Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 18 articles for you...
100

SUSE: Kernel Livepatch Important Network Security Issues 2025:20616-1

* bsc#1244337 * bsc#1245776 * bsc#1245793 * bsc#1245797 . # Security update for kernel-livepatch-MICRO-6-0_Update_9 Announcement ID: SUSE-SU-2025:20616-1 Release Date: 2025-08-25T12:16:44Z Rating: important References: * bsc#1244337 * bsc#1245776 * bsc#1245793 * bsc#1245797 Cross-References: * CVE-2025-21702 * CVE-2025-37752 * CVE-2025-37797 CVSS scores: * CVE-2025-21702 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-37752 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-37797 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves three vulnerabilities and has one fix can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0_Update_9 fixes the following issues: * CVE-2025-37752: net_sched: sch_sfq: move the limit validation (bsc#1245776) * CVE-2025-37797: net_sched: hfsc: Fix a UAF vulnerability in class handling (bsc#1245793) * CVE-2025-21702: pfifo_tail_enqueue: Drop new packet when sch-> limit == 0 (bsc#1245797) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-80=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-31-default-2-1.2 * kernel-livepatch-6_4_0-31-default-debuginfo-2-1.2 * kernel-livepatch-MICRO-6-0_Update_9-debugsource-2-1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-21702.html * https://www.suse.com/security/cve/CVE-2025-37752.html * https://www.suse.com/security/cve/CVE-2025-37797.html * https://bugzilla.suse.com/show_bug.cgi?id=1244337 * https://bugzilla.suse.com/show_bug.cgi?id=1245776 * https://bugzilla.suse.com/show_bug.cgi?id=1245793 *https://bugzilla.suse.com/show_bug.cgi?id=1245797 . SUSE rolls out live kernel patching updates to address urgent vulnerabilities in network security, boosting overall system reliability and efficiency.. SUSE Linux Micro, kernel update, security patch, network exploit, system integrity. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 29, 2025 Important SuSE
100

SUSE: 2024:0620-1 Important: Use-After-Free Threat in Kernel RT

* bsc#1218733 Cross-References: * CVE-2023-51780 . # Security update for the Linux Kernel RT (Live Patch 7 for SLE 15 SP5) Announcement ID: SUSE-SU-2024:0620-1 Rating: important References: * bsc#1218733 Cross-References: * CVE-2023-51780 CVSS scores: * CVE-2023-51780 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-51780 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for the Linux Kernel 5.14.21-150500_13_24 fixes one issue. The following security issue was fixed: * CVE-2023-51780: Fixed a use-after-free in do_vcc_ioctl in net/atm/ioctl.c, because of a vcc_recvmsg race condition (bsc#1218733). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2024-620=1 SUSE-2024-621=1 * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2024-620=1 SUSE-SLE- Module-Live-Patching-15-SP5-2024-621=1 ## Package List: * openSUSE Leap 15.5 (x86_64) * kernel-livepatch-5_14_21-150500_13_24-rt-4-150500.2.1 * kernel-livepatch-5_14_21-150500_13_21-rt-4-150500.2.1 * kernel-livepatch-SLE15-SP5-RT_Update_6-debugsource-4-150500.2.1 * kernel-livepatch-5_14_21-150500_13_24-rt-debuginfo-4-150500.2.1 * kernel-livepatch-SLE15-SP5-RT_Update_7-debugsource-4-150500.2.1 * kernel-livepatch-5_14_21-150500_13_21-rt-debuginfo-4-150500.2.1 * SUSE Linux Enterprise LivePatching 15-SP5 (x86_64) * kernel-livepatch-5_14_21-150500_13_24-rt-4-150500.2.1 * kernel-livepatch-5_14_21-150500_13_21-rt-4-150500.2.1 * kernel-livepatch-SLE15-SP5-RT_Update_6-debugsource-4-150500.2.1 * kernel-livepatch-5_14_21-150500_13_24-rt-debuginfo-4-150500.2.1 * kernel-livepatch-SLE15-SP5-RT_Update_7-debugsource-4-150500.2.1 * kernel-livepatch-5_14_21-150500_13_21-rt-debuginfo-4-150500.2.1 ## References: * https://www.suse.com/security/cve/CVE-2023-51780.html * https://bugzilla.suse.com/show_bug.cgi?id=1218733 . Patch released targeting type confusion vulnerability in Linux Kernel RT for SLE 15 SP5, enhances protection measures against potential threats.. Linux Kernel, Security Update, SUSE Linux, Use-After-Free, System Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 26, 2024 Important SuSE
172

