Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
98

Critical Kernel Exploit in Red Hat 7.1 RHSA-2016:1657-01 Advisory

An update for kernel is now available for Red Hat Enterprise Linux 7.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel security update Advisory ID: RHSA-2016:1657-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2016:1657.html Issue date: 2016-08-23 CVE Names: CVE-2016-4470 CVE-2016-4565 CVE-2016-5696 ==================================================================== 1. Summary: An update for kernel is now available for Red Hat Enterprise Linux 7.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode EUS (v. 7.1) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.1) - x86_64 Red Hat Enterprise Linux Server EUS (v. 7.1) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional EUS (v. 7.1) - ppc64, ppc64le, s390x, x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * A flaw was found in the Linux kernel's keyring handling code, where in key_reject_and_link() an uninitialised variable would eventually lead to arbitrary free address which could allow attacker to use a use-after-free style attack. (CVE-2016-4470, Important) * A flaw was found in the way certain interfaces of the Linux kernel's Infiniband subsystem used write() as bi-directional ioctl() replacement, which could lead toinsufficient memory security checks when being invoked using the splice() system call. A local unprivileged user on a system with either Infiniband hardware present or RDMA Userspace Connection Manager Access module explicitly loaded, could use this flaw to escalate their privileges on the system. (CVE-2016-4565, Important) * A flaw was found in the implementation of the Linux kernel's handling of networking challenge ack where an attacker is able to determine the shared counter which could be used to determine sequence numbers for TCP stream injection. (CVE-2016-5696, Important) Red Hat would like to thank Jann Horn for reporting CVE-2016-4565 and Yue Cao (Cyber Security Group of the CS department of University of California in Riverside) for reporting CVE-2016-5696. The CVE-2016-4470 issue was discovered by David Howells (Red Hat Inc.). 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1310570 - CVE-2016-4565 kernel: infiniband: Unprivileged process can overwrite kernel memory using rdma_ucm.ko 1341716 - CVE-2016-4470 kernel: Uninitialized variable in request_key handling causes kernel crash in error handling path 1354708 - CVE-2016-5696 kernel: challenge ACK counter information disclosure. 6. Package List: Red Hat Enterprise Linux ComputeNode EUS (v.7.1): Source: kernel-3.10.0-229.40.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-229.40.1.el7.noarch.rpm kernel-doc-3.10.0-229.40.1.el7.noarch.rpm x86_64: kernel-3.10.0-229.40.1.el7.x86_64.rpm kernel-debug-3.10.0-229.40.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-229.40.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-229.40.1.el7.x86_64.rpm kernel-devel-3.10.0-229.40.1.el7.x86_64.rpm kernel-headers-3.10.0-229.40.1.el7.x86_64.rpm kernel-tools-3.10.0-229.40.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-229.40.1.el7.x86_64.rpm perf-3.10.0-229.40.1.el7.x86_64.rpm perf-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.1): x86_64: kernel-debug-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-229.40.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-229.40.1.el7.x86_64.rpm perf-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm python-perf-3.10.0-229.40.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm Red Hat Enterprise Linux Server EUS (v.7.1): Source: kernel-3.10.0-229.40.