Oval Definition:oval:org.opensuse.security:def:98255
Revision Date:2019-12-10Version:1
Title:Security update for the Linux Kernel (Live Patch 2 for SLE 15 SP1) (Important)
Description:

This update for the Linux Kernel 4.12.14-197_7 fixes several issues.

The following security issues were fixed:

- CVE-2019-13272: Fixed a privilege escalation from user to root due to improper handling of credentials by leveraging certain scenarios with a parent-child process relationship (bsc#1156321). - CVE-2019-15239: Fixed a vulnerability where a local attacker could have triggered multiple use-after-free conditions resulted in privilege escalation (bsc#1156317). - CVE-2019-10220: Fixed an issue where samba servers could inject relative paths in directory entry lists (bsc#1153108).

The following bugs were fixed:

- Fixed boot up hang revealed by int3 self test (bsc#1157770).
Family:unixClass:patch
Status:Reference(s):1153108
1156317
1156321
1157770
CVE-2019-10220
CVE-2019-13272
CVE-2019-15239
SUSE-SU-2019:3230-1
Platform(s):SUSE Linux Enterprise High Performance Computing 15 SP1
SUSE Linux Enterprise Module for Live Patching 15 SP1
SUSE Linux Enterprise Server 15 SP1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Live Patching 15 SP1 is installed
  • AND kernel-livepatch-4_12_14-197_7-default-6-2.1 is installed
  • BACK