gpp_maybe
Live patch for the linux kernel
SUSE-SLE-Live-Patching-12-2015-488
This update contains a kernel live patch for the 3.12.43-52.6 SUSE Linux Enterprise Server 12 Kernel, fixing following security issues. - CVE-2015-5364/CVE-2015-5366: Two denial of service attacks via a flood of UDP packets with invalid checksums were fixed that could be used by remote attackers to delay execution. (bsc#939276) - CVE-2015-1805: The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel did not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allowed local users to cause a denial of service (system crash) or possibly gain privileges via a crafted application, aka an "I/O vector array overrun." (bsc#939270) - CVE-2015-4700: A BPF Jit optimization flaw could allow local users to panic the kernel. (bsc#939273)
-
Release DateAug 14 2015
-
ReferencesBugzilla: 939044, 939270, 939273, 939276
CVEs: CVE-2015-1805, CVE-2015-4700, CVE-2015-5364, CVE-2015-5366 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Live Patching 12 x86_64
-
Packageskgraft-patch-3_12_43-52_6-default
Kgraft patch modulekgraft-patch-3_12_43-52_6-xen2-6.1 lock rpm
Kgraft patch modulekgraft-patch-SLE12_Update_52-6.1 lock rpm
Kgraft patch module2-6.1 lock src