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-229.40.1.el7.noarch.rpm kernel-doc-3.10.0-229.40.1.el7.noarch.rpm ppc64: kernel-3.10.0-229.40.1.el7.ppc64.rpm kernel-bootwrapper-3.10.0-229.40.1.el7.ppc64.rpm kernel-debug-3.10.0-229.40.1.el7.ppc64.rpm kernel-debug-debuginfo-3.10.0-229.40.1.el7.ppc64.rpm kernel-debug-devel-3.10.0-229.40.1.el7.ppc64.rpm kernel-debuginfo-3.10.0-229.40.1.el7.ppc64.rpm kernel-debuginfo-common-ppc64-3.10.0-229.40.1.el7.ppc64.rpm kernel-devel-3.10.0-229.40.1.el7.ppc64.rpm kernel-headers-3.10.0-229.40.1.el7.ppc64.rpm kernel-tools-3.10.0-229.40.1.el7.ppc64.rpm kernel-tools-debuginfo-3.10.0-229.40.1.el7.ppc64.rpm kernel-tools-libs-3.10.0-229.40.1.el7.ppc64.rpm perf-3.10.0-229.40.1.el7.ppc64.rpm perf-debuginfo-3.10.0-229.40.1.el7.ppc64.rpm python-perf-debuginfo-3.10.0-229.40.1.el7.ppc64.rpm s390x: kernel-3.10.0-229.40.1.el7.s390x.rpm kernel-debug-3.10.0-229.40.1.el7.s390x.rpm kernel-debug-debuginfo-3.10.0-229.40.1.el7.s390x.rpm kernel-debug-devel-3.10.0-229.40.1.el7.s390x.rpm kernel-debuginfo-3.10.0-229.40.1.el7.s390x.rpm kernel-debuginfo-common-s390x-3.10.0-229.40.1.el7.s390x.rpm kernel-devel-3.10.0-229.40.1.el7.s390x.rpm kernel-headers-3.10.0-229.40.1.el7.s390x.rpm kernel-kdump-3.10.0-229.40.1.el7.s390x.rpm kernel-kdump-debuginfo-3.10.0-229.40.1.el7.s390x.rpm kernel-kdump-devel-3.10.0-229.40.1.el7.s390x.rpm perf-3.10.0-229.40.1.el7.s390x.rpm perf-debuginfo-3.10.0-229.40.1.el7.s390x.rpm python-perf-debuginfo-3.10.0-229.40.1.el7.s390x.rpm x86_64: kernel-3.10.0-229.40.1.el7.x86_64.rpm kernel-debug-3.10.0-229.40.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-229.40.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-229.40.1.el7.x86_64.rpm kernel-devel-3.10.0-229.40.1.el7.x86_64.rpm kernel-headers-3.10.0-229.40.1.el7.x86_64.rpm kernel-tools-3.10.0-229.40.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-229.40.1.el7.x86_64.rpm perf-3.10.0-229.40.1.el7.x86_64.rpm perf-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm Red Hat Enterprise Linux Server EUS (v. 7.1): Source: kernel-3.10.0-229.40.1.ael7b.src.rpm noarch: kernel-abi-whitelists-3.10.0-229.40.1.ael7b.noarch.rpm kernel-doc-3.10.0-229.40.1.ael7b.noarch.rpm ppc64le: kernel-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-bootwrapper-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-debug-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-debug-debuginfo-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-debuginfo-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-devel-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-headers-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-tools-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-tools-debuginfo-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-tools-libs-3.10.0-229.40.1.ael7b.ppc64le.rpm perf-3.10.0-229.40.1.ael7b.ppc64le.rpm perf-debuginfo-3.10.0-229.40.1.ael7b.ppc64le.rpm python-perf-debuginfo-3.10.0-229.40.1.ael7b.ppc64le.rpm Red Hat Enterprise Linux Server Optional EUS (v.7.1): ppc64: kernel-debug-debuginfo-3.10.0-229.40.1.el7.ppc64.rpm kernel-debuginfo-3.10.0-229.40.1.el7.ppc64.rpm kernel-debuginfo-common-ppc64-3.10.0-229.40.1.el7.ppc64.rpm kernel-tools-debuginfo-3.10.0-229.40.1.el7.ppc64.rpm kernel-tools-libs-devel-3.10.0-229.40.1.el7.ppc64.rpm perf-debuginfo-3.10.0-229.40.1.el7.ppc64.rpm python-perf-3.10.0-229.40.1.el7.ppc64.rpm python-perf-debuginfo-3.10.0-229.40.1.el7.ppc64.rpm s390x: kernel-debug-debuginfo-3.10.0-229.40.1.el7.s390x.rpm kernel-debuginfo-3.10.0-229.40.1.el7.s390x.rpm kernel-debuginfo-common-s390x-3.10.0-229.40.1.el7.s390x.rpm kernel-kdump-debuginfo-3.10.0-229.40.1.el7.s390x.rpm perf-debuginfo-3.10.0-229.40.1.el7.s390x.rpm python-perf-3.10.0-229.40.1.el7.s390x.rpm python-perf-debuginfo-3.10.0-229.40.1.el7.s390x.rpm x86_64: kernel-debug-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-229.40.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-229.40.1.el7.x86_64.rpm perf-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm python-perf-3.10.0-229.40.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-229.40.1.