{"affected":[{"ecosystem_specific":{"binaries":[{"kernel-ec2":"3.12.61-52.66.1","kernel-ec2-devel":"3.12.61-52.66.1","kernel-ec2-extra":"3.12.61-52.66.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Public Cloud 12","name":"kernel-ec2","purl":"pkg:rpm/suse/kernel-ec2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"3.12.61-52.66.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"kernel-default":"3.12.61-52.66.1","kernel-default-base":"3.12.61-52.66.1","kernel-default-devel":"3.12.61-52.66.1","kernel-devel":"3.12.61-52.66.1","kernel-macros":"3.12.61-52.66.1","kernel-source":"3.12.61-52.66.1","kernel-syms":"3.12.61-52.66.1","kernel-xen":"3.12.61-52.66.1","kernel-xen-base":"3.12.61-52.66.1","kernel-xen-devel":"3.12.61-52.66.1","kgraft-patch-3_12_61-52_66-default":"1-2.1","kgraft-patch-3_12_61-52_66-xen":"1-2.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12","name":"kernel-default","purl":"pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"3.12.61-52.66.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"kernel-default":"3.12.61-52.66.1","kernel-default-base":"3.12.61-52.66.1","kernel-default-devel":"3.12.61-52.66.1","kernel-devel":"3.12.61-52.66.1","kernel-macros":"3.12.61-52.66.1","kernel-source":"3.12.61-52.66.1","kernel-syms":"3.12.61-52.66.1","kernel-xen":"3.12.61-52.66.1","kernel-xen-base":"3.12.61-52.66.1","kernel-xen-devel":"3.12.61-52.66.1","kgraft-patch-3_12_61-52_66-default":"1-2.1","kgraft-patch-3_12_61-52_66-xen":"1-2.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12","name":"kernel-source","purl":"pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"3.12.61-52.66.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"kernel-default":"3.12.61-52.66.1","kernel-default-base":"3.12.61-52.66.1","kernel-default-devel":"3.12.61-52.66.1","kernel-devel":"3.12.61-52.66.1","kernel-macros":"3.12.61-52.66.1","kernel-source":"3.12.61-52.66.1","kernel-syms":"3.12.61-52.66.1","kernel-xen":"3.12.61-52.66.1","kernel-xen-base":"3.12.61-52.66.1","kernel-xen-devel":"3.12.61-52.66.1","kgraft-patch-3_12_61-52_66-default":"1-2.1","kgraft-patch-3_12_61-52_66-xen":"1-2.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12","name":"kernel-syms","purl":"pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"3.12.61-52.66.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"kernel-default":"3.12.61-52.66.1","kernel-default-base":"3.12.61-52.66.1","kernel-default-devel":"3.12.61-52.66.1","kernel-devel":"3.12.61-52.66.1","kernel-macros":"3.12.61-52.66.1","kernel-source":"3.12.61-52.66.1","kernel-syms":"3.12.61-52.66.1","kernel-xen":"3.12.61-52.66.1","kernel-xen-base":"3.12.61-52.66.1","kernel-xen-devel":"3.12.61-52.66.1","kgraft-patch-3_12_61-52_66-default":"1-2.1","kgraft-patch-3_12_61-52_66-xen":"1-2.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12","name":"kernel-xen","purl":"pkg:rpm/suse/kernel-xen&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"3.12.61-52.66.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"kernel-default":"3.12.61-52.66.1","kernel-default-base":"3.12.61-52.66.1","kernel-default-devel":"3.12.61-52.66.1","kernel-devel":"3.12.61-52.66.1","kernel-macros":"3.12.61-52.66.1","kernel-source":"3.12.61-52.66.1","kernel-syms":"3.12.61-52.66.1","kernel-xen":"3.12.61-52.66.1","kernel-xen-base":"3.12.61-52.66.1","kernel-xen-devel":"3.12.61-52.66.1","kgraft-patch-3_12_61-52_66-default":"1-2.1","kgraft-patch-3_12_61-52_66-xen":"1-2.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12","name":"kgraft-patch-SLE12_Update_19","purl":"pkg:rpm/suse/kgraft-patch-SLE12_Update_19&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1-2.