SUSE update for kernel

by Carol~ Moderator - 6/4/12 9:08 AM

In Reply to: VULNERABILITIES / FIXES - June 04, 2012 by Carol~ Moderator

Release Date : 2012-06-04

Criticality level : Moderately critical
Impact : Privilege escalation
DoS
Where : From remote
Solution Status : Vendor Patch

Operating System: SUSE Linux Enterprise Server (SLES) 11

Software: SUSE Linux Enterprise 11 High Availability Extension

Description:
SUSE has issued an update for the kernel. This fixes two vulnerabilities, which can be exploited by malicious, local users to potentially gain escalated privileges and by malicious people to cause a DoS (Denial of Service).

1) An error within the pid_namespace handling can be exploited to leak pid_namespace slabs and consume CPU resources via e.g. vsftpd.

Solution:
Apply updated packages via the zypper package manager.

Provided and/or discovered by:
1) Vadim Ponomarev within a Novell bug report.

Original Advisory:
SUSE-SU-2012:0689-1:
http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00001.html

Novell Bug#757783:
https://bugzilla.novell.com/show_bug.cgi?id=757783

http://secunia.com/advisories/49374/