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional EUS (v. 7.1): ppc64le: kernel-debug-debuginfo-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-debug-devel-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-debuginfo-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-tools-debuginfo-3.10.0-229.40.1.ael7b.ppc64le.rpm kernel-tools-libs-devel-3.10.0-229.40.1.ael7b.ppc64le.rpm perf-debuginfo-3.10.0-229.40.1.ael7b.ppc64le.rpm python-perf-3.10.0-229.40.1.ael7b.ppc64le.rpm python-perf-debuginfo-3.10.0-229.40.1.ael7b.ppc64le.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2016-4470 https://access.redhat.com/security/cve/CVE-2016-4565 https://access.redhat.com/security/cve/CVE-2016-5696 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2016 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFXvHb0XlSAg2UNWIIRAjQCAJwL/6O1STRM5ctSuThZwU8Nb6mcDACdE5gh ENdtmy7rWAntcOoDcJJXHKc=2mv7 -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Crucial kernel security patch released by Red Hat tackling several vulnerabilities classified as major threats.. Red Hat Kernel Update, Linux Kernel Security, Memory Exploit Fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 23, 2016 Important Red Hat
100

SUSE 11 SP4: 2016:0911-1 Important: Kernel Security Update

An update that solves 23 vulnerabilities and has 42 fixes An update that solves 23 vulnerabilities and has 42 fixes An update that solves 23 vulnerabilities and has 42 fixes is now available. is now available.. SUSE Security Update: Security update for the Linux Kernel ______________________________________________________________________________ Announcement ID: SUSE-SU-2016:0911-1 Rating: important References: #758040 #904035 #912738 #915183 #924919 #933782 #937444 #940017 #940946 #942082 #947128 #948330 #949298 #951392 #951815 #952976 #953369 #954992 #955308 #955654 #955837 #955925 #956084 #956375 #956514 #956708 #956949 #957986 #957988 #957990 #958000 #958463 #958886 #958906 #958912 #958951 #959190 #959312 #959399 #959649 #959705 #961500 #961509 #961516 #961658 #962965 #963276 #963561 #963765 #963767 #964201 #964818 #966094 #966137 #966437 #966693 #967042 #967972 #967973 #967974 #967975 #968011 #968012 #968013 #969307 Cross-References: CVE-2013-7446 CVE-2015-7515 CVE-2015-7550 CVE-2015-8539 CVE-2015-8543 CVE-2015-8550 CVE-2015-8551 CVE-2015-8552 CVE-2015-8569 CVE-2015-8575 CVE-2015-8767 CVE-2015-8785 CVE-2015-8812 CVE-2016-0723 CVE-2016-2069 CVE-2016-2384 CVE-2016-2543 CVE-2016-2544 CVE-2016-2545 CVE-2016-2546 CVE-2016-2547 CVE-2016-2548 CVE-2016-2549 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Server 11-EXTRA SUSE Linux Enterprise Desktop 11-SP4 SUSE Linux Enterprise Debuginfo11-SP4 ______________________________________________________________________________ An update that solves 23 vulnerabilities and has 42 fixes is now available. Description: The SUSE Linux Enterprise 11 SP4 kernel was updated to receive various security and bugfixes. Following feature was added to kernel-xen: - A improved XEN blkfront module was added, which allows more I/O bandwidth. (FATE#320200) It is called xen-blkfront in PV, and xen-vbd-upstream in HVM mode. The following security bugs were fixed: - CVE-2013-7446: Use-after-free vulnerability in net/unix/af_unix.c in the Linux kernel allowed local users to bypass intended AF_UNIX socket permissions or cause a denial of service (panic) via crafted epoll_ctl calls (bnc#955654). - CVE-2015-7515: An out of bounds memory access in the aiptek USB driver could be used by physical local attackers to crash the kernel (bnc#956708). - CVE-2015-7550: The keyctl_read_key function in security/keys/keyctl.c in the Linux kernel did not properly use a semaphore, which allowed local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted application that leverages a race condition between keyctl_revoke and keyctl_read calls (bnc#958951). - CVE-2015-8539: The KEYS subsystem in the Linux kernel allowed local users to gain privileges or cause a denial of service (BUG) via crafted keyctl commands that negatively instantiate a key, related to security/keys/encrypted-keys/encrypted.c, security/keys/trusted.c, and security/keys/user_defined.c (bnc#958463). - CVE-2015-8543: The networking implementation in the Linux kernel did not validate protocol identifiers for certain protocol families, which allowed local users to cause a denial of service (NULL function pointer dereference and system crash) or possibly gain privileges by leveraging CLONE_NEWUSER support toexecute a crafted SOCK_RAW application (bnc#958886). - CVE-2015-8550: Compiler optimizations in the XEN PV backend drivers could have lead to double fetch vulnerabilities, causing denial of service or arbitrary code execution (depending on the configuration) (bsc#957988). - CVE-2015-8551, CVE-2015-8552: xen/pciback: For XEN_PCI_OP_disable_msi[|x] only disable if device has MSI(X) enabled (bsc#957990). - CVE-2015-8569: The (1) pptp_bind and (2) pptp_connect functions in drivers/net/ppp/pptp.c in the Linux kernel did not verify an address length, which allowed local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism via a crafted application (bnc#959190). - CVE-2015-8575: The sco_sock_bind function in net/bluetooth/sco.c in the Linux kernel did not verify an address length, which allowed local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism via a crafted application (bnc#959190 bnc#959399). - CVE-2015-8767: net/sctp/sm_sideeffect.c in the Linux kernel did not properly manage the relationship between a lock and a socket, which allowed local users to cause a denial of service (deadlock) via a crafted sctp_accept call (bnc#961509). - CVE-2015-8785: The fuse_fill_write_pages function in fs/fuse/file.c in the Linux kernel allowed local users to cause a denial of service (infinite loop) via a writev system call that triggers a zero length for the first segment of an iov (bnc#963765). - CVE-2015-8812: A use-after-free flaw was found in the CXGB3 kernel driver when the network was considered to be congested. This could be used by local attackers to cause machine crashes or potentially code execution (bsc#966437). - CVE-2016-0723: Race condition in the tty_ioctl function in drivers/tty/tty_io.c in the Linux kernel allowed local users to obtain sensitive information from kernelmemory or cause a denial of service (use-after-free and system crash) by making a TIOCGETD ioctl call during processing of a TIOCSETD ioctl call (bnc#961500). - CVE-2016-2069: Race conditions in TLB syncing was fixed which could leak to information leaks (bnc#963767). - CVE-2016-2384: Removed a double free in the ALSA usb-audio driver in the umidi object which could lead to crashes (bsc#966693). - CVE-2016-2543: Added a missing NULL check at remove_events ioctl in ALSA that could lead to crashes. (bsc#967972). - CVE-2016-2544, CVE-2016-2545, CVE-2016-2546, CVE-2016-2547, CVE-2016-2548, CVE-2016-2549: Various race conditions in ALSAs timer handling were fixed. (bsc#967975, bsc#967974, bsc#967973, bsc#968011, bsc#968012, bsc#968013). The following non-security bugs were fixed: - alsa: hda - Add one more node in the EAPD supporting candidate list (bsc#963561). - alsa: hda - Apply clock gate workaround to Skylake, too (bsc#966137). - alsa: hda - Fix playback noise with 24/32 bit sample size on BXT (bsc#966137). - alsa: hda - disable dynamic clock gating on Broxton before reset (bsc#966137). - Add /etc/modprobe.d/50-xen.conf selecting Xen frontend driver implementation (bsc#957986, bsc#956084, bsc#961658). - Fix handling of re-write-before-commit for mmapped NFS pages (bsc#964201). - nfsv4: Recovery of recalled read delegations is broken (bsc#956514). - nvme: default to 4k device page size (bsc#967042). - pci: leave MEM and IO decoding disabled during 64-bit BAR sizing, too (bsc#951815). - Refresh patches.xen/xen3-08-x86-ldt-make-modify_ldt-synchronous.patch (bsc#959705). - Refresh patches.xen/xen-vscsi-large-requests (refine fix and also address bsc#966094). - sunrpc: restore fair scheduling to priority queues (bsc#955308). - usb: ftdi_sio: fix race condition in TIOCMIWAIT, and abort of TIOCMIWAIT when the device is removed (bnc#956375). - usb: ftdi_sio: fix status linechange handling for TIOCMIWAIT and TIOCGICOUNT (bnc#956375). - usb: ftdi_sio: fix tiocmget and tiocmset return values (bnc#956375). - usb: ftdi_sio: fix tiocmget indentation (bnc#956375). - usb: ftdi_sio: optimise chars_in_buffer (bnc#956375). - usb: ftdi_sio: refactor modem-control status retrieval (bnc#956375). - usb: ftdi_sio: remove unnecessary memset (bnc#956375). - usb: ftdi_sio: use ftdi_get_modem_status in chars_in_buffer (bnc#956375). - usb: ftdi_sio: use generic chars_in_buffer (bnc#956375). - usb: pl2303: clean up line-status handling (bnc#959649). - usb: pl2303: only wake up MSR queue on changes (bnc#959649). - usb: pl2303: remove bogus delta_msr_wait wake up (bnc#959649). - usb: serial: export usb_serial_generic_chars_in_buffer (bnc#956375). - Update patches.fixes/mm-exclude-reserved-pages-from-dirtyable-memory-fix.patch (bnc#940017, bnc#949298, bnc#947128). - xen: Update Xen config files (enable upstream block frontend). - ec2: Update kabi files and start tracking ec2 - xen: consolidate and simplify struct xenbus_driver instantiation (bsc#961658 fate#320200). - blktap: also call blkif_disconnect() when frontend switched to closed (bsc#952976). - blktap: refine mm tracking (bsc#952976). - block: Always check queue limits for cloned requests (bsc#933782). - block: xen-blkfront: Fix possible NULL ptr dereference (bsc#961658 fate#320200). - bnx2x: Add new device ids under the Qlogic vendor (bsc#964818). - bnx2x: Alloc 4k fragment for each rx ring buffer element (bsc#953369). - bnx2x: fix DMA API usage (bsc#953369). - driver core: Add BUS_NOTIFY_REMOVED_DEVICE event (bnc#962965). - driver: xen-blkfront: move talk_to_blkback to a more suitable place (bsc#961658 fate#320200). - drivers: xen-blkfront: only talk_to_blkback() when in XenbusStateInitialising (bsc#961658 fate#320200). - drm/i915: Change semantics of hw_contexts_disabled (bsc#963276). - drm/i915: Evict CS TLBs between batches(bsc#758040). - drm/i915: Fix SRC_COPY width on 830/845g (bsc#758040). - e1000e: Do not read ICR in Other interrupt (bsc#924919). - e1000e: Do not write lsc to ics in msi-x mode (bsc#924919). - e1000e: Fix msi-x interrupt automask (bsc#924919). - e1000e: Remove unreachable code (bsc#924919). - ext3: NULL dereference in ext3_evict_inode() (bsc#942082). - ext3: fix data=journal fast mount/umount hang (bsc#942082). - firmware: Create directories for external firmware (bsc#959312). - firmware: Simplify directory creation (bsc#959312). - ftdi_sio: private backport of TIOCMIWAIT (bnc#956375). - iommu/vt-d: Do not change dma domain on dma-mask change (bsc#955925). - jbd: Fix unreclaimed pages after truncate in data=journal mode (bsc#961516). - kabi/severities: Add exception for bnx2x_schedule_sp_rtnl() There is no external, 3rd party modules use the symbol and the bnx2x_schedule_sp_rtnl symbol is only used in the bnx2x driver. (bsc#953369) - kbuild: create directory for dir/file.o (bsc#959312). - llist/xen-blkfront: implement safe version of llist_for_each_entry (bsc#961658 fate#320200). - lpfc: Fix null ndlp dereference in target_reset_handler (bsc#951392). - mm-memcg-print-statistics-from-live-counters-fix (bnc#969307). - nvme: Clear BIO_SEG_VALID flag in nvme_bio_split() (bsc#954992). - pci: Update VPD size with correct length (bsc#958906). - pl2303: fix TIOCMIWAIT (bnc#959649). - pl2303: introduce private disconnect method (bnc#959649). - qeth: initialize net_device with carrier off (bnc#958000, LTC#136514). - s390/cio: collect format 1 channel-path description data (bnc#958000, LTC#136434). - s390/cio: ensure consistent measurement state (bnc#958000, LTC#136434). - s390/cio: fix measurement characteristics memleak (bnc#958000, LTC#136434). - s390/cio: update measurement characteristics (bnc#958000, LTC#136434). - s390/dasd: fix failfast for disconnected devices (bnc#958000, LTC#135138). -s390/sclp: Determine HSA size dynamically for zfcpdump (bnc#958000, LTC#136143). - s390/sclp: Move declarations for sclp_sdias into separate header file (bnc#958000, LTC#136143). - scsi_dh_rdac: always retry MODE SELECT on command lock violation (bsc#956949). - supported.conf: Add xen-blkfront. - tg3: 5715 does not link up when autoneg off (bsc#904035). - usb: serial: ftdi_sio: Add missing chars_in_buffer function (bnc#956375). - vmxnet3: fix building without CONFIG_PCI_MSI (bsc#958912). - vmxnet3: fix netpoll race condition (bsc#958912). - xen, blkfront: factor out flush-related checks from do_blkif_request() (bsc#961658 fate#320200). - xen-blkfront: Handle discard requests (bsc#961658 fate#320200). - xen-blkfront: If no barrier or flush is supported, use invalid operation (bsc#961658 fate#320200). - xen-blkfront: Introduce a 'max' module parameter to alter the amount of indirect segments (bsc#961658 fate#320200). - xen-blkfront: Silence pfn maybe-uninitialized warning (bsc#961658 fate#320200). - xen-blkfront: allow building in our Xen environment (bsc#961658 fate#320200). - xen-blkfront: check for null drvdata in blkback_changed (XenbusStateClosing) (bsc#961658 fate#320200). - xen-blkfront: do not add indirect pages to list when !feature_persistent (bsc#961658 fate#320200). - xen-blkfront: drop the use of llist_for_each_entry_safe (bsc#961658 fate#320200). - xen-blkfront: fix a deadlock while handling discard response (bsc#961658 fate#320200). - xen-blkfront: fix accounting of reqs when migrating (bsc#961658 fate#320200). - xen-blkfront: free allocated page (bsc#961658 fate#320200). - xen-blkfront: handle backend CLOSED without CLOSING (bsc#961658 fate#320200). - xen-blkfront: handle bvecs with partial data (bsc#961658 fate#320200). - xen-blkfront: improve aproximation of required grants per request (bsc#961658 fate#320200). - xen-blkfront: make blkif_io_lock spinlockper-device (bsc#961658 fate#320200). - xen-blkfront: plug device number leak in xlblk_init() error path (bsc#961658 fate#320200). - xen-blkfront: pre-allocate pages for requests (bsc#961658 fate#320200). - xen-blkfront: remove frame list from blk_shadow (bsc#961658 fate#320200). - xen-blkfront: remove type check from blkfront_setup_discard (bsc#961658 fate#320200). - xen-blkfront: restore the non-persistent data path (bsc#961658 fate#320200). - xen-blkfront: revoke foreign access for grants not mapped by the backend (bsc#961658 fate#320200). - xen-blkfront: set blk_queue_max_hw_sectors correctly (bsc#961658 fate#320200). - xen-blkfront: switch from llist to list (bsc#961658 fate#320200). - xen-blkfront: use a different scatterlist for each request (bsc#961658 fate#320200). - xen-block: implement indirect descriptors (bsc#961658 fate#320200). - xen/blk[front|back]: Enhance discard support with secure erasing support (bsc#961658 fate#320200). - xen/blk[front|back]: Squash blkif_request_rw and blkif_request_discard together (bsc#961658 fate#320200). - xen/blkback: Persistent grant maps for xen blk drivers (bsc#961658 fate#320200). - xen/blkback: persistent-grants fixes (bsc#961658 fate#320200). - xen/blkfront: Fix crash if backend does not follow the right states (bsc#961658 fate#320200). - xen/blkfront: do not put bdev right after getting it (bsc#961658 fate#320200). - xen/blkfront: improve protection against