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"kernel-default":"3.12.61-52.66.1","kernel-default-base":"3.12.61-52.66.1","kernel-default-devel":"3.12.61-52.66.1","kernel-default-man":"3.12.61-52.66.1","kernel-devel":"3.12.61-52.66.1","kernel-macros":"3.12.61-52.66.1","kernel-source":"3.12.61-52.66.1","kernel-syms":"3.12.61-52.66.1","kernel-xen":"3.12.61-52.66.1","kernel-xen-base":"3.12.61-52.66.1","kernel-xen-devel":"3.12.61-52.66.1","kgraft-patch-3_12_61-52_66-default":"1-2.1","kgraft-patch-3_12_61-52_66-xen":"1-2.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12-LTSS","name":"kernel-default","purl":"pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"3.12.61-52.66.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"kernel-default":"3.12.61-52.66.1","kernel-default-base":"3.12.61-52.66.1","kernel-default-devel":"3.12.61-52.66.1","kernel-default-man":"3.12.61-52.66.1","kernel-devel":"3.12.61-52.66.1","kernel-macros":"3.12.61-52.66.1","kernel-source":"3.12.61-52.66.1","kernel-syms":"3.12.61-52.66.1","kernel-xen":"3.12.61-52.66.1","kernel-xen-base":"3.12.61-52.66.1","kernel-xen-devel":"3.12.61-52.66.1","kgraft-patch-3_12_61-52_66-default":"1-2.1","kgraft-patch-3_12_61-52_66-xen":"1-2.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12-LTSS","name":"kernel-source","purl":"pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"3.12.61-52.66.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"kernel-default":"3.12.61-52.66.1","kernel-default-base":"3.12.61-52.66.1","kernel-default-devel":"3.12.61-52.66.1","kernel-default-man":"3.12.61-52.66.1","kernel-devel":"3.12.61-52.66.1","kernel-macros":"3.12.61-52.66.1","kernel-source":"3.12.61-52.66.1","kernel-syms":"3.12.61-52.66.1","kernel-xen":"3.12.61-52.66.1","kernel-xen-base":"3.12.61-52.66.1","kernel-xen-devel":"3.12.61-52.66.1","kgraft-patch-3_12_61-52_66-default":"1-2.1","kgraft-patch-3_12_61-52_66-xen":"1-2.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12-LTSS","name":"kernel-syms","purl":"pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"3.12.61-52.66.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"kernel-default":"3.12.61-52.66.1","kernel-default-base":"3.12.61-52.66.1","kernel-default-devel":"3.12.61-52.66.1","kernel-default-man":"3.12.61-52.66.1","kernel-devel":"3.12.61-52.66.1","kernel-macros":"3.12.61-52.66.1","kernel-source":"3.12.61-52.66.1","kernel-syms":"3.12.61-52.66.1","kernel-xen":"3.12.61-52.66.1","kernel-xen-base":"3.12.61-52.66.1","kernel-xen-devel":"3.12.61-52.66.1","kgraft-patch-3_12_61-52_66-default":"1-2.1","kgraft-patch-3_12_61-52_66-xen":"1-2.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12-LTSS","name":"kernel-xen","purl":"pkg:rpm/suse/kernel-xen&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"3.12.61-52.66.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"kernel-default":"3.12.61-52.66.1","kernel-default-base":"3.12.61-52.66.1","kernel-default-devel":"3.12.61-52.66.1","kernel-default-man":"3.12.61-52.66.1","kernel-devel":"3.12.61-52.66.1","kernel-macros":"3.12.61-52.66.1","kernel-source":"3.12.61-52.66.1","kernel-syms":"3.12.61-52.66.1","kernel-xen":"3.12.61-52.66.1","kernel-xen-base":"3.12.61-52.66.1","kernel-xen-devel":"3.12.61-52.66.1","kgraft-patch-3_12_61-52_66-default":"1-2.1","kgraft-patch-3_12_61-52_66-xen":"1-2.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12-LTSS","name":"kgraft-patch-SLE12_Update_19","purl":"pkg:rpm/suse/kgraft-patch-SLE12_Update_19&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1-2.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"\n\nThe SUSE Linux Enterprise 12 GA LTSS kernel was updated to 3.12.61 to receive various security and bugfixes.\n\nThe following feature was implemented:\n\n- The ext2 filesystem got reenabled and supported to allow support for 'XIP' (Execute In Place) (FATE#320805).