Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The SUSE Linux Enterprise 11 SP4 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2014-3688: The SCTP implementation allowed remote attackers to cause a denial of service (memory consumption) by triggering a large number of chunks in an association's output queue (bsc#902351). The following non-security bugs were fixed: - ALSA: hda/ca0132: fix build failure when a local macro is defined (bsc#1045538). - ALSA: seq: Do not allow resizing pool in use (bsc#1045538). - Delete patches.fixes/0001-ipc-shm-Fix-shmat-mmap-nil-page-protection.patch (bsc# 1090078) - IB/mlx4: fix sprintf format warning (bnc#786036). - RDMA/mlx4: Discard unknown SQP work requests (bnc#786036). - USB: uss720: fix NULL-deref at probe (bnc#1047487).
#1045538 #1047487 #1087086 #1090078 #1094244
#1094876 #1098408 #1099177 #1099598 #1099709
#1099966 #1100089 #1100091 #1101296 #780242
#784815 #786036 #790588 #795301 #902351 #909495
#923242 #925105 #936423
Cross- CVE-2014-3688
Affected Products:
SUSE Linux Enterprise Software Development Kit 11-SP4
SUSE Linux Enterprise Server 11-SP4
SUSE Linux Enterprise Server 11-EXTRA
SUSE Linux Enterprise Debuginfo 11-SP4
https://www.suse.com/security/cve/CVE-2014-3688.html
https://bugzilla.suse.com/1045538
https://bugzilla.suse.com/1047487
https://bugzilla.suse.com/1087086
https://bugzilla.suse.com/1090078
https://bugzilla.suse.com/1094244
https://bugzilla.suse.com/1094876
https://bugzilla.suse.com/1098408
https://bugzilla.suse.com/1099177
Get the latest Linux and open source security news straight to your inbox.