← Search the atlas
SUSE-SU-2016:3146-1
Not scored
Security update for the Linux Kernel
The SUSE Linux Enterprise 12 SP 2 kernel was updated to fix two security issues.
The following security bugs were fixed:
- CVE-2016-9576: A use-after-free vulnerability in the SCSI generic driver allows users with write access to /dev/sg* or /dev/bsg* to elevate their privileges (bsc#1013604).
- CVE-2016-9794: A use-after-free vulnerability in the ALSA pcm layer allowed local users to cause a denial of service, memory corruption or possibly even to elevate their privileges (bsc#1013533).
Exploit probability
Not scored
Published
December 13, 2016
Required by
Not available
Last source change
February 4, 2026
02 / AFFECTED SOFTWARE
Affected packages
SUSE:Linux Enterprise Desktop 12 SP2
kernel-default
SUSE:Linux Enterprise Desktop 12 SP2
kernel-source
SUSE:Linux Enterprise Desktop 12 SP2
kernel-syms
SUSE:Linux Enterprise High Availability Extension 12 SP2
kernel-default
SUSE:Linux Enterprise Live Patching 12
kgraft-patch-SLE12-SP2_Update_3
SUSE:Linux Enterprise Server 12 SP2
kernel-default
SUSE:Linux Enterprise Server 12 SP2
kernel-source
SUSE:Linux Enterprise Server 12 SP2
kernel-syms
SUSE:Linux Enterprise Server for Raspberry Pi 12 SP2
kernel-default
SUSE:Linux Enterprise Server for Raspberry Pi 12 SP2
kernel-source
SUSE:Linux Enterprise Server for Raspberry Pi 12 SP2
kernel-syms
SUSE:Linux Enterprise Server for SAP Applications 12 SP2
kernel-default
SUSE:Linux Enterprise Server for SAP Applications 12 SP2
kernel-source
SUSE:Linux Enterprise Server for SAP Applications 12 SP2
kernel-syms
SUSE:Linux Enterprise Software Development Kit 12 SP2
kernel-docs
SUSE:Linux Enterprise Software Development Kit 12 SP2
kernel-obs-build
SUSE:Linux Enterprise Workstation Extension 12 SP2
kernel-default
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
SUSE-SU-2016:3146-1
The SUSE Linux Enterprise 12 SP 2 kernel was updated to fix two security issues.
The following security bugs were fixed:
- CVE-2016-9576: A use-after-free vulnerability in the SCSI generic driver allows users with write access to /dev/sg* or /dev/bsg* to elevate their privileges (bsc#1013604).
- CVE-2016-9794: A use-after-free vulnerability in the ALSA pcm layer allowed local users to cause a denial of service, memory corruption or possibly even to elevate their privileges (bsc#1013533).
View original source ↗
05 / REFERENCES
Further evidence