Antw: [security-announce] SUSE-SU-2017:2791-1: important: Security update for Linux Kernel Live Patch 21 for SLE 12 SP1
"Ulrich Windl" <[email protected]> Mon, 23 Oct 2017 08:18:42 +0200
| Newsgroups | gmane.linux.suse.security |
|---|---|
| Message-ID | <[email protected]> |
>>> <[email protected]> schrieb am 20.10.2017 um 03:07 in = Nachricht <[email protected]>: > SUSE Security Update: Security update for Linux Kernel Live Patch 21 for = SLE=20 > 12 SP1 I wonder: Shouldn't the subject be like "[security-announce] SUSE-SU-2017:2= 791-1: important: Security update (Linux Kernel Live Patch 21 for SLE 12 = SP1)"? Or is it actually a security update for the kernel live patch? Regards, Ulrich > _________________________________________________________________________= ___ > __ >=20 > Announcement ID: SUSE-SU-2017:2791-1 > Rating: important > References: #1038564 #1042892 #1045327 #1052311 #1052368=20 > =20 > Cross-References: CVE-2017-1000112 CVE-2017-15274 CVE-2017-8890 > CVE-2017-9242 > Affected Products: > SUSE Linux Enterprise Server for SAP 12-SP1 > SUSE Linux Enterprise Server 12-SP1-LTSS > _________________________________________________________________________= ___ > __ >=20 > An update that solves four vulnerabilities and has one > errata is now available. >=20 > Description: >=20 > This update for the Linux Kernel 3.12.74-60_64_60 fixes several = issues. >=20 > The following security bugs were fixed: >=20 > - CVE-2017-15274: security/keys/keyctl.c in the Linux kernel did not > consider the case of a NULL payload in conjunction with a nonzero=20= > length > value, which allowed local users to cause a denial of service (NULL > pointer dereference and OOPS) via a crafted add_key or keyctl = system > call (bsc#1045327). > - CVE-2017-1000112: Updated patch for this issue to be in sync with = the > other livepatches. Description of the issue: Prevent race condition = in > net-packet code that could have been exploited by unprivileged = users to > gain root access (bsc#1052368, bsc#1052311). > - CVE-2017-9242: The __ip6_append_data function in net/ipv6/ip6_output= .c > was too late in checking whether an overwrite of an skb data = structure > may occur, which allowed local users to cause a denial of service > (system crash) via crafted system calls (bsc#1042892). > - CVE-2017-8890: The inet_csk_clone_lock function in > net/ipv4/inet_connection_sock.c allowed attackers to cause a denial = of > service (double free) or possibly have unspecified other impact by > leveraging use of the accept system call (bsc#1038564). >=20 >=20 > Patch Instructions: >=20 > To install this SUSE Security Update use YaST online_update. > Alternatively you can run the command listed for your product: >=20 > - SUSE Linux Enterprise Server for SAP 12-SP1: >=20 > zypper in -t patch SUSE-SLE-SAP-12-SP1-2017-1732=3D1 >=20 > - SUSE Linux Enterprise Server 12-SP1-LTSS: >=20 > zypper in -t patch SUSE-SLE-SERVER-12-SP1-2017-1732=3D1 >=20 > To bring your system up-to-date, use "zypper patch". >=20 >=20 > Package List: >=20 > - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): >=20 > kgraft-patch-3_12_74-60_64_60-default-2-4.1 > kgraft-patch-3_12_74-60_64_60-xen-2-4.1 >=20 > - SUSE Linux Enterprise Server 12-SP1-LTSS (x86_64): >=20 > kgraft-patch-3_12_74-60_64_60-default-2-4.1 > kgraft-patch-3_12_74-60_64_60-xen-2-4.1 >=20 >=20 > References: >=20 > https://www.suse.com/security/cve/CVE-2017-1000112.html=20 > https://www.suse.com/security/cve/CVE-2017-15274.html=20 > https://www.suse.com/security/cve/CVE-2017-8890.html=20 > https://www.suse.com/security/cve/CVE-2017-9242.html=20 > https://bugzilla.suse.com/1038564=20 > https://bugzilla.suse.com/1042892=20 > https://bugzilla.suse.com/1045327=20 > https://bugzilla.suse.com/1052311=20 > https://bugzilla.suse.com/1052368=20 >=20 > --=20 > To unsubscribe, e-mail: [email protected]= rg=20 > For additional commands, e-mail: opensuse-security-announce+help@opensuse= .org=20 -- To unsubscribe, e-mail: [email protected] To contact the owner, e-mail: [email protected]