\n\n\nThe following security bugs were fixed:\n\n- CVE-2017-5551: The tmpfs filesystem implementation in the Linux kernel preserved the setgid bit during a setxattr call, which allowed local users to gain group privileges by leveraging the existence of a setgid program with restrictions on execute permissions (bsc#1021258).\n- CVE-2016-7097: The filesystem implementation in the Linux kernel preserved the setgid bit during a setxattr call, which allowed local users to gain group privileges by leveraging the existence of a setgid program with restrictions on execute permissions (bnc#995968).\n- CVE-2017-2583: A Linux kernel built with the Kernel-based Virtual Machine (CONFIG_KVM) support was vulnerable to an incorrect segment selector(SS) value error. A user/process inside guest could have used this flaw to crash the guest resulting in DoS or potentially escalate their privileges inside guest. (bsc#1020602).\n- CVE-2017-2584: arch/x86/kvm/emulate.c in the Linux kernel allowed local users to obtain sensitive information from kernel memory or cause a denial of service (use-after-free) via a crafted application that leverages instruction emulation for fxrstor, fxsave, sgdt, and sidt (bnc#1019851).\n- CVE-2016-10088: The sg implementation in the Linux kernel did not properly restrict write operations in situations where the KERNEL_DS option is set, which allowed local users to read or write to arbitrary kernel memory locations or cause a denial of service (use-after-free) by leveraging access to a /dev/sg device, related to block/bsg.c and drivers/scsi/sg.c.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-9576 (bnc#1017710).\n- CVE-2016-8645: The TCP stack in the Linux kernel mishandled skb truncation, which allowed local users to cause a denial of service (system crash) via a crafted application that made sendto system calls, related to net/ipv4/tcp_ipv4.c and net/ipv6/tcp_ipv6.c (bnc#1009969).\n- CVE-2016-8399: An elevation of privilege vulnerability in the kernel networking subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process and current compiler optimizations restrict access to the vulnerable code. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31349935 (bnc#1014746).\n- CVE-2016-9806: Race condition in the netlink_dump function in net/netlink/af_netlink.c in the Linux kernel allowed local users to cause a denial of service (double free) or possibly have unspecified other impact via a crafted application that made sendmsg system calls, leading to a free operation associated with a new dump that started earlier than anticipated (bnc#1013540).\n- CVE-2016-9756: arch/x86/kvm/emulate.c in the Linux kernel did not properly initialize Code Segment (CS) in certain error cases, which allowed local users to obtain sensitive information from kernel stack memory via a crafted application (bnc#1013038).\n- CVE-2016-9793: The sock_setsockopt function in net/core/sock.c in the Linux kernel mishandled negative values of sk_sndbuf and sk_rcvbuf, which allowed local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact by leveraging the CAP_NET_ADMIN capability for a crafted setsockopt system call with the (1) SO_SNDBUFFORCE or (2) SO_RCVBUFFORCE option (bnc#1013531).\n- CVE-2016-7910: Use-after-free vulnerability in the disk_seqf_stop function in block/genhd.c in the Linux kernel allowed local users to gain privileges by leveraging the execution of a certain stop operation even if the corresponding start operation had failed (bnc#1010716).\n- CVE-2015-8962: Double free vulnerability in the sg_common_write function in drivers/scsi/sg.c in the Linux kernel allowed local users to gain privileges or cause a denial of service (memory corruption and system crash) by detaching a device during an SG_IO ioctl call (bnc#1010501).