SUSE Security Update: Security update for the Linux Kernel
______________________________________________________________________________

Announcement ID:    SUSE-SU-2017:2131-1
Rating:             important
References:         #1038078 #1043652 #1048914 #1052311 #1052365 
                    
Cross-References:   CVE-2017-1000111 CVE-2017-1000112
Affected Products:
                    SUSE Linux Enterprise Workstation Extension 12-SP2
                    SUSE Linux Enterprise Software Development Kit 12-SP2
                    SUSE Linux Enterprise Server for Raspberry Pi 12-SP2
                    SUSE Linux Enterprise Server 12-SP2
                    SUSE Linux Enterprise Live Patching 12
                    SUSE Linux Enterprise High Availability 12-SP2
                    SUSE Linux Enterprise Desktop 12-SP2
                    SUSE Container as a Service Platform ALL
                    OpenStack Cloud Magnum Orchestration 7
______________________________________________________________________________

   An update that solves two vulnerabilities and has three
   fixes is now available.

Description:


   The SUSE Linux Enterprise 12 SP2 kernel was updated to 4.4.74 to receive
   various security and bugfixes.

   The following security bugs were fixed:

   - CVE-2017-1000111: fix race condition in net-packet code that could be
     exploited to cause out-of-bounds memory access (bsc#1052365).
   - CVE-2017-1000112: fix race condition in net-packet code that could have
     been exploited by unprivileged users to gain root access. (bsc#1052311).

   The following non-security bugs were fixed:

   - powerpc/numa: fix regression that could cause kernel panics during
     installation (bsc#1048914).
   - bcache: force trigger gc (bsc#1038078).
   - bcache: only recovery I/O error for writethrough mode (bsc#1043652).


Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Workstation Extension 12-SP2:

      zypper in -t patch SUSE-SLE-WE-12-SP2-2017-1319=1

   - SUSE Linux Enterprise Software Development Kit 12-SP2:

      zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-1319=1

   - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2:

      zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1319=1

   - SUSE Linux Enterprise Server 12-SP2:

      zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1319=1

   - SUSE Linux Enterprise Live Patching 12:

      zypper in -t patch SUSE-SLE-Live-Patching-12-2017-1319=1

   - SUSE Linux Enterprise High Availability 12-SP2:

      zypper in -t patch SUSE-SLE-HA-12-SP2-2017-1319=1

   - SUSE Linux Enterprise Desktop 12-SP2:

      zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1319=1

   - SUSE Container as a Service Platform ALL:

      zypper in -t patch SUSE-CAASP-ALL-2017-1319=1

   - OpenStack Cloud Magnum Orchestration 7:

      zypper in -t patch SUSE-OpenStack-Cloud-Magnum-Orchestration-7-2017-1319=1

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Workstation Extension 12-SP2 (x86_64):

      kernel-default-debuginfo-4.4.74-92.35.1
      kernel-default-debugsource-4.4.74-92.35.1
      kernel-default-extra-4.4.74-92.35.1
      kernel-default-extra-debuginfo-4.4.74-92.35.1

   - SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 ppc64le s390x x86_64):

      kernel-obs-build-4.4.74-92.35.1
      kernel-obs-build-debugsource-4.4.74-92.35.1

   - SUSE Linux Enterprise Software Development Kit 12-SP2 (noarch):

      kernel-docs-4.4.74-92.35.3

   - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64):

      kernel-default-4.4.74-92.35.1
      kernel-default-base-4.4.74-92.35.1
      kernel-default-base-debuginfo-4.4.74-92.35.1
      kernel-default-debuginfo-4.4.74-92.35.1
      kernel-default-debugsource-4.4.74-92.35.1
      kernel-default-devel-4.4.74-92.35.1
      kernel-syms-4.4.74-92.35.1

   - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (noarch):

      kernel-devel-4.4.74-92.35.1
      kernel-macros-4.4.74-92.35.1
      kernel-source-4.4.74-92.35.1

   - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le s390x x86_64):

      kernel-default-4.4.74-92.35.1
      kernel-default-base-4.4.74-92.35.1
      kernel-default-base-debuginfo-4.4.74-92.35.1
      kernel-default-debuginfo-4.4.74-92.35.1
      kernel-default-debugsource-4.4.74-92.35.1
      kernel-default-devel-4.4.74-92.35.1
      kernel-syms-4.4.74-92.35.1

   - SUSE Linux Enterprise Server 12-SP2 (noarch):

      kernel-devel-4.4.74-92.35.1
      kernel-macros-4.4.74-92.35.1
      kernel-source-4.4.74-92.35.1

   - SUSE Linux Enterprise Server 12-SP2 (s390x):

      kernel-default-man-4.4.74-92.35.1

   - SUSE Linux Enterprise Live Patching 12 (x86_64):

      kgraft-patch-4_4_74-92_35-default-1-2.1

   - SUSE Linux Enterprise High Availability 12-SP2 (ppc64le s390x x86_64):

      cluster-md-kmp-default-4.4.74-92.35.1
      cluster-md-kmp-default-debuginfo-4.4.74-92.35.1
      cluster-network-kmp-default-4.4.74-92.35.1
      cluster-network-kmp-default-debuginfo-4.4.74-92.35.1
      dlm-kmp-default-4.4.74-92.35.1
      dlm-kmp-default-debuginfo-4.4.74-92.35.1
      gfs2-kmp-default-4.4.74-92.35.1
      gfs2-kmp-default-debuginfo-4.4.74-92.35.1
      kernel-default-debuginfo-4.4.74-92.35.1
      kernel-default-debugsource-4.4.74-92.35.1
      ocfs2-kmp-default-4.4.74-92.35.1
      ocfs2-kmp-default-debuginfo-4.4.74-92.35.1

   - SUSE Linux Enterprise Desktop 12-SP2 (noarch):

      kernel-devel-4.4.74-92.35.1
      kernel-macros-4.4.74-92.35.1
      kernel-source-4.4.74-92.35.1

   - SUSE Linux Enterprise Desktop 12-SP2 (x86_64):

      kernel-default-4.4.74-92.35.1
      kernel-default-debuginfo-4.4.74-92.35.1
      kernel-default-debugsource-4.4.74-92.35.1
      kernel-default-devel-4.4.74-92.35.1
      kernel-default-extra-4.4.74-92.35.1
      kernel-default-extra-debuginfo-4.4.74-92.35.1
      kernel-syms-4.4.74-92.35.1

   - SUSE Container as a Service Platform ALL (x86_64):

      kernel-default-4.4.74-92.35.1
      kernel-default-debuginfo-4.4.74-92.35.1
      kernel-default-debugsource-4.4.74-92.35.1

   - OpenStack Cloud Magnum Orchestration 7 (x86_64):

      kernel-default-4.4.74-92.35.1
      kernel-default-debuginfo-4.4.74-92.35.1
      kernel-default-debugsource-4.4.74-92.35.1


References:

   https://www.suse.com/security/cve/CVE-2017-1000111.html
   https://www.suse.com/security/cve/CVE-2017-1000112.html
   https://bugzilla.suse.com/1038078
   https://bugzilla.suse.com/1043652
   https://bugzilla.suse.com/1048914
   https://bugzilla.suse.com/1052311
   https://bugzilla.suse.com/1052365

SuSE: 2017:2131-1: important: the Linux Kernel

August 11, 2017
An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three fixes is now...

Summary

The SUSE Linux Enterprise 12 SP2 kernel was updated to 4.4.74 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2017-1000111: fix race condition in net-packet code that could be exploited to cause out-of-bounds memory access (bsc#1052365). - CVE-2017-1000112: fix race condition in net-packet code that could have been exploited by unprivileged users to gain root access. (bsc#1052311). The following non-security bugs were fixed: - powerpc/numa: fix regression that could cause kernel panics during installation (bsc#1048914). - bcache: force trigger gc (bsc#1038078). - bcache: only recovery I/O error for writethrough mode (bsc#1043652). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP2: zypper in -t patch SUSE-SLE-WE-12-SP2-2017-1319=1 ...

Read the Full Advisory

References

#1038078 #1043652 #1048914 #1052311 #1052365

Cross- CVE-2017-1000111 CVE-2017-1000112

Affected Products:

SUSE Linux Enterprise Workstation Extension 12-SP2

SUSE Linux Enterprise Software Development Kit 12-SP2

SUSE Linux Enterprise Server for Raspberry Pi 12-SP2

SUSE Linux Enterprise Server 12-SP2

SUSE Linux Enterprise Live Patching 12

SUSE Linux Enterprise High Availability 12-SP2

SUSE Linux Enterprise Desktop 12-SP2

SUSE Container as a Service Platform ALL

OpenStack Cloud Magnum Orchestration 7

https://www.suse.com/security/cve/CVE-2017-1000111.html

https://www.suse.com/security/cve/CVE-2017-1000112.html

https://bugzilla.suse.com/1038078

https://bugzilla.suse.com/1043652

https://bugzilla.suse.com/1048914

https://bugzilla.suse.com/1052311

https://bugzilla.suse.com/1052365

Severity
Announcement ID: SUSE-SU-2017:2131-1
Rating: important

Related News