Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

SUSE Linux 11 SP4 Important Security Update: Kernel Issues Resolved

suse
Calendar Grey October 10, 2017
Dist Suse Esm H88
SUSE unveils fixes for 8 critical flaws in the Linux Kernel, boosting security and system reliability for everyone. Discover the details.
An update that solves 8 vulnerabilities and has 25 fixes is An update that solves 8 vulnerabilities and has 25 fixes is An update that solves 8 vulnerabilities and has 25 fixes is ...

Summary

The SUSE Linux Enterprise 11 SP4 RT kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2017-1000251: The native Bluetooth stack was vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in remote code execution in kernel space (bnc#1057389). - CVE-2017-14340: The XFS_IS_REALTIME_INODE macro in fs/xfs/xfs_linux.h did not verify that a filesystem has a realtime device, which allowed local users to cause a denial of service (NULL pointer dereference and OOPS) via vectors related to setting an RHINHERIT flag on a directory (bnc#1058524). - CVE-2017-14140: The move_pages system call in mm/migrate.c did not check the effective uid of the target process, enabling a local attacker to

References

#1013018 #1024450 #1031358 #1036629 #1037441

#1037667 #1037669 #1037994 #1039803 #1040609

#1042863 #1045154 #1047523 #1050381 #1050431

#1051932 #1052311 #1052370 #1053148 #1053152

#1053802 #1053933 #1054070 #1054076 #1054093

#1054247 #1054706 #1055680 #1056588 #1057179

#1057389 #1058524 #984530

Cross- CVE-2017-1000112 CVE-2017-1000251 CVE-2017-10661

CVE-2017-12762 CVE-2017-14051 CVE-2017-14140

CVE-2017-14340 CVE-2017-8831

Affected Products:

SUSE Linux Enterprise Real Time Extension 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2017-1000112.html

https://www.suse.com/security/cve/CVE-2017-1000251.html

https://www.suse.com/security/cve/CVE-2017-10661.html

https://www.suse.com/security/cve/CVE-2017-12762.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:2694-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here