\n- CVE-2016-7913: The xc2028_set_config function in drivers/media/tuners/tuner-xc2028.c in the Linux kernel allowed local users to gain privileges or cause a denial of service (use-after-free) via vectors involving omission of the firmware name from a certain data structure (bnc#1010478).\n- CVE-2016-7911: Race condition in the get_task_ioprio function in block/ioprio.c in the Linux kernel allowed local users to gain privileges or cause a denial of service (use-after-free) via a crafted ioprio_get system call (bnc#1010711).\n- CVE-2015-8964: The tty_set_termios_ldisc function in drivers/tty/tty_ldisc.c in the Linux kernel allowed local users to obtain sensitive information from kernel memory by reading a tty data structure (bnc#1010507).\n- CVE-2015-8963: Race condition in kernel/events/core.c in the Linux kernel allowed local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect handling of an swevent data structure during a CPU unplug operation (bnc#1010502).\n- CVE-2016-7914: The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel did not check whether a slot is a leaf, which allowed local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and out-of-bounds read) via an application that uses associative-array data structures, as demonstrated by the keyutils test suite (bnc#1010475).\n- CVE-2016-8633: drivers/firewire/net.c in the Linux kernel allowed remote attackers to execute arbitrary code via crafted fragmented packets (bnc#1008833).\n- CVE-2016-9083: drivers/vfio/pci/vfio_pci.c in the Linux kernel allowed local users to bypass integer overflow checks, and cause a denial of service (memory corruption) or have unspecified other impact, by leveraging access to a vfio PCI device file for a VFIO_DEVICE_SET_IRQS ioctl call, aka a 'state machine confusion bug (bnc#1007197).\n- CVE-2016-9084: drivers/vfio/pci/vfio_pci_intrs.c in the Linux kernel misused the kzalloc function, which allowed local users to cause a denial of service (integer overflow) or have unspecified other impact by leveraging access to a vfio PCI device file (bnc#1007197).\n- CVE-2016-7042: The proc_keys_show function in security/keys/proc.c in the Linux kernel uses an incorrect buffer size for certain timeout data, which allowed local users to cause a denial of service (stack memory corruption and panic) by reading the /proc/keys file (bnc#1004517).\n- CVE-2015-8956: The rfcomm_sock_bind function in net/bluetooth/rfcomm/sock.c in the Linux kernel allowed local users to obtain sensitive information or cause a denial of service (NULL pointer dereference) via vectors involving a bind system call on a Bluetooth RFCOMM socket (bnc#1003925).\n- CVE-2016-8658: Stack-based buffer overflow in the brcmf_cfg80211_start_ap function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux kernel allowed local users to cause a denial of service (system crash) or possibly have unspecified other impact via a long SSID Information Element in a command to a Netlink socket (bnc#1004462).\n- CVE-2016-7425: The arcmsr_iop_message_xfer function in drivers/scsi/arcmsr/arcmsr_hba.c in the Linux kernel did not restrict a certain length field, which allowed local users to gain privileges or cause a denial of service (heap-based buffer overflow) via an ARCMSR_MESSAGE_WRITE_WQBUFFER control code (bnc#999932).\n- CVE-2016-6327: drivers/infiniband/ulp/srpt/ib_srpt.c in the Linux kernel allowed local users to cause a denial of service (NULL pointer dereference and system crash) by using an ABORT_TASK command to abort a device write operation (bnc#994748).\n- CVE-2016-6828: The tcp_check_send_head function in include/net/tcp.h in the Linux kernel did not properly maintain certain SACK state after a failed data copy, which allowed local users to cause a denial of service (tcp_xmit_retransmit_queue use-after-free and system crash) via a crafted SACK option (bnc#994296).