2015-05-06
ALT-BU-2015-2442-1
Branch sisyphus update bulletin.
Package kernel-image-un-def updated to version 3.19.6-alt1 for branch sisyphus in task 143911.
Closed vulnerabilities
Published: 2015-05-27
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2015-2922
The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.
Severity: LOW (3.3)
References:
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6fd99094de2b83d1d4c8457f2c83483b2828e75a
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6fd99094de2b83d1d4c8457f2c83483b2828e75a
- FEDORA-2015-6294
- FEDORA-2015-6294
- FEDORA-2015-6320
- FEDORA-2015-6320
- FEDORA-2015-6100
- FEDORA-2015-6100
- SUSE-SU-2015:1224
- SUSE-SU-2015:1224
- openSUSE-SU-2015:1382
- openSUSE-SU-2015:1382
- SUSE-SU-2015:1478
- SUSE-SU-2015:1478
- RHSA-2015:1221
- RHSA-2015:1221
- RHSA-2015:1534
- RHSA-2015:1534
- RHSA-2015:1564
- RHSA-2015:1564
- DSA-3237
- DSA-3237
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.19.6
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.19.6
- [oss-security] 20150404 Re: CVE Request : IPv6 Hop limit lowering via RA messages
- [oss-security] 20150404 Re: CVE Request : IPv6 Hop limit lowering via RA messages
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- 74315
- 74315
- 1032417
- 1032417
- https://bugzilla.redhat.com/show_bug.cgi?id=1203712
- https://bugzilla.redhat.com/show_bug.cgi?id=1203712
- https://github.com/torvalds/linux/commit/6fd99094de2b83d1d4c8457f2c83483b2828e75a
- https://github.com/torvalds/linux/commit/6fd99094de2b83d1d4c8457f2c83483b2828e75a
Published: 2015-05-27
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2015-3339
Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows local users to gain privileges by executing a setuid program at a time instant when a chown to root is in progress, and the ownership is changed but the setuid bit is not yet stripped.
Severity: MEDIUM (6.2)
References:
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8b01fc86b9f425899f8a3a8fc1c47d73c2c20543
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8b01fc86b9f425899f8a3a8fc1c47d73c2c20543
- FEDORA-2015-7736
- FEDORA-2015-7736
- FEDORA-2015-8518
- FEDORA-2015-8518
- openSUSE-SU-2015:1382
- openSUSE-SU-2015:1382
- SUSE-SU-2015:1487
- SUSE-SU-2015:1487
- SUSE-SU-2015:1488
- SUSE-SU-2015:1488
- SUSE-SU-2015:1489
- SUSE-SU-2015:1489
- SUSE-SU-2015:1491
- SUSE-SU-2015:1491
- SUSE-SU-2016:2074
- SUSE-SU-2016:2074
- RHSA-2015:1272
- RHSA-2015:1272
- DSA-3237
- DSA-3237
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.19.6
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.19.6
- [oss-security] 20150420 Re: Linux: chown() was racy relative to execve() - Linux kernel
- [oss-security] 20150420 Re: Linux: chown() was racy relative to execve() - Linux kernel
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- 1032412
- 1032412
- https://bugzilla.redhat.com/show_bug.cgi?id=1214030
- https://bugzilla.redhat.com/show_bug.cgi?id=1214030
- https://github.com/torvalds/linux/commit/8b01fc86b9f425899f8a3a8fc1c47d73c2c20543
- https://github.com/torvalds/linux/commit/8b01fc86b9f425899f8a3a8fc1c47d73c2c20543