FlawAtlas
Search the atlas
SUSE-SU-2017:0307-1 Not scored

Security update for Linux Kernel Live Patch 4 for SLE 12 SP2

This update for the Linux Kernel fixes one security issue: - CVE-2016-10088: The sg implementation in the Linux kernel did not properly restrict write operations in situations where the KERNEL_DS option is set, which allowed local users to read or write to arbitrary kernel memory locations or cause a denial of service (use-after-free) by leveraging access to a /dev/sg device (bsc#1017710).

Exploit probability Not scored
Published January 27, 2017
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Live Patching 12 kgraft-patch-SLE12-SP2_Update_4

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2017:0307-1

This update for the Linux Kernel fixes one security issue: - CVE-2016-10088: The sg implementation in the Linux kernel did not properly restrict write operations in situations where the KERNEL_DS option is set, which allowed local users to read or write to arbitrary kernel memory locations or cause a denial of service (use-after-free) by leveraging access to a /dev/sg device (bsc#1017710).

View original source

05 / REFERENCES

Further evidence