\n- CVE-2016-5696: net/ipv4/tcp_input.c in the Linux kernel did not properly determine the rate of challenge ACK segments, which made it easier for remote attackers to hijack TCP sessions via a blind in-window attack (bnc#989152).\n- CVE-2016-6130: Race condition in the sclp_ctl_ioctl_sccb function in drivers/s390/char/sclp_ctl.c in the Linux kernel allowed local users to obtain sensitive information from kernel memory by changing a certain length value, aka a 'double fetch' vulnerability (bnc#987542).\n- CVE-2016-6480: Race condition in the ioctl_send_fib function in drivers/scsi/aacraid/commctrl.c in the Linux kernel allowed local users to cause a denial of service (out-of-bounds access or system crash) by changing a certain size value, aka a 'double fetch' vulnerability (bnc#991608).\n- CVE-2016-4998: The IPT_SO_SET_REPLACE setsockopt implementation in the netfilter subsystem in the Linux kernel allowed local users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from kernel heap memory by leveraging in-container root access to provide a crafted offset value that leads to crossing a ruleset blob boundary (bnc#986362 bnc#986365).\n- CVE-2016-5828: The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel on powerpc platforms mishandled transactional state, which allowed local users to cause a denial of service (invalid process state or TM Bad Thing exception, and system crash) or possibly have unspecified other impact by starting and suspending a transaction before an exec system call (bnc#986569).\n- CVE-2014-9904: The snd_compress_check_input function in sound/core/compress_offload.c in the ALSA subsystem in the Linux kernel did not properly check for an integer overflow, which allowed local users to cause a denial of service (insufficient memory allocation) or possibly have unspecified other impact via a crafted SNDRV_COMPRESS_SET_PARAMS ioctl call (bnc#986811).\n- CVE-2016-5829: Multiple heap-based buffer overflows in the hiddev_ioctl_usage function in drivers/hid/usbhid/hiddev.c in the Linux kernel allow local users to cause a denial of service or possibly have unspecified other impact via a crafted (1) HIDIOCGUSAGES or (2) HIDIOCSUSAGES ioctl call (bnc#986572).\n- CVE-2016-4470: The key_reject_and_link function in security/keys/key.c in the Linux kernel did not ensure that a certain data structure is initialized, which allowed local users to cause a denial of service (system crash) via vectors involving a crafted keyctl request2 command (bnc#984755).\n\nThe following non-security bugs were fixed:\n\n- base: make module_create_drivers_dir race-free (bnc#983977).\n- btrfs-8448-improve-performance-on-fsync-against-new-inode.patch: Disable (bsc#981597).\n- btrfs: account for non-CoW'd blocks in btrfs_abort_transaction (bsc#983619).\n- btrfs: be more precise on errors when getting an inode from disk (bsc#981038).\n- btrfs: do not create or leak aliased root while cleaning up orphans (bsc#994881).\n- btrfs: ensure that file descriptor used with subvol ioctls is a dir (bsc#999600).\n- btrfs: fix relocation incorrectly dropping data references (bsc#990384).\n- btrfs: handle quota reserve failure properly (bsc#1005666).\n- btrfs: improve performance on fsync against new inode after rename/unlink (bsc#981038).\n- btrfs: increment ctx->pos for every emitted or skipped dirent in readdir (bsc#981709).\n- btrfs: remove old tree_root dirent processing in btrfs_real_readdir() (bsc#981709).\n- cdc-acm: added sanity checking for probe() (bsc#993891).\n- ext2: Enable ext2 driver in config files (bsc#976195, fate#320805)\n- ext4: Add parameter for tuning handling of ext2 (bsc#976195).\n- ext4: Fixup handling for custom configs in tuning.