Ubuntu 22.04 LTS: USN-5779-1 Moderate: Kernel Exploits Overview

Several security issues were fixed in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-5779-1 December 14, 2022 linux-azure, linux-azure-5.15, linux-azure-fde vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-azure: Linux kernel for Microsoft Azure Cloud systems - linux-azure-fde: Linux kernel for Microsoft Azure CVM cloud systems - linux-azure-5.15: Linux kernel for Microsoft Azure cloud systems Details: It was discovered that the NFSD implementation in the Linux kernel did not properly handle some RPC messages, leading to a buffer overflow. A remote attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-43945) Jann Horn discovered that the Linux kernel did not properly track memory allocations for anonymous VMA mappings in some situations, leading to potential data structure reuse. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-42703) It was discovered that a memory leak existed in the IPv6 implementation of the Linux kernel. A local attacker could use this to cause a denial of service (memory exhaustion). (CVE-2022-3524) It was discovered that a race condition existed in the Bluetooth subsystem in the Linux kernel, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-3564) It was discovered that the ISDN implementation of the Linux kernel contained a use-after-free vulnerability. A privileged user could use this to cause a denial of service (system crash) or possibly execute arbitrary code.(CVE-2022-3565) It was discovered that the TCP implementation in the Linux kernel contained a data race condition. An attacker could possibly use this to cause undesired behaviors. (CVE-2022-3566) It was discovered that the IPv6 implementation in the Linux kernel contained a data race condition. An attacker could possibly use this to cause undesired behaviors. (CVE-2022-3567) It was discovered that the Realtek RTL8152 USB Ethernet adapter driver in the Linux kernel did not properly handle certain error conditions. A local attacker with physical access could plug in a specially crafted USB device to cause a denial of service (memory exhaustion). (CVE-2022-3594) It was discovered that a null pointer dereference existed in the NILFS2 file system implementation in the Linux kernel. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-3621) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: linux-image-5.15.0-1029-azure 5.15.0-1029.36 linux-image-5.15.0-1029-azure-fde 5.15.0-1029.36.1 linux-image-azure 5.15.0.1029.25 linux-image-azure-fde 5.15.0.1029.36.6 linux-image-azure-lts-22.04 5.15.0.1029.25 Ubuntu 20.04 LTS: linux-image-5.15.0-1029-azure 5.15.0-1029.36~20.04.1 linux-image-azure 5.15.0.1029.36~20.04.19 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-5779-1 CVE-2022-3524, CVE-2022-3564, CVE-2022-3565, CVE-2022-3566, CVE-2022-3567, CVE-2022-3594, CVE-2022-3621, CVE-2022-42703, CVE-2022-43945 Package Information: https://launchpad.net/ubuntu/+source/linux-azure/5.15.0-1029.36 https://launchpad.net/ubuntu/+source/linux-azure-fde/5.15.0-1029.36.1 https://launchpad.net/ubuntu/+source/linux-azure-5.15/5.15.0-1029.36~20.04.1 . Severe flaws in the Ubuntu Linux kernel require immediate intervention to safeguard your cloud infrastructure against potential risks.. Linux Kernel Update, Azure Security Issues, Ubuntu Security Notice. . LinuxSecurity.com Team

Calendar%202 Dec 14, 2022 Ubuntu
198

Arch Linux 2021-07-21 High: Privilege Escalation In Linux Package

The package linux before version 5.13.4.arch1-1 is vulnerable to privilege escalation. . Arch Linux Security Advisory ASA-202107-48 ========================================= Severity: High Date : 2021-07-21 CVE-ID : CVE-2021-3609 CVE-2021-3612 CVE-2021-33909 Package : linux Type : privilege escalation Remote : No Link : https://security.archlinux.org/AVG-2181 Summary ====== The package linux before version 5.13.4.arch1-1 is vulnerable to privilege escalation. Resolution ========= Upgrade to 5.13.4.arch1-1. # pacman -Syu "linux> =5.13.4.arch1-1" The problems have been fixed upstream in version 5.13.4.arch1. Workaround ========= None. Description ========== - CVE-2021-3609 (privilege escalation) A race condition in net/can/bcm.c in the Linux kernel before version 5.13.2 allows for local privilege escalation to root. The CAN BCM networking protocol allows to register a CAN message receiver for a specified socket. The function bcm_rx_handler() is run for incoming CAN messages. Simultaneously to running this function, the socket can be closed and bcm_release() will be called. Inside bcm_release(), struct bcm_op and struct bcm_sock are freed while bcm_rx_handler() is still running, finally leading to multiple use-after-free's. - CVE-2021-3612 (privilege escalation) An out-of-bounds memory write security issue was found in the Linux kernel’s joystick devices subsystem before version 5.13.2, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on the system. - CVE-2021-33909 (privilege escalation) An privilege escalation security issue has been found in the filesystem layer of the Linux kernel before version 5.13.4. An unprivileged local attacker can obtain full root privileges by creating, mounting, and deleting a deep directory structure whose total path length exceeds 1GB, which leads to an uncontrolled out-of-bounds write. Impact ===== An unprivilegedlocal attacker could obtain full root privileges or crash the system. References ========= https://www.openwall.com/lists/oss-security/2021/06/19/1 https://www.openwall.com/lists/oss-security/2021/06/19/2 https://github.com/nrb547/kernel-exploitation/blob/main/cve-2021-3609/cve-2021-3609.md https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.13.2&id=014f8baa9d240c4cf7180d37abd625fd4a4527c8 https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.12.17&id=d8a5cf5cfc07a296c78bd515671e374b8d8db022 https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.10.50&id=b52e0cf0bfc1ede495de36aec86f6013efa18f60 https://bugzilla.redhat.com/show_bug.cgi?id=1974079 https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.13.2&id=81acf1015233b3ee1d9834ba4fcca087a75c0c1b https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.12.17&id=b88243d8f1c7eb2a834fd7cd1ea9691554240d3a https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.10.50&id=b4c35e9e8061b2386da1aa0d708e991204e76c45 https:// https://https:// https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.13.4&id=71de462034c69525a5049fbdf3903c5833cbce04 https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.12.19&id=514b6531b1cbb64199db63bfdb80953d71998cca https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.10.52&id=174c34d9cda1b5818419b8f5a332ced10755e52f https://security.archlinux.org/CVE-2021-3609 https://security.archlinux.org/CVE-2021-3612 https://security.archlinux.org/CVE-2021-33909 . Debian Linux security bulletin highlights substantial privilege elevation threats within the core package. Immediate updates are essential for safeguarding systems.. Arch Linux Privilege Escalation, Linux Kernel Exploit, Security Advisory Details. . LinuxSecurity.com Team

Calendar%202 Jul 22, 2021 ArchLinux
172

Ubuntu 20.04: USN-4948-1 Critical: Linux Kernel DoS Threats

Several security issues were fixed in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-4948-1 May 11, 2021 linux-oem-5.10 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-oem-5.10: Linux kernel for OEM systems Details: Ryota Shiga discovered that the eBPF implementation in the Linux kernel did not properly verify that a BPF program only reserved as much memory for a ring buffer as was allocated. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2021-3489) Manfred Paul discovered that the eBPF implementation in the Linux kernel did not properly track bounds on bitwise operations. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2021-3490) Billy Jheng Bing-Jhong discovered that the io_uring implementation of the Linux kernel did not properly enforce the MAX_RW_COUNT limit in some situations. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2021-3491) Kiyin (尹亮) discovered that the NFC LLCP protocol implementation in the Linux kernel contained a reference counting error. A local attacker could use this to cause a denial of service (system crash). (CVE-2020-25670) Kiyin (尹亮) discovered that the NFC LLCP protocol implementation in the Linux kernel did not properly deallocate memory in certain error situations. A local attacker could use this to cause a denial of service (memory exhaustion). (CVE-2020-25671, CVE-2020-25672) It was discovered that the Xen paravirtualization backend in the Linux kernel did not properly deallocate memory in some situations. A local attacker could use this tocause a denial of service (memory exhaustion). (CVE-2021-28688) It was discovered that the io_uring subsystem in the Linux kernel contained a race condition leading to a deadlock condition. A local attacker could use this to cause a denial of service. (CVE-2021-28951) John Stultz discovered that the audio driver for Qualcomm SDM845 systems in the Linux kernel did not properly validate port ID numbers. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-28952) Zygo Blaxell discovered that the btrfs file system implementation in the Linux kernel contained a race condition during certain cloning operations. A local attacker could possibly use this to cause a denial of service (system crash). (CVE-2021-28964) Vince Weaver discovered that the perf subsystem in the Linux kernel did not properly handle certain PEBS records properly for some Intel Haswell processors. A local attacker could use this cause a denial of service (system crash). (CVE-2021-28971) It was discovered that the RPA PCI Hotplug driver implementation in the Linux kernel did not properly handle device name writes via sysfs, leading to a buffer overflow. A privileged attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-28972) It was discovered that the Freescale Gianfar Ethernet driver for the Linux kernel did not properly handle receive queue overrun when jumbo frames were enabled in some situations. An attacker could use this to cause a denial of service (system crash). (CVE-2021-29264) It was discovered that the vDPA backend virtio driver in the Linux kernel contained a use-after-free vulnerability. An attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-29266) It was discovered that the TIPC protocol implementation in the Linux kernel did not properly validate passed encryption key sizes. A local attacker coulduse this to cause a denial of service (system crash). (CVE-2021-29646) It was discovered that the Qualcomm IPC router implementation in the Linux kernel did not properly initialize memory passed to user space. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2021-29647) It was discovered that the BPF user mode driver implementation in the Linux kernel did not properly deallocate memory in some situations. A local attacker could use this to cause a denial of service (memory exhaustion). (CVE-2021-29649) It was discovered that a race condition existed in the netfilter subsystem of the Linux kernel when replacing tables. A local attacker could use this to cause a denial of service (system crash). (CVE-2021-29650) Felix Wilhelm discovered that the KVM implementation in the Linux kernel for AMD processors contained race conditions on nested VMCB controls. A local attacker in a guest vm could possibly use this to gain elevated privileges. (CVE-2021-29657) Dan Carpenter discovered that the block device manager (dm) implementation in the Linux kernel contained a buffer overflow in the ioctl for listing devices. A privileged local attacker could use this to cause a denial of service (system crash). (CVE-2021-31916) 马哲宇 discovered that the IEEE 1394 (Firewire) nosy packet sniffer driver in the Linux kernel did not properly perform reference counting in some situations, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-3483) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: linux-image-5.10.0-1026-oem 5.10.0-1026.27 linux-image-oem-20.04b 5.10.0.1026.27 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updateshave been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-4948-1 CVE-2020-25670, CVE-2020-25671, CVE-2020-25672, CVE-2021-28688, CVE-2021-28951, CVE-2021-28952, CVE-2021-28964, CVE-2021-28971, CVE-2021-28972, CVE-2021-29264, CVE-2021-29266, CVE-2021-29646, CVE-2021-29647, CVE-2021-29649, CVE-2021-29650, CVE-2021-29657, CVE-2021-31916, CVE-2021-3483, CVE-2021-3489, CVE-2021-3490, CVE-2021-3491 Package Information: https://launchpad.net/ubuntu/+source/linux-oem-5.10/5.10.0-1026.27 . Important security alerts for Ubuntu's linux-oem-5.10 highlighting various kernel vulnerabilities necessitating prompt updates.. Ubuntu Security, Linux Kernel Updates, eBPF Security Issues, DoS Attacks. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 11, 2021 Critical Ubuntu
100

