FlawAtlas
Search the atlas
SUSE-SU-2016:1709-1 Not scored

Security update for the Linux Kernel

The SUSE Linux Enterprise 12 kernel was updated to receive critical security and bugfixes. Security issue fixed: - CVE-2016-4997: A buffer overflow in 32bit compat_setsockopt iptables handling could lead to a local privilege escalation. (bsc#986362) The following non-security bugs were fixed: - KVM: x86: expose invariant tsc cpuid bit (v2) (bsc#971770). - block: do not check request size in blk_cloned_rq_check_limits() (bsc#972124). - rbd: handle OBJ_REQUEST_SG types for copyup (bsc#983394). - target/rbd: do not put snap_context twice (bsc#981143). - target/rbd: remove caw_mutex usage (bsc#981143).

Exploit probability Not scored
Published June 30, 2016
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Server for SAP Applications 12 SP1 kernel-default
SUSE:Linux Enterprise Desktop 12 SP1 kernel-default
SUSE:Linux Enterprise Desktop 12 SP1 kernel-source
SUSE:Linux Enterprise Desktop 12 SP1 kernel-syms
SUSE:Linux Enterprise Desktop 12 SP1 kernel-xen
SUSE:Linux Enterprise Live Patching 12 kgraft-patch-SLE12-SP1_Update_6
SUSE:Linux Enterprise Module for Public Cloud 12 kernel-ec2
SUSE:Linux Enterprise Server 12 SP1 kernel-default
SUSE:Linux Enterprise Server 12 SP1 kernel-source
SUSE:Linux Enterprise Server 12 SP1 kernel-syms
SUSE:Linux Enterprise Server 12 SP1 kernel-xen
SUSE:Linux Enterprise Server for SAP Applications 12 SP1 kernel-source
SUSE:Linux Enterprise Server for SAP Applications 12 SP1 kernel-syms
SUSE:Linux Enterprise Server for SAP Applications 12 SP1 kernel-xen
SUSE:Linux Enterprise Software Development Kit 12 SP1 kernel-docs
SUSE:Linux Enterprise Software Development Kit 12 SP1 kernel-obs-build
SUSE:Linux Enterprise Workstation Extension 12 SP1 kernel-default

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2016:1709-1

The SUSE Linux Enterprise 12 kernel was updated to receive critical security and bugfixes. Security issue fixed: - CVE-2016-4997: A buffer overflow in 32bit compat_setsockopt iptables handling could lead to a local privilege escalation. (bsc#986362) The following non-security bugs were fixed: - KVM: x86: expose invariant tsc cpuid bit (v2) (bsc#971770). - block: do not check request size in blk_cloned_rq_check_limits() (bsc#972124). - rbd: handle OBJ_REQUEST_SG types for copyup (bsc#983394). - target/rbd: do not put snap_context twice (bsc#981143). - target/rbd: remove caw_mutex usage (bsc#981143).

View original source

05 / REFERENCES

Further evidence