\n- ftrace/x86: Set ftrace_stub to weak to prevent gcc from using short jumps to it (bsc#984419).\n- ipv6: Fix improper use or RCU in patches.kabi/ipv6-add-complete-rcu-protection-around-np-opt.kabi.patch. (bsc#961257)\n- ipv6: KABI workaround for ipv6: add complete rcu protection around np->opt.\n- kabi: prevent spurious modversion changes after bsc#982544 fix (bsc#982544).\n- kabi: reintroduce sk_filter (kabi).\n- kaweth: fix firmware download (bsc#993890).\n- kaweth: fix oops upon failed memory allocation (bsc#993890).\n- kgraft/iscsi-target: Do not block kGraft in iscsi_np kthread (bsc#1010612, fate#313296).\n- kgraft/xen: Do not block kGraft in xenbus kthread (bsc#1017410, fate#313296).\n- kgr: ignore zombie tasks during the patching (bnc#1008979).\n- mm/swap.c: flush lru pvecs on compound page arrival (bnc#983721).\n- mm: thp: fix SMP race condition between THP page fault and MADV_DONTNEED (VM Functionality, bnc#986445).\n- modsign: Print appropriate status message when accessing UEFI variable (bsc#958606).\n- mpi: Fix NULL ptr dereference in mpi_powm() [ver #3] (bsc#1011820).\n- mpt3sas: Fix panic when aer correct error occurred (bsc#997708, bsc#999943).\n- netfilter: allow logging fron non-init netns (bsc#970083).\n- netfilter: bridge: do not leak skb in error paths (bsc#982544).\n- netfilter: bridge: forward IPv6 fragmented packets (bsc#982544).\n- netfilter: bridge: Use __in6_dev_get rather than in6_dev_get in br_validate_ipv6 (bsc#982544).\n- nfs: Do not write enable new pages while an invalidation is proceeding (bsc#999584).\n- nfs: Fix a regression in the read() syscall (bsc#999584).\n- pci/aer: Clear error status registers during enumeration and restore (bsc#985978).\n- ppp: defer netns reference release for ppp channel (bsc#980371).\n- reiserfs: fix race in prealloc discard (bsc#987576).\n- scsi: ibmvfc: Fix I/O hang when port is not mapped (bsc#971989)\n- scsi: Increase REPORT_LUNS timeout (bsc#982282).\n- series.conf: move stray netfilter patches to the right section\n- squashfs3: properly handle dir_emit() failures (bsc#998795).\n- supported.conf: Add ext2\n- timers: Use proper base migration in add_timer_on() (bnc#993392).\n- tty: audit: Fix audit source (bsc#1016482).\n- tty: Prevent ldisc drivers from re-using stale tty fields (bnc#1010507).\n- usb: fix typo in wMaxPacketSize validation (bsc#991665).\n- usb: validate wMaxPacketValue entries in endpoint descriptors (bnc#991665).\n- xen: Fix refcnt regression in xen netback introduced by changes made for bug#881008 (bnc#978094)\n- xfs: allow lazy sb counter sync during filesystem freeze sequence (bsc#980560).\n- xfs: fixed signedness of error code in xfs_inode_buf_verify (bsc#1003153).\n- xfs: fix premature enospc on inode allocation (bsc#984148).\n- xfs: get rid of XFS_IALLOC_BLOCKS macros (bsc#984148).\n- xfs: get rid of XFS_INODE_CLUSTER_SIZE macros (bsc#984148).\n- xfs: refactor xlog_recover_process_data() (bsc#1019300).\n- xfs: Silence warnings in xfs_vm_releasepage() (bnc#915183 bsc#987565).\n- xhci: silence warnings in switch (bnc#991665).\n","id":"SUSE-SU-2017:0471-1","modified":"2017-02-15T16:20:32Z","published":"2017-02-15T16:20:32Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2017/suse-su-20170471-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1003153"},{"type":"REPORT","url":"https://bugzilla.suse.com/1003925"},{"type":"REPORT","url":"https://bugzilla.suse.com/1004462"},{"type":"REPORT","url":"https://bugzilla.suse.com/1004517"},{"type":"REPORT","url":"https://bugzilla.suse.com/1005666"},{"type":"REPORT","url":"https://bugzilla.suse.com/1007197"},{"type":"REPORT","url":"https://bugzilla.suse.com/1008833"},{"type":"REPORT","url":"https://bugzilla.suse.com/1008979"},{"type":"REPORT","url":"https