VYPR

rpm package

suse/kernel-docs&distro=SUSE Linux Enterprise Software Development Kit 12 SP2

pkg:rpm/suse/kernel-docs&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2

Vulnerabilities (124)

  • CVE-2016-7117CriOct 10, 2016
    affected < 4.4.49-92.11.3fixed 4.4.49-92.11.3

    Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandled during error processing.

  • CVE-2016-2117HigMay 2, 2016
    affected < 4.4.59-92.17.8fixed 4.4.59-92.17.8

    The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c in the Linux kernel through 4.5.2 incorrectly enables scatter/gather I/O, which allows remote attackers to obtain sensitive information from kernel memory by reading packet data.

  • CVE-2015-1350MedMay 2, 2016
    affected < 4.4.38-93.3fixed 4.4.38-93.3

    The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability stripping) via a failed invocation of a system

  • CVE-2015-8709HigFeb 8, 2016
    affected < 4.4.49-92.11.3fixed 4.4.49-92.11.3

    kernel/ptrace.c in the Linux kernel through 4.4.1 mishandles uid and gid mappings, which allows local users to gain privileges by establishing a user namespace, waiting for a root process to enter that namespace with an unsafe uid or gid, and then using the ptrace system call. N

Page 7 of 7