Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2017:0873-1

Опубликовано: 30 мар. 2017
Источник: suse-cvrf

Описание

Security update for Linux Kernel Live Patch 13 for SLE 12

This update for the Linux Kernel 3.12.55-52_45 fixes one issue.

The following security bugs were fixed:

  • CVE-2017-7184: The XFRM processsing in the Linux kernel 16.10 allowed local users to obtain root privileges or cause a denial of service (heap-based out-of-bounds access) via an integer overflow, as demonstrated during a Pwn2Own competition at CanSecWest 2017 (bsc#1030575).

Список пакетов

SUSE Linux Enterprise Server 12-LTSS
kgraft-patch-3_12_55-52_45-default-8-2.1
kgraft-patch-3_12_55-52_45-xen-8-2.1
SUSE Linux Enterprise Server for SAP Applications 12
kgraft-patch-3_12_55-52_45-default-8-2.1
kgraft-patch-3_12_55-52_45-xen-8-2.1

Описание

The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does not validate certain size data after an XFRM_MSG_NEWAE update, which allows local users to obtain root privileges or cause a denial of service (heap-based out-of-bounds access) by leveraging the CAP_NET_ADMIN capability, as demonstrated during a Pwn2Own competition at CanSecWest 2017 for the Ubuntu 16.10 linux-image-* package 4.8.0.41.52.


Затронутые продукты
SUSE Linux Enterprise Server 12-LTSS:kgraft-patch-3_12_55-52_45-default-8-2.1
SUSE Linux Enterprise Server 12-LTSS:kgraft-patch-3_12_55-52_45-xen-8-2.1
SUSE Linux Enterprise Server for SAP Applications 12:kgraft-patch-3_12_55-52_45-default-8-2.1
SUSE Linux Enterprise Server for SAP Applications 12:kgraft-patch-3_12_55-52_45-xen-8-2.1

Ссылки