.com/security/cve/CVE-2017-8890.html

https://www.suse.com/security/cve/CVE-2017-9077.html

https://www.suse.com/security/cve/CVE-2017-9242.html

https://bugzilla.suse.com/1027575

https://bugzilla.suse.com/1038564

https://bugzilla.suse.com/1042364

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:2062-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here