Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

SUSE Linux Enterprise 12: SUSE-SU-2017:3249-1 Important: Kernel Update

suse
Calendar Grey December 8, 2017
Dist Suse Esm H88
SUSE Security Patch for the Linux Kernel resolves various vulnerabilities, providing enhancements for overall robustness and protection.
An update that solves 14 vulnerabilities and has 8 fixes is An update that solves 14 vulnerabilities and has 8 fixes is An update that solves 14 vulnerabilities and has 8 fixes is ...

Summary

The SUSE Linux Enterprise 12 kernel was updated to 3.12.61 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2017-16939: The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel allowed local users to gain privileges or cause a denial of service (use-after-free) via a crafted SO_RCVBUF setsockopt system call in conjunction with XFRM_MSG_GETPOLICY Netlink messages (bnc#1069702 1069708). - CVE-2017-1000405: The Linux Kernel had a problematic use of pmd_mkdirty() in the touch_pmd() function inside the THP implementation. touch_pmd() could be reached by get_user_pages(). In such case, the pmd would become dirty. This scenario breaks the new can_follow_write_pmd()'s logic - pmd could become dirty without going

References

#1043652 #1047626 #1066192 #1066471 #1066472

#1066573 #1066606 #1066618 #1066625 #1066650

#1066671 #1066700 #1066705 #1067085 #1067086

#1067997 #1069496 #1069702 #1069708 #1070307

#1070781 #860993

Cross- CVE-2014-0038 CVE-2017-1000405 CVE-2017-12193

CVE-2017-15102 CVE-2017-16525 CVE-2017-16527

CVE-2017-16529 CVE-2017-16531 CVE-2017-16535

CVE-2017-16536 CVE-2017-16537 CVE-2017-16649

CVE-2017-16650 CVE-2017-16939

Affected Products:

SUSE Linux Enterprise Server 12-LTSS

SUSE Linux Enterprise Module for Public Cloud 12

https://www.suse.com/security/cve/CVE-2014-0038.html

https://www.suse.com/security/cve/CVE-2017-1000405.html

https://www.suse.com/security/cve/CVE-2017-12193.html

https://www.suse.com/security/cve/CVE-2017-15102.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:3249-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here