File _patchinfo of Package patchinfo.4422
<patchinfo incident="4422">
<issue id="1027565" tracker="bnc">VUL-0: CVE-2017-2636: kernel-source: tty: n_hdlc: get rid of racy n_hdlc.tbuf</issue>
<issue id="1028372" tracker="bnc">VUL-0: CVE-2017-2636: kernel-source: local privilege escalation flaw in n_hdlc</issue>
<issue id="1030573" tracker="bnc">VUL-0: CVE-2017-7184: kernel-source: xfrm kernel heap out-of-bounds access</issue>
<issue id="2017-7184" tracker="cve" />
<issue id="2017-2636" tracker="cve" />
<category>security</category>
<rating>important</rating>
<packager>michal-m</packager>
<reboot_needed/>
<description>
The SUSE Linux Enterprise 12 kernel was updated to fix the following security bugs:
- CVE-2017-7184: The Linux kernel allowed local users to obtain root privileges or cause a denial of service (heap-based out-of-bounds access) via unspecified vectors, as demonstrated during a Pwn2Own competition at CanSecWest 2017 (bnc#1030573, bnc#1028372).
- CVE-2017-2636: Race condition in drivers/tty/n_hdlc.c in the Linux kernel allowed local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline (bnc#1027565).
</description>
<summary>Security update for the Linux Kernel</summary>
</patchinfo>