SUSE: 2019:0761-1 Important: Kernel Live Patch Critical Exploit Repair

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for the Linux Kernel (Live Patch 23 for SLE 12 SP3) ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:0761-1 Rating: important References: #1128378 Cross-References: CVE-2019-9213 Affected Products: SUSE Linux Enterprise Live Patching 12-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for the Linux Kernel 4.4.175-94_79 fixes one issue. The following security issue was fixed: - CVE-2019-9213: Expand_downwards in mm/mmap.c lacked a check for the mmap minimum address, which made it easier for attackers to exploit kernel NULL pointer dereferences on non-SMAP platforms. This is related to a capability check for the wrong task (bsc#1128378). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Live Patching 12-SP3: zypper in -t patch SUSE-SLE-Live-Patching-12-SP3-2019-761=1 Package List: - SUSE Linux Enterprise Live Patching 12-SP3 (ppc64le x86_64): kgraft-patch-4_4_175-94_79-default-2-2.1 kgraft-patch-4_4_175-94_79-default-debuginfo-2-2.1 References: https://www.suse.com/security/cve/CVE-2019-9213.html https://bugzilla.suse.com/1128378 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE Security Notice: Key kernel live patch resolves a severe vulnerability impacting SLE 12 SP3 installations.. SLES 12 SP3 Kernel Patch, SUSE Security Update, Kernel Exploit Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 26, 2019 Important SuSE
98

