Описание
Security update for the Linux Kernel
The SUSE Linux Enterprise 12 kernel was updated to fix the following security bugs:
- CVE-2017-7184: The Linux kernel allowed local users to obtain root privileges or cause a denial of service (heap-based out-of-bounds access) via unspecified vectors, as demonstrated during a Pwn2Own competition at CanSecWest 2017 (bnc#1030573, bnc#1028372).
- CVE-2017-2636: Race condition in drivers/tty/n_hdlc.c in the Linux kernel allowed local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline (bnc#1027565).
Список пакетов
SUSE Linux Enterprise Module for Public Cloud 12
SUSE Linux Enterprise Server 12-LTSS
SUSE Linux Enterprise Server for SAP Applications 12
Ссылки
- Link for SUSE-SU-2017:0866-1
- E-Mail link for SUSE-SU-2017:0866-1
- SUSE Security Ratings
- SUSE Bug 1027565
- SUSE Bug 1028372
- SUSE Bug 1030573
- SUSE CVE CVE-2017-2636 page
- SUSE CVE CVE-2017-7184 page
Описание
Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline.
Затронутые продукты
Ссылки
- CVE-2017-2636
- SUSE Bug 1027565
- SUSE Bug 1027575
- SUSE Bug 1028372
- SUSE Bug 1115893
Описание
The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does not validate certain size data after an XFRM_MSG_NEWAE update, which allows local users to obtain root privileges or cause a denial of service (heap-based out-of-bounds access) by leveraging the CAP_NET_ADMIN capability, as demonstrated during a Pwn2Own competition at CanSecWest 2017 for the Ubuntu 16.10 linux-image-* package 4.8.0.41.52.
Затронутые продукты
Ссылки
- CVE-2017-7184
- SUSE Bug 1030573
- SUSE Bug 1030575
- SUSE Bug 1115893