gpp_maybe
Security update for linux kernel live patch 21 for sle 12 sp1
SUSE-SLE-SERVER-12-SP1-2017-1732
This update for the Linux Kernel 3.12.74-60_64_60 fixes several issues. The following security bugs were fixed: - CVE-2017-15274: security/keys/keyctl.c in the Linux kernel did not consider the case of a NULL payload in conjunction with a nonzero length value, which allowed local users to cause a denial of service (NULL pointer dereference and OOPS) via a crafted add_key or keyctl system call (bsc#1045327). - CVE-2017-1000112: Updated patch for this issue to be in sync with the other livepatches. Description of the issue: Prevent race condition in net-packet code that could have been exploited by unprivileged users to gain root access (bsc#1052368, bsc#1052311). - CVE-2017-9242: The __ip6_append_data function in net/ipv6/ip6_output.c was too late in checking whether an overwrite of an skb data structure may occur, which allowed local users to cause a denial of service (system crash) via crafted system calls (bsc#1042892). - CVE-2017-8890: The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c allowed attackers to cause a denial of service (double free) or possibly have unspecified other impact by leveraging use of the accept system call (bsc#1038564).
-
Release DateOct 19 2017
-
ReferencesBugzilla: 1045327, 1038564, 1042892, 1052311, 1052368
CVEs: CVE-2017-15274, CVE-2017-1000112, CVE-2017-8890, CVE-2017-9242 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Server LTSS 12.1 x86_64
-
Packageskgraft-patch-3_12_74-60_64_60-default
Kgraft patch modulekgraft-patch-3_12_74-60_64_60-xen2-4.1 lock rpm
Kgraft patch modulekgraft-patch-SLE12-SP1_Update_212-4.1 lock rpm
Kgraft patch module2-4.1 lock src