Red Hat 6.7: RHSA-2017:0316-01 Important: DCCP Exploit Fix

An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2017:0316-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2017:0316.html Issue date: 2017-02-23 CVE Names: CVE-2017-6074 ==================================================================== 1. Summary: An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux HPC Node EUS (v. 6.7) - noarch, x86_64 Red Hat Enterprise Linux HPC Node Optional EUS (v. 6.7) - x86_64 Red Hat Enterprise Linux Server EUS (v. 6.7) - i386, noarch, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional EUS (v. 6.7) - i386, ppc64, s390x, x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * A use-after-free flaw was found in the way the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation freed SKB (socket buffer) resources for a DCCP_PKT_REQUEST packet when the IPV6_RECVPKTINFO option is set on the socket. A local, unprivileged user could use this flaw to alter the kernel memory, allowing them to escalate their privileges on the system. (CVE-2017-6074, Important) Red Hat would like to thank Andrey Konovalov(Google) for reporting this issue. Bug Fix(es): * When an NFS server received a compound Remote Procedure Call (RPC) with multiple operations where the SECINFO operation was the ninth or later operation, the server terminated unexpectedly. This update fixes the NFS server to correctly initialize all arguments of all compound RPC operations that are beyond the first eight operations. As a result, the NFS server no longer crashes in the described situation. (BZ#1413035) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1423071 - CVE-2017-6074 kernel: use after free in dccp protocol 6. Package List: Red Hat Enterprise Linux HPC Node EUS (v. 6.7): Source: kernel-2.6.32-573.40.1.el6.src.rpm noarch: kernel-abi-whitelists-2.6.32-573.40.1.el6.noarch.rpm kernel-doc-2.6.32-573.40.1.el6.noarch.rpm kernel-firmware-2.6.32-573.40.1.el6.noarch.rpm x86_64: kernel-2.6.32-573.40.1.el6.x86_64.rpm kernel-debug-2.6.32-573.40.1.el6.x86_64.rpm kernel-debug-debuginfo-2.6.32-573.40.1.el6.i686.rpm kernel-debug-debuginfo-2.6.32-573.40.1.el6.x86_64.rpm kernel-debug-devel-2.6.32-573.40.1.el6.i686.rpm kernel-debug-devel-2.6.32-573.40.1.el6.x86_64.rpm kernel-debuginfo-2.6.32-573.40.1.el6.i686.rpm kernel-debuginfo-2.6.32-573.40.1.el6.x86_64.rpm kernel-debuginfo-common-i686-2.6.32-573.40.1.el6.i686.rpm kernel-debuginfo-common-x86_64-2.6.32-573.40.1.el6.x86_64.rpm kernel-devel-2.6.32-573.40.1.el6.x86_64.rpm kernel-headers-2.6.32-573.40.1.el6.x86_64.rpm perf-2.6.32-573.40.1.el6.x86_64.rpm perf-debuginfo-2.6.32-573.40.1.el6.i686.rpm perf-debuginfo-2.6.32-573.40.1.el6.x86_64.rpm python-perf-debuginfo-2.6.32-573.40.1.el6.i686.rpm python-perf-debuginfo-2.6.32-573.40.1.el6.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional EUS (v.6.7): x86_64: kernel-debug-debuginfo-2.6.32-573.40.1.el6.x86_64.rpm kernel-debuginfo-2.6.32-573.40.1.el6.x86_64.rpm kernel-debuginfo-common-x86_64-2.6.32-573.40.1.el6.x86_64.rpm perf-debuginfo-2.6.32-573.40.1.el6.x86_64.rpm python-perf-2.6.32-573.40.1.el6.x86_64.rpm python-perf-debuginfo-2.6.32-573.40.1.el6.x86_64.rpm Red Hat Enterprise Linux Server EUS (v.6.7): Source: kernel-2.6.32-573.40.1.el6.src.rpm i386: kernel-2.6.32-573.40.1.el6.i686.rpm kernel-debug-2.6.32-573.40.1.el6.i686.rpm kernel-debug-debuginfo-2.6.32-573.40.1.el6.i686.rpm kernel-debug-devel-2.6.32-573.40.1.el6.i686.rpm kernel-debuginfo-2.6.32-573.40.1.el6.i686.rpm kernel-debuginfo-common-i686-2.6.32-573.40.1.el6.i686.rpm kernel-devel-2.6.32-573.40.1.el6.i686.rpm kernel-headers-2.6.32-573.40.1.el6.i686.rpm perf-2.6.32-573.40.1.el6.i686.rpm perf-debuginfo-2.6.32-573.40.1.el6.i686.rpm python-perf-debuginfo-2.6.32-573.40.1.el6.i686.rpm noarch: kernel-abi-whitelists-2.6.32-573.40.1.el6.noarch.rpm kernel-doc-2.6.32-573.40.1.el6.noarch.rpm kernel-firmware-2.6.32-573.40.1.el6.noarch.rpm ppc64: kernel-2.6.32-573.40.1.el6.ppc64.rpm