://bugzilla.suse.com/1009969"},{"type":"REPORT","url":"https://bugzilla.suse.com/1010040"},{"type":"REPORT","url":"https://bugzilla.suse.com/1010475"},{"type":"REPORT","url":"https://bugzilla.suse.com/1010478"},{"type":"REPORT","url":"https://bugzilla.suse.com/1010501"},{"type":"REPORT","url":"https://bugzilla.suse.com/1010502"},{"type":"REPORT","url":"https://bugzilla.suse.com/1010507"},{"type":"REPORT","url":"https://bugzilla.suse.com/1010612"},{"type":"REPORT","url":"https://bugzilla.suse.com/1010711"},{"type":"REPORT","url":"https://bugzilla.suse.com/1010716"},{"type":"REPORT","url":"https://bugzilla.suse.com/1011820"},{"type":"REPORT","url":"https://bugzilla.suse.com/1012422"},{"type":"REPORT","url":"https://bugzilla.suse.com/1013038"},{"type":"REPORT","url":"https://bugzilla.suse.com/1013531"},{"type":"REPORT","url":"https://bugzilla.suse.com/1013540"},{"type":"REPORT","url":"https://bugzilla.suse.com/1013542"},{"type":"REPORT","url":"https://bugzilla.suse.com/1014746"},{"type":"REPORT","url":"https://bugzilla.suse.com/1016482"},{"type":"REPORT","url":"https://bugzilla.suse.com/1017410"},{"type":"REPORT","url":"https://bugzilla.suse.com/1017589"},{"type":"REPORT","url":"https://bugzilla.suse.com/1017710"},{"type":"REPORT","url":"https://bugzilla.suse.com/1019300"},{"type":"REPORT","url":"https://bugzilla.suse.com/1019851"},{"type":"REPORT","url":"https://bugzilla.suse.com/1020602"},{"type":"REPORT","url":"https://bugzilla.suse.com/1021258"},{"type":"REPORT","url":"https://bugzilla.suse.com/881008"},{"type":"REPORT","url":"https://bugzilla.suse.com/915183"},{"type":"REPORT","url":"https://bugzilla.suse.com/958606"},{"type":"REPORT","url":"https://bugzilla.suse.com/961257"},{"type":"REPORT","url":"https://bugzilla.suse.com/970083"},{"type":"REPORT","url":"https://bugzilla.suse.com/971989"},{"type":"REPORT","url":"https://bugzilla.suse.com/976195"},{"type":"REPORT","url":"https://bugzilla.suse.com/978094"},{"type":"REPORT","url":"https://bugzilla.suse.com/980371"},{"type":"REPORT","url":"https://bugzilla.suse.com/980560"},{"type":"REPORT","url":"https://bugzilla.suse.com/981038"},{"type":"REPORT","url":"https://bugzilla.suse.com/981597"},{"type":"REPORT","url":"https://bugzilla.suse.com/981709"},{"type":"REPORT","url":"https://bugzilla.suse.com/982282"},{"type":"REPORT","url":"https://bugzilla.suse.com/982544"},{"type":"REPORT","url":"https://bugzilla.suse.com/983619"},{"type":"REPORT","url":"https://bugzilla.suse.com/983721"},{"type":"REPORT","url":"https://bugzilla.suse.com/983977"},{"type":"REPORT","url":"https://bugzilla.suse.com/984148"},{"type":"REPORT","url":"https://bugzilla.suse.com/984419"},{"type":"REPORT","url":"https://bugzilla.suse.com/984755"},{"type":"REPORT","url":"https://bugzilla.suse.com/985978"},{"type":"REPORT","url":"https://bugzilla.suse.com/986362"},{"type":"REPORT","url":"https://bugzilla.suse.com/986365"},{"type":"REPORT","url":"https://bugzilla.suse.com/986445"},{"type":"REPORT","url":"https://bugzilla.suse.com/986569"},{"type":"REPORT","url":"https://bugzilla.suse.com/986572"},{"type":"REPORT","url":"https://bugzilla.suse.com/986811"},{"type":"REPORT","url":"https://bugzilla.suse.com/986941"},{"type":"REPORT","url":"https://bugzilla.suse.com/987542"},{"type":"REPORT","url":"https://bugzilla.suse.com/987565"},{"type":"REPORT","url":"https://bugzilla.suse.com/987576"},{"type":"REPORT","url":"https://bugzilla.suse.com/989152"},{"type":"REPORT","url":"https://bugzilla.suse.com/990384"},{"type":"REPORT","url":"https://bugzilla.suse.com/991608"},{"type":"REPORT","url":"https://bugzilla.suse.com/991665"},{"type":"REPORT","url":"https://bugzilla.suse.com/993392"},{"type":"REPORT","url":"https://bugzilla.suse.com/993890"},{"type":"REPORT","url":"https://bugzilla.suse.com