Описание
Security update for Linux Kernel Live Patch 3 for SLE 12 SP2
This update for the Linux Kernel 4.4.21-90 fixes several issues.
The following security bugs were fixed:
- CVE-2016-10088: The sg implementation in the Linux kernel did not properly restrict write operations in situations where the KERNEL_DS option is set, which allowed local users to read or write to arbitrary kernel memory locations or cause a denial of service (use-after-free) by leveraging access to a /dev/sg device, related to block/bsg.c and drivers/scsi/sg.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-9576 (bsc#1019079).
Список пакетов
SUSE Linux Enterprise Live Patching 12
kgraft-patch-4_4_21-90-default-2-2.1
Ссылки
- Link for SUSE-SU-2017:0232-1
- E-Mail link for SUSE-SU-2017:0232-1
- SUSE Security Ratings
- SUSE Bug 1019079
- SUSE CVE CVE-2016-10088 page
Описание
The sg implementation in the Linux kernel through 4.9 does not properly restrict write operations in situations where the KERNEL_DS option is set, which allows local users to read or write to arbitrary kernel memory locations or cause a denial of service (use-after-free) by leveraging access to a /dev/sg device, related to block/bsg.c and drivers/scsi/sg.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-9576.
Затронутые продукты
SUSE Linux Enterprise Live Patching 12:kgraft-patch-4_4_21-90-default-2-2.1
Ссылки
- CVE-2016-10088
- SUSE Bug 1013604
- SUSE Bug 1014271
- SUSE Bug 1017710
- SUSE Bug 1019079
- SUSE Bug 1115893