kernel-bootwrapper-2.6.32-573.40.1.el6.ppc64.rpm kernel-debug-2.6.32-573.40.1.el6.ppc64.rpm kernel-debug-debuginfo-2.6.32-573.40.1.el6.ppc64.rpm kernel-debug-devel-2.6.32-573.40.1.el6.ppc64.rpm kernel-debuginfo-2.6.32-573.40.1.el6.ppc64.rpm kernel-debuginfo-common-ppc64-2.6.32-573.40.1.el6.ppc64.rpm kernel-devel-2.6.32-573.40.1.el6.ppc64.rpm kernel-headers-2.6.32-573.40.1.el6.ppc64.rpm perf-2.6.32-573.40.1.el6.ppc64.rpm perf-debuginfo-2.6.32-573.40.1.el6.ppc64.rpm python-perf-debuginfo-2.6.32-573.40.1.el6.ppc64.rpm s390x: kernel-2.6.32-573.40.1.el6.s390x.rpm kernel-debug-2.6.32-573.40.1.el6.s390x.rpm kernel-debug-debuginfo-2.6.32-573.40.1.el6.s390x.rpm kernel-debug-devel-2.6.32-573.40.1.el6.s390x.rpm kernel-debuginfo-2.6.32-573.40.1.el6.s390x.rpm kernel-debuginfo-common-s390x-2.6.32-573.40.1.el6.s390x.rpm kernel-devel-2.6.32-573.40.1.el6.s390x.rpm kernel-headers-2.6.32-573.40.1.el6.s390x.rpm kernel-kdump-2.6.32-573.40.1.el6.s390x.rpm kernel-kdump-debuginfo-2.6.32-573.40.1.el6.s390x.rpm kernel-kdump-devel-2.6.32-573.40.1.el6.s390x.rpm perf-2.6.32-573.40.1.el6.s390x.rpm perf-debuginfo-2.6.32-573.40.1.el6.s390x.rpm python-perf-debuginfo-2.6.32-573.40.1.el6.s390x.rpm x86_64: kernel-2.6.32-573.40.1.el6.x86_64.rpm kernel-debug-2.6.32-573.40.1.el6.x86_64.rpm kernel-debug-debuginfo-2.6.32-573.40.1.el6.i686.rpm kernel-debug-debuginfo-2.6.32-573.40.1.el6.x86_64.rpm kernel-debug-devel-2.6.32-573.40.1.el6.i686.rpm kernel-debug-devel-2.6.32-573.40.1.el6.x86_64.rpm kernel-debuginfo-2.6.32-573.40.1.el6.i686.rpm kernel-debuginfo-2.6.32-573.40.1.el6.x86_64.rpm kernel-debuginfo-common-i686-2.6.32-573.40.1.el6.i686.rpm kernel-debuginfo-common-x86_64-2.6.32-573.40.1.el6.x86_64.rpm kernel-devel-2.6.32-573.40.1.el6.x86_64.rpm kernel-headers-2.6.32-573.40.1.el6.x86_64.rpm perf-2.6.32-573.40.1.el6.x86_64.rpm perf-debuginfo-2.6.32-573.40.1.el6.i686.rpm perf-debuginfo-2.6.32-573.40.1.el6.x86_64.rpm python-perf-debuginfo-2.6.32-573.40.1.el6.i686.rpm python-perf-debuginfo-2.6.32-573.40.1.el6.x86_64.rpm Red Hat Enterprise Linux Server Optional EUS (v.6.7): i386: kernel-debug-debuginfo-2.6.32-573.40.1.el6.i686.rpm kernel-debuginfo-2.6.32-573.40.1.el6.i686.rpm kernel-debuginfo-common-i686-2.6.32-573.40.1.el6.i686.rpm perf-debuginfo-2.6.32-573.40.1.el6.i686.rpm python-perf-2.6.32-573.40.1.el6.i686.rpm python-perf-debuginfo-2.6.32-573.40.1.el6.i686.rpm ppc64: kernel-debug-debuginfo-2.6.32-573.40.1.el6.ppc64.rpm kernel-debuginfo-2.6.32-573.40.1.el6.ppc64.rpm kernel-debuginfo-common-ppc64-2.6.32-573.40.1.el6.ppc64.rpm perf-debuginfo-2.6.32-573.40.1.el6.ppc64.rpm python-perf-2.6.32-573.40.1.el6.ppc64.rpm python-perf-debuginfo-2.6.32-573.40.1.el6.ppc64.rpm s390x: kernel-debug-debuginfo-2.6.32-573.40.1.el6.s390x.rpm kernel-debuginfo-2.6.32-573.40.1.el6.s390x.rpm kernel-debuginfo-common-s390x-2.6.32-573.40.1.el6.s390x.rpm kernel-kdump-debuginfo-2.6.32-573.40.1.el6.s390x.rpm perf-debuginfo-2.6.32-573.40.1.el6.s390x.rpm python-perf-2.6.32-573.40.1.el6.s390x.rpm python-perf-debuginfo-2.6.32-573.40.1.el6.s390x.rpm x86_64: kernel-debug-debuginfo-2.6.32-573.40.1.el6.x86_64.rpm kernel-debuginfo-2.6.32-573.40.1.el6.x86_64.rpm kernel-debuginfo-common-x86_64-2.6.32-573.40.1.el6.x86_64.rpm perf-debuginfo-2.6.32-573.40.1.el6.x86_64.rpm python-perf-2.6.32-573.40.1.el6.x86_64.rpm python-perf-debuginfo-2.6.32-573.40.1.el6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2017-6074 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2017 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFYryAUXlSAg2UNWIIRAjmQAKCTmPf6PQcw3a6FA+fZb06P6DOwAACfQvds veY8z8VY5ewF646wsRGayAk=URf4 -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Kernel vulnerability patch and update for RedHat Enterprise Linux 6.7 categorized as critical by Red Hat security team.. Kernel Update, Red Hat Security, Bug Fix, Important Updates, DCCP Exploit. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 23, 2017 Important Red Hat
98

Critical Kernel Exploit in Red Hat 7.1 RHSA-2016:1657-01 Advisory

An update for kernel is now available for Red Hat Enterprise Linux 7.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel security update Advisory ID: RHSA-2016:1657-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2016:1657.html Issue date: 2016-08-23 CVE Names: CVE-2016-4470 CVE-2016-4565 CVE-2016-5696 ==================================================================== 1. Summary: An update for kernel is now available for Red Hat Enterprise Linux 7.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode EUS (v. 7.1) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.1) - x86_64 Red Hat Enterprise Linux Server EUS (v. 7.1) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional EUS (v. 7.1) - ppc64, ppc64le, s390x, x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * A flaw was found in the Linux kernel's keyring handling code, where in key_reject_and_link() an uninitialised variable would eventually lead to arbitrary free address which could allow attacker to use a use-after-free style attack. (CVE-2016-4470, Important) * A flaw was found in the way certain interfaces of the Linux kernel's Infiniband subsystem used write() as bi-directional ioctl() replacement, which could lead toinsufficient memory security checks when being invoked using the splice() system call. A local unprivileged user on a system with either Infiniband hardware present or RDMA Userspace Connection Manager Access module explicitly loaded, could use this flaw to escalate their privileges on the system. (CVE-2016-4565, Important) * A flaw was found in the implementation of the Linux kernel's handling of networking challenge ack where an attacker is able to determine the shared counter which could be used to determine sequence numbers for TCP stream injection. (CVE-2016-5696, Important) Red Hat would like to thank Jann Horn for reporting CVE-2016-4565 and Yue Cao (Cyber Security Group of the CS department of University of California in Riverside) for reporting CVE-2016-5696. The CVE-2016-4470 issue was discovered by David Howells (Red Hat Inc.). 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1310570 - CVE-2016-4565 kernel: infiniband: Unprivileged process can overwrite kernel memory using rdma_ucm.ko 1341716 - CVE-2016-4470 kernel: Uninitialized variable in request_key handling causes kernel crash in error handling path 1354708 - CVE-2016-5696 kernel: challenge ACK counter information disclosure. 6. Package List: Red Hat Enterprise Linux ComputeNode EUS (v.7.1): Source: kernel-3.10.0-229.40.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-229.40.1.el7.noarch.rpm kernel-doc-3.10.0-229.40.1.el7.noarch.rpm x86_64: kernel-3.10.0-229.40.1.el7.x86_64.rpm kernel-debug-3.10.0-229.40.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-229.40.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-229.40.1.el7.x86_64.rpm kernel-devel-3.10.0-229.40.1.el7.x86_64.rpm kernel-headers-3.10.0-229.40.1.el7.x86_64.rpm kernel-tools-3.10.0-229.40.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-229.40.1.el7.x86_64.rpm perf-3.10.0-229.40.1.el7.x86_64.rpm perf-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.1): x86_64: kernel-debug-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-229.40.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-229.40.1.el7.x86_64.rpm perf-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm python-perf-3.10.0-229.40.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm Red Hat Enterprise Linux Server EUS (v.7.1): Source: kernel-3.10.0-229.40.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-229.40.1.el7.noarch.rpm kernel-doc-3.10.0-229.40.1.el7.noarch.rpm ppc64: kernel-3.10.0-229.40.1.el7.ppc64.rpm kernel-bootwrapper-3.10.0-229.40.1.el7.ppc64.rpm kernel-debug-3.10.0-229.40.1.el7.ppc64.rpm kernel-debug-debuginfo-3.10.0-229.40.1.el7.ppc64.rpm kernel-debug-devel-3.10.0-229.40.1.el7.ppc64.rpm kernel-debuginfo-3.10.0-229.40.1.el7.ppc64.rpm kernel-debuginfo-common-ppc64-3.10.0-229.40.1.el7.ppc64.rpm kernel-devel-3.10.0-229.40.1.el7.ppc64.rpm kernel-headers-3.10.0-229.40.1.el7.ppc64.rpm kernel-tools-3.10.0-229.40.1.el7.ppc64.rpm kernel-tools-debuginfo-3.10.0-229.40.1.el7.ppc64.rpm kernel-tools-libs-3.10.0-229.40.1.el7.ppc64.rpm perf-3.10.0-229.40.1.el7.ppc64.rpm perf-debuginfo-3.10.0-229.40.1.el7.ppc64.rpm python-perf-debuginfo-3.10.0-229.40.1.el7.ppc64.rpm s390x: kernel-3.10.0-229.40.1.el7.s390x.rpm kernel-debug-3.10.0-229.40.1.el7.s390x.rpm kernel-debug-debuginfo-3.10.0-229.40.1.el7.s390x.rpm kernel-debug-devel-3.10.0-229.40.1.el7.s390x.rpm kernel-debuginfo-3.10.0-229.40.1.el7.s390x.rpm kernel-debuginfo-common-s390x-3.10.0-229.40.1.el7.s390x.rpm kernel-devel-3.10.0-229.40.1.el7.s390x.rpm kernel-headers-3.10.0-229.40.1.el7.s390x.rpm kernel-kdump-3.10.0-229.40.1.el7.s390x.rpm kernel-kdump-debuginfo-3.10.0-229.40.1.el7.s390x.rpm kernel-kdump-devel-3.10.0-229.40.1.el7.s390x.rpm perf-3.10.0-229.40.1.el7.s390x.rpm perf-debuginfo-3.10.0-229.40.1.el7.s390x.rpm python-perf-debuginfo-3.10.0-229.40.1.el7.s390x.rpm x86_64: kernel-3.10.0-229.40.1.el7.x86_64.rpm kernel-debug-3.10.0-229.40.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-229.40.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-229.40.1.el7.x86_64.rpm kernel-devel-3.10.0-229.40.1.el7.x86_64.rpm kernel-headers-3.10.0-229.40.1.el7.x86_64.rpm kernel-tools-3.10.0-229.40.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-229.40.1.el7.x86_64.rpm perf-3.10.0-229.40.1.el7.x86_64.rpm perf-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm Red Hat Enterprise Linux Server EUS (v. 7.1): Source: kernel-3.10.0-229.40.1.ael7b.src.rpm noarch: kernel-abi-whitelists-3.10.0-229.40.1.ael7b.noarch.rpm kernel-doc-3.10.0-229.40.1.ael7b.noarch.rpm ppc64le: kernel-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-bootwrapper-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-debug-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-debug-debuginfo-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-debuginfo-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-devel-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-headers-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-tools-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-tools-debuginfo-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-tools-libs-3.10.0-229.40.1.ael7b.ppc64le.rpm perf-3.10.0-229.40.1.ael7b.ppc64le.rpm perf-debuginfo-3.10.0-229.40.1.ael7b.ppc64le.rpm python-perf-debuginfo-3.10.0-229.40.1.ael7b.ppc64le.rpm Red Hat Enterprise Linux Server Optional EUS (v.7.1): ppc64: kernel-debug-debuginfo-3.10.0-229.40.1.el7.ppc64.rpm kernel-debuginfo-3.10.0-229.40.1.el7.ppc64.rpm kernel-debuginfo-common-ppc64-3.10.0-229.40.1.el7.ppc64.rpm kernel-tools-debuginfo-3.10.0-229.40.1.el7.ppc64.rpm kernel-tools-libs-devel-3.10.0-229.40.1.el7.ppc64.rpm perf-debuginfo-3.10.0-229.40.1.el7.ppc64.rpm python-perf-3.10.0-229.40.1.el7.ppc64.rpm python-perf-debuginfo-3.10.0-229.40.1.el7.ppc64.rpm s390x: kernel-debug-debuginfo-3.10.0-229.40.1.el7.s390x.rpm kernel-debuginfo-3.10.0-229.40.1.el7.s390x.rpm kernel-debuginfo-common-s390x-3.10.0-229.40.1.el7.s390x.rpm kernel-kdump-debuginfo-3.10.0-229.40.1.el7.s390x.rpm perf-debuginfo-3.10.0-229.40.1.el7.s390x.rpm python-perf-3.10.0-229.40.1.el7.s390x.rpm python-perf-debuginfo-3.10.0-229.40.1.el7.s390x.rpm x86_64: kernel-debug-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-229.40.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-229.40.1.el7.x86_64.rpm perf-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm python-perf-3.10.0-229.40.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional EUS (v. 7.1): ppc64le: kernel-debug-debuginfo-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-debug-devel-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-debuginfo-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-tools-debuginfo-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-tools-libs-devel-3.10.0-229.40.1.ael7b.ppc64le.rpm perf-debuginfo-3.10.0-229.40.1.ael7b.ppc64le.rpm python-perf-3.10.0-229.40.1.ael7b.ppc64le.rpm python-perf-debuginfo-3.10.0-229.40.1.ael7b.ppc64le.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2016-4470 https://access.redhat.com/security/cve/CVE-2016-4565 https://access.redhat.com/security/cve/CVE-2016-5696 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2016 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFXvHb0XlSAg2UNWIIRAjQCAJwL/6O1STRM5ctSuThZwU8Nb6mcDACdE5gh ENdtmy7rWAntcOoDcJJXHKc=2mv7 -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Crucial kernel security patch released by Red Hat tackling several vulnerabilities classified as major threats.. Red Hat Kernel Update, Linux Kernel Security, Memory Exploit Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 23, 2016 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200