/993891"},{"type":"REPORT","url":"https://bugzilla.suse.com/994296"},{"type":"REPORT","url":"https://bugzilla.suse.com/994748"},{"type":"REPORT","url":"https://bugzilla.suse.com/994881"},{"type":"REPORT","url":"https://bugzilla.suse.com/995968"},{"type":"REPORT","url":"https://bugzilla.suse.com/997708"},{"type":"REPORT","url":"https://bugzilla.suse.com/998795"},{"type":"REPORT","url":"https://bugzilla.suse.com/999584"},{"type":"REPORT","url":"https://bugzilla.suse.com/999600"},{"type":"REPORT","url":"https://bugzilla.suse.com/999932"},{"type":"REPORT","url":"https://bugzilla.suse.com/999943"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-9904"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-8956"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-8962"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-8963"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-8964"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-10088"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-4470"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-4997"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-5696"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-5828"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-5829"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-6130"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-6327"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-6480"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-6828"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7042"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7097"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7425"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7910"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7911"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7913"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7914"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-8399"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-8633"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-8645"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-8658"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-9083"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-9084"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-9756"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-9793"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-9806"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-2583"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-2584"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5551"}],"related":["CVE-2014-9904","CVE-2015-8956","CVE-2015-8962","CVE-2015-8963","CVE-2015-8964","CVE-2016-10088","CVE-2016-4470","CVE-2016-4997","CVE-2016-5696","CVE-2016-5828","CVE-2016-5829","CVE-2016-6130","CVE-2016-6327","CVE-2016-6480","CVE-2016-6828","CVE-2016-7042","CVE-2016-7097","CVE-2016-7425","CVE-2016-7910","CVE-2016-7911","CVE-2016-7913","CVE-2016-7914","CVE-2016-8399","CVE-2016-8633","CVE-2016-8645","CVE-2016-8658","CVE-2016-9083","CVE-2016-9084","CVE-2016-9756","CVE-2016-9793","CVE-2016-9806","CVE-2017-2583","CVE-2017-2584","CVE-2017-5551"],"summary":"Security update for the Linux Kernel","upstream":["CVE-2014-9904","CVE-2015-8956","CVE-2015-8962","CVE-2015-8963","CVE-2015-8964","CVE-2016-10088","CVE-2016-4470","CVE-2016-4997","CVE-2016-5696","CVE-2016-5828","CVE-2016-5829","CVE-2016-6130","CVE-2016-6327","CVE-2016-6480","CVE-2016-6828","CVE-2016-7042","CVE-2016-7097","CVE-2016-7425","CVE-2016-7910","CVE-2016-7911","CVE-2016-7913","CVE-2016-7914","CVE-2016-8399","CVE-2016-8633","CVE-2016-8645","CVE-2016-8658","CVE-2016-9083","CVE-2016-9084","CVE-2016-9756","CVE-2016-9793","CVE-2016-9806","CVE-2017-2583","CVE-2017-2584","CVE-2017-5551"]}