SUSE-SU-2015:1490-1
Dashboard / Vulnerabilities / SUSE-SU-2015:1490-1
SUSE-SU-2015:1490-1
Summary: Live patch for the Linux Kernel
Details: This update contains a kernel live patch for the 3.12.43-52.6 SUSE Linux Enterprise Server 12 Kernel, fixing following security issues. - CVE-2015-5364/CVE-2015-5366: Two denial of service attacks via a flood of UDP packets with invalid checksums were fixed that could be used by remote attackers to delay execution. (bsc#939276) - CVE-2015-1805: The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel did not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allowed local users to cause a denial of service (system crash) or possibly gain privileges via a crafted application, aka an 'I/O vector array overrun.' (bsc#939270) - CVE-2015-4700: A BPF Jit optimization flaw could allow local users to panic the kernel. (bsc#939273)
References: https://www.suse.com/support/update/announcement/2015/suse-su-20151490-1/, https://bugzilla.suse.com/939044, https://bugzilla.suse.com/939270, https://bugzilla.suse.com/939273, https://bugzilla.suse.com/939276, https://www.suse.com/security/cve/CVE-2015-1805, https://www.suse.com/security/cve/CVE-2015-4700, https://www.suse.com/security/cve/CVE-2015-5364, https://www.suse.com/security/cve/CVE-2015-5366
Affected packages
Package
Name: kgraft-patch-SLE12_Update_5
Purl: pkg:rpm/suse/kgraft-patch-SLE12_Update_5&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2012
Affected ranges
Type: ECOSYSTEM
Events:
