Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

SUSE 12 SP2: 2017-2064-1 Important Kernel Live Patch Addresses Threats

suse
Calendar Grey August 7, 2017
Dist Suse Esm H88
Essential patch release for SUSE kernel tackling various vulnerabilities and bolstering system defenses against intrusions.
An update that solves 6 vulnerabilities and has two fixes An update that solves 6 vulnerabilities and has two fixes An update that solves 6 vulnerabilities and has two fixes is now...

Summary

This update for the Linux Kernel 4.4.59-92_17 fixes several issues. The following security bugs were fixed: - CVE-2017-7533: A bug in inotify code allowed local users to escalate privilege (bsc#1050751). - CVE-2017-8797: The NFSv4 server in the Linux kernel did not properly validate the layout type when processing the NFSv4 pNFS GETDEVICEINFO or LAYOUTGET operand in a UDP packet from a remote attacker. This type value is uninitialized upon encountering certain error conditions. This value is used as an array index for dereferencing, which leads to an OOPS and eventually a DoS of knfsd and a soft-lockup of the whole system (bsc#1046202) - CVE-2017-7645: The NFSv2/NFSv3 server in the nfsd subsystem in the Linux kernel allowed remote attackers to cause a denial of service (system

References

#1038564 #1042364 #1042892 #1046191 #1046202

#1046206 #1047518 #1050751

Cross- CVE-2017-7533 CVE-2017-7645 CVE-2017-8797

CVE-2017-8890 CVE-2017-9077 CVE-2017-9242

Affected Products:

SUSE Linux Enterprise Live Patching 12

https://www.suse.com/security/cve/CVE-2017-7533.html

https://www.suse.com/security/cve/CVE-2017-7645.html

https://www.suse.com/security/cve/CVE-2017-8797.html

https://www.suse.com/security/cve/CVE-2017-8890.html

https://www.suse.com/security/cve/CVE-2017-9077.html

https://www.suse.com/security/cve/CVE-2017-9242.html

https://bugzilla.suse.com/1038564

https://bugzilla.suse.com/1042364

https://bugzilla.suse.com/1042892

https://bugzilla.suse.com/1046191

https://bugzilla.suse.com/1046202

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:2064-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here