SuSE: 2012:0789-1: important: Linux kernel
Summary
The SUSE Linux Enterprise 11 SP2 kernel was updated to 3.0.34, fixing a lot of bugs and security issues. The update from Linux kernel 3.0.31 to 3.0.34 also fixes various bugs not listed here. The following security issues have been fixed: * CVE-2012-2136: Local attackers could trigger an overflow in sock_alloc_send_pksb(), potentially crashing the machine or escalate privileges. * CVE-2012-2390: A memory leak in transparent hugepages on mmap failure could be used by local attacker to run the machine out of memory (local denial of service). * CVE-2012-2119: A malicious guest driver could overflow the host stack by passing a long descriptor, so potentially crashing the host system or escalating privileges on the host. * CVE-2012-2375: Malicious NFS server could crash the clients when more than 2 GETATTR bitmap words are returned in response to the FATTR4_ACL attribute requests, only incompletely fixed ...
Read the Full AdvisoryReferences
#556135 #735909 #743579 #744404 #747404 #754690
#756050 #757315 #758243 #759336 #759545 #759805
#760237 #760806 #761087 #761245 #762991 #762992
#763267 #763307 #763485 #763717 #764091 #764150
#764209 #764500 #764900 #765102 #765253 #765320
#765524
Cross- CVE-2012-2119 CVE-2012-2136 CVE-2012-2373
CVE-2012-2375 CVE-2012-2390
Affected Products:
SUSE Linux Enterprise Server 11 SP2 for VMware
SUSE Linux Enterprise Server 11 SP2
SUSE Linux Enterprise High Availability Extension 11 SP2
SUSE Linux Enterprise Desktop 11 SP2
SLE 11 SERVER Unsupported Extras
https://www.suse.com/security/cve/CVE-2012-2119.html
https://www.suse.com/security/cve/CVE-2012-2136.html
https://www.suse.com/security/cve/CVE-2012-2373.html
https://www.suse.com/security/cve/CVE-2012-2375.html
...
Read the Full Advisory