issuing unsupported REQ_FUA (bsc#961658 fate#320200). - xen/blkfront: remove redundant flush_op (bsc#961658 fate#320200). - xen/panic/x86: Allow cpus to save registers even if they (bnc#940946). - xen/panic/x86: Fix re-entrance problem due to panic on (bnc#937444). - xen/pvhvm: If xen_platform_pci=0 is set do not blow up (v4) (bsc#961658 fate#320200). - xen/x86/mm: Add barriers and document switch_mm()-vs-flush synchronization (bnc#963767). - xen: x86: mm: drop TLBflush from ptep_set_access_flags (bsc#948330). - xen: x86: mm: only do a local tlb flush in ptep_set_access_flags() (bsc#948330). - xfs: Skip dirty pages in -> releasepage (bnc#912738, bnc#915183). - zfcp: fix fc_host port_type with NPIV (bnc#958000, LTC#132479). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-kernel-201603-12480=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-kernel-201603-12480=1 - SUSE Linux Enterprise Server 11-EXTRA: zypper in -t patch slexsp3-kernel-201603-12480=1 - SUSE Linux Enterprise Desktop 11-SP4: zypper in -t patch sledsp4-kernel-201603-12480=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-kernel-201603-12480=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (noarch): kernel-docs-3.0.101-71.2 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): kernel-default-3.0.101-71.1 kernel-default-base-3.0.101-71.1 kernel-default-devel-3.0.101-71.1 kernel-source-3.0.101-71.1 kernel-syms-3.0.101-71.1 kernel-trace-3.0.101-71.1 kernel-trace-base-3.0.101-71.1 kernel-trace-devel-3.0.101-71.1 - SUSE Linux Enterprise Server 11-SP4 (i586 x86_64): kernel-ec2-3.0.101-71.1 kernel-ec2-base-3.0.101-71.1 kernel-ec2-devel-3.0.101-71.1 kernel-xen-3.0.101-71.1 kernel-xen-base-3.0.101-71.1 kernel-xen-devel-3.0.101-71.1 - SUSE Linux Enterprise Server 11-SP4 (ppc64): kernel-ppc64-3.0.101-71.1 kernel-ppc64-base-3.0.101-71.1 kernel-ppc64-devel-3.0.101-71.1 - SUSE Linux Enterprise Server 11-SP4 (s390x): kernel-default-man-3.0.101-71.1 - SUSE Linux Enterprise Server 11-SP4 (i586): kernel-pae-3.0.101-71.1 kernel-pae-base-3.0.101-71.1 kernel-pae-devel-3.0.101-71.1 - SUSE Linux Enterprise Server 11-EXTRA (i586 ia64 ppc64 s390x x86_64): kernel-default-extra-3.0.101-71.1 - SUSE Linux Enterprise Server 11-EXTRA (i586 x86_64): kernel-xen-extra-3.0.101-71.1 - SUSE Linux Enterprise Server 11-EXTRA (x86_64): kernel-trace-extra-3.0.101-71.1 - SUSE Linux Enterprise Server 11-EXTRA (ppc64): kernel-ppc64-extra-3.0.101-71.1 - SUSE Linux Enterprise Server 11-EXTRA (i586): kernel-pae-extra-3.0.101-71.1 - SUSE Linux Enterprise Desktop 11-SP4 (i586 x86_64): kernel-default-3.0.101-71.1 kernel-default-base-3.0.101-71.1 kernel-default-devel-3.0.101-71.1 kernel-default-extra-3.0.101-71.1 kernel-source-3.0.101-71.1 kernel-syms-3.0.101-71.1 kernel-trace-devel-3.0.101-71.1 kernel-xen-3.0.101-71.1 kernel-xen-base-3.0.101-71.1 kernel-xen-devel-3.0.101-71.1 kernel-xen-extra-3.0.101-71.1 - SUSE Linux Enterprise Desktop 11-SP4 (i586): kernel-pae-3.0.101-71.1 kernel-pae-base-3.0.101-71.1 kernel-pae-devel-3.0.101-71.1 kernel-pae-extra-3.0.101-71.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): kernel-default-debuginfo-3.0.101-71.1 kernel-default-debugsource-3.0.101-71.1 kernel-trace-debuginfo-3.0.101-71.1 kernel-trace-debugsource-3.0.101-71.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 s390x x86_64): kernel-default-devel-debuginfo-3.0.101-71.1 kernel-trace-devel-debuginfo-3.0.101-71.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 x86_64): kernel-ec2-debuginfo-3.0.101-71.1 kernel-ec2-debugsource-3.0.101-71.1 kernel-xen-debuginfo-3.0.101-71.1 kernel-xen-debugsource-3.0.101-71.1 kernel-xen-devel-debuginfo-3.0.101-71.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (ppc64): kernel-ppc64-debuginfo-3.0.101-71.1 kernel-ppc64-debugsource-3.0.101-71.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586): kernel-pae-debuginfo-3.0.101-71.1 kernel-pae-debugsource-3.0.101-71.1 kernel-pae-devel-debuginfo-3.0.101-71.1 References: https://www.suse.com/security/cve/CVE-2013-7446.html https://www.suse.com/security/cve/CVE-2015-7515.html https://www.suse.com/security/cve/CVE-2015-7550.html https://www.suse.com/security/cve/CVE-2015-8539.html https://www.suse.com/security/cve/CVE-2015-8543.html https://www.suse.com/security/cve/CVE-2015-8550.html https://www.suse.com/security/cve/CVE-2015-8551.html https://www.suse.com/security/cve/CVE-2015-8552.html https://www.suse.com/security/cve/CVE-2015-8569.html https://www.suse.com/security/cve/CVE-2015-8575.html https://www.suse.com/security/cve/CVE-2015-8767.html https://www.suse.com/security/cve/CVE-2015-8785.html https://www.suse.com/security/cve/CVE-2015-8812.html https://www.suse.com/security/cve/CVE-2016-0723.html https://www.suse.com/security/cve/CVE-2016-2069.html https://www.suse.com/security/cve/CVE-2016-2384.html https://www.suse.com/security/cve/CVE-2016-2543.html https://www.suse.com/security/cve/CVE-2016-2544.html https://www.suse.com/security/cve/CVE-2016-2545.html https://www.suse.com/security/cve/CVE-2016-2546.html https://www.suse.com/security/cve/CVE-2016-2547.html https://www.suse.com/security/cve/CVE-2016-2548.html https://www.suse.com/security/cve/CVE-2016-2549.html https://bugzilla.suse.com/758040 https://bugzilla.suse.com/904035 https://bugzilla.suse.com/912738 https://bugzilla.suse.com/915183 https://bugzilla.suse.com/924919 https://bugzilla.suse.com/933782 https://bugzilla.suse.com/937444 https://bugzilla.suse.com/940017 https://bugzilla.suse.com/940946 https://bugzilla.suse.com/942082 https://bugzilla.suse.com/947128 https://bugzilla.suse.com/948330 https://bugzilla.suse.com/949298 https://bugzilla.suse.com/951392 https://bugzilla.suse.com/951815 https://bugzilla.suse.com/952976 https://bugzilla.suse.com/953369 https://bugzilla.suse.com/954992 https://bugzilla.suse.com/955308 https://bugzilla.suse.com/955654 https://bugzilla.suse.com/955837 https://bugzilla.suse.com/955925 https://bugzilla.suse.com/956084 https://bugzilla.suse.com/956375 https://bugzilla.suse.com/956514 https://bugzilla.suse.com/956708 https://bugzilla.suse.com/956949 https://bugzilla.suse.com/957986 https://bugzilla.suse.com/957988 https://bugzilla.suse.com/957990 https://bugzilla.suse.com/958000 https://bugzilla.suse.com/958463 https://bugzilla.suse.com/958886 https://bugzilla.suse.com/958906 https://bugzilla.suse.com/958912 https://bugzilla.suse.com/958951 https://bugzilla.suse.com/959190 https://bugzilla.suse.com/959312 https://bugzilla.suse.com/959399 https://bugzilla.suse.com/959649 https://bugzilla.suse.com/959705 https://bugzilla.suse.com/961500 https://bugzilla.suse.com/961509 https://bugzilla.suse.com/961516 https://bugzilla.suse.com/961658 https://bugzilla.suse.com/962965 https://bugzilla.suse.com/963276 https://bugzilla.suse.com/963561 https://bugzilla.suse.com/963765 https://bugzilla.suse.com/963767 https://bugzilla.suse.com/964201 https://bugzilla.suse.com/964818 https://bugzilla.suse.com/966094 https://bugzilla.suse.com/966137 https://bugzilla.suse.com/966437 https://bugzilla.suse.com/966693 https://bugzilla.suse.com/967042 https://bugzilla.suse.com/967972 https://bugzilla.suse.com/967973 https://bugzilla.suse.com/967974 https://bugzilla.suse.com/967975 https://bugzilla.suse.com/968011 https://bugzilla.suse.com/968012 https://bugzilla.suse.com/968013 https://bugzilla.suse.com/969307 . SUSE Linux Kernel has rolled out an update that resolves 23 security vulnerabilities and implements 42 improvements aimed at bolstering both system security and performance stability.. SUSE Linux Kernelupdate, security advisory, system vulnerabilities, important kernel patch. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 30, 2016 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here