SB2016061603 - SUSE Linux update for the Linux Kernel
Published: June 16, 2016
Security Bulletin ID
SB2016061603
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource exhaustion (CVE-ID: CVE-2016-1583)
The vulnerability allows a local attacker to cause DoS condition and gain elevated privileges on the target system.The weakness exists in the ecryptfs_privileged_open function in fs/ecryptfs/kthread.c due to stack memory consumption. A local attacker can cause the service to crash and gain elevated privileges via vectors involving crafted mmap calls for /proc pathnames, leading to recursive pagefault handling.
Remediation
Install update from vendor's website.