rpm package
suse/cluster-network&distro=SUSE Linux Enterprise High Availability Extension 11 SP4
pkg:rpm/suse/cluster-network&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2011%20SP4
Vulnerabilities (30)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2017-9075 | Hig | 7.8 | < 1.4-2.32.2.14 | 1.4-2.32.2.14 | May 19, 2017 | The sctp_v6_create_accept_sk function in net/sctp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890. | |
| CVE-2017-9074 | Hig | 7.8 | < 1.4-2.32.2.14 | 1.4-2.32.2.14 | May 19, 2017 | The IPv6 fragmentation implementation in the Linux kernel through 4.11.1 does not consider that the nexthdr field may be associated with an invalid option, which allows local users to cause a denial of service (out-of-bounds read and BUG) or possibly have unspecified other impact | |
| CVE-2017-7487 | Hig | 7.8 | < 1.4-2.32.2.14 | 1.4-2.32.2.14 | May 14, 2017 | The ipxitf_ioctl function in net/ipx/af_ipx.c in the Linux kernel through 4.11.1 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a failed SIOCGIFADDR ioctl call for an IPX interface. | |
| CVE-2017-8925 | Med | 5.5 | < 1.4-2.32.2.14 | 1.4-2.32.2.14 | May 12, 2017 | The omninet_open function in drivers/usb/serial/omninet.c in the Linux kernel before 4.10.4 allows local users to cause a denial of service (tty exhaustion) by leveraging reference count mishandling. | |
| CVE-2017-8924 | Med | 4.6 | < 1.4-2.32.2.14 | 1.4-2.32.2.14 | May 12, 2017 | The edge_bulk_in_callback function in drivers/usb/serial/io_ti.c in the Linux kernel before 4.10.4 allows local users to obtain sensitive information (in the dmesg ringbuffer and syslog) from uninitialized kernel memory by using a crafted USB device (posing as an io_ti USB serial | |
| CVE-2016-10277 | Hig | 7.8 | < 1.4-2.32.2.14 | 1.4-2.32.2.14 | May 12, 2017 | An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute arbitrary code within the context of the bootloader. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may r | |
| CVE-2017-8890 | Hig | 7.8 | < 1.4-2.32.2.14 | 1.4-2.32.2.14 | May 10, 2017 | The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel through 4.10.15 allows attackers to cause a denial of service (double free) or possibly have unspecified other impact by leveraging use of the accept system call. | |
| CVE-2014-9922 | Hig | 7.8 | < 1.4-2.32.2.14 | 1.4-2.32.2.14 | Apr 4, 2017 | The eCryptfs subsystem in the Linux kernel before 3.18 allows local users to gain privileges via a large filesystem stack that includes an overlayfs layer, related to fs/ecryptfs/main.c and fs/overlayfs/super.c. | |
| CVE-2017-2647 | Hig | 7.8 | < 1.4-2.32.2.14 | 1.4-2.32.2.14 | Mar 31, 2017 | The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving a NULL value for a certain match field, related to the keyring_search_iterator function in keyri | |
| CVE-2017-6951 | Med | 5.5 | < 1.4-2.32.2.14 | 1.4-2.32.2.14 | Mar 16, 2017 | The keyring_search_aux function in security/keys/keyring.c in the Linux kernel through 3.14.79 allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a request_key system call for the "dead" type. |
- affected < 1.4-2.32.2.14fixed 1.4-2.32.2.14
The sctp_v6_create_accept_sk function in net/sctp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890.
- affected < 1.4-2.32.2.14fixed 1.4-2.32.2.14
The IPv6 fragmentation implementation in the Linux kernel through 4.11.1 does not consider that the nexthdr field may be associated with an invalid option, which allows local users to cause a denial of service (out-of-bounds read and BUG) or possibly have unspecified other impact
- affected < 1.4-2.32.2.14fixed 1.4-2.32.2.14
The ipxitf_ioctl function in net/ipx/af_ipx.c in the Linux kernel through 4.11.1 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a failed SIOCGIFADDR ioctl call for an IPX interface.
- affected < 1.4-2.32.2.14fixed 1.4-2.32.2.14
The omninet_open function in drivers/usb/serial/omninet.c in the Linux kernel before 4.10.4 allows local users to cause a denial of service (tty exhaustion) by leveraging reference count mishandling.
- affected < 1.4-2.32.2.14fixed 1.4-2.32.2.14
The edge_bulk_in_callback function in drivers/usb/serial/io_ti.c in the Linux kernel before 4.10.4 allows local users to obtain sensitive information (in the dmesg ringbuffer and syslog) from uninitialized kernel memory by using a crafted USB device (posing as an io_ti USB serial
- affected < 1.4-2.32.2.14fixed 1.4-2.32.2.14
An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute arbitrary code within the context of the bootloader. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may r
- affected < 1.4-2.32.2.14fixed 1.4-2.32.2.14
The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel through 4.10.15 allows attackers to cause a denial of service (double free) or possibly have unspecified other impact by leveraging use of the accept system call.
- affected < 1.4-2.32.2.14fixed 1.4-2.32.2.14
The eCryptfs subsystem in the Linux kernel before 3.18 allows local users to gain privileges via a large filesystem stack that includes an overlayfs layer, related to fs/ecryptfs/main.c and fs/overlayfs/super.c.
- affected < 1.4-2.32.2.14fixed 1.4-2.32.2.14
The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving a NULL value for a certain match field, related to the keyring_search_iterator function in keyri
- affected < 1.4-2.32.2.14fixed 1.4-2.32.2.14
The keyring_search_aux function in security/keys/keyring.c in the Linux kernel through 3.14.79 allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a request_key system call for the "dead" type.
Page 2 of 2