← Search the atlas
SUSE-SU-2016:3203-1
Not scored
Security update for the Linux Kernel
The SUSE Linux Enterprise 11 SP4 kernel was updated to fix two security issues.
The following security bugs were fixed:
- CVE-2016-9576: A use-after-free vulnerability in the SCSI generic driver allows users with write access to /dev/sg* or /dev/bsg* to elevate their privileges (bsc#1013604).
- CVE-2016-9794: A use-after-free vulnerability in the ALSA pcm layer allowed local users to cause a denial of service, memory corruption or possibly even to elevate their privileges (bsc#1013533).
Exploit probability
Not scored
Published
December 20, 2016
Required by
Not available
Last source change
February 4, 2026
02 / AFFECTED SOFTWARE
Affected packages
SUSE:Linux Enterprise Server 11 SP4
kernel-bigmem
SUSE:Linux Enterprise Server 11 SP4
kernel-default
SUSE:Linux Enterprise Server 11 SP4
kernel-ec2
SUSE:Linux Enterprise Server 11 SP4
kernel-pae
SUSE:Linux Enterprise Server 11 SP4
kernel-ppc64
SUSE:Linux Enterprise Server 11 SP4
kernel-source
SUSE:Linux Enterprise Server 11 SP4
kernel-syms
SUSE:Linux Enterprise Server 11 SP4
kernel-trace
SUSE:Linux Enterprise Server 11 SP4
kernel-xen
SUSE:Linux Enterprise Server for SAP Applications 11 SP4
kernel-bigmem
SUSE:Linux Enterprise Server for SAP Applications 11 SP4
kernel-default
SUSE:Linux Enterprise Server for SAP Applications 11 SP4
kernel-ec2
SUSE:Linux Enterprise Server for SAP Applications 11 SP4
kernel-pae
SUSE:Linux Enterprise Server for SAP Applications 11 SP4
kernel-ppc64
SUSE:Linux Enterprise Server for SAP Applications 11 SP4
kernel-source
SUSE:Linux Enterprise Server for SAP Applications 11 SP4
kernel-syms
SUSE:Linux Enterprise Server for SAP Applications 11 SP4
kernel-trace
SUSE:Linux Enterprise Server for SAP Applications 11 SP4
kernel-xen
SUSE:Linux Enterprise Software Development Kit 11 SP4
kernel-docs
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
SUSE-SU-2016:3203-1
The SUSE Linux Enterprise 11 SP4 kernel was updated to fix two security issues.
The following security bugs were fixed:
- CVE-2016-9576: A use-after-free vulnerability in the SCSI generic driver allows users with write access to /dev/sg* or /dev/bsg* to elevate their privileges (bsc#1013604).
- CVE-2016-9794: A use-after-free vulnerability in the ALSA pcm layer allowed local users to cause a denial of service, memory corruption or possibly even to elevate their privileges (bsc#1013533).
View original source ↗
05 / REFERENCES
Further evidence