Upstream information
Description
Buffer overflow in the xfs_readlink function in fs/xfs/xfs_vnodeops.c in XFS in the Linux kernel 2.6, when CONFIG_XFS_DEBUG is disabled, allows local users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via an XFS image containing a symbolic link with a long pathname.NVD CVSS v2 Base Score: 6.9 (AV:L/AC:M/Au:N/C:C/I:C/A:C)
Novell/SUSE information
Novell Bugzilla entry: 726600 SUSE Security Advisories:- SUSE-SU-2012:0153-1, published Mon, 6 Feb 2012 15:08:23 +0100 (CET)
- SUSE-SU-2012:0153-2, published Mon, 6 Feb 2012 23:08:27 +0100 (CET)
- SUSE-SU-2012:0736-1, published Thu, 14 Jun 2012 18:08:31 +0200 (CEST)
- openSUSE-SU-2012:0540-1, published Fri, 20 Apr 2012 16:08:14 +0200 (CEST)
- openSUSE-SU-2012:0799-1, published Thu, 28 Jun 2012 10:08:31 +0200 (CEST)
- openSUSE-SU-2012:1439-1, published Mon, 5 Nov 2012 10:09:03 +0100 (CET)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SLE 11 SERVER Unsupported Extras |
| Builds SAT Patch Nr: 5726 |
| SLE 11 SP1 DEBUGINFO |
| sles11-sp1-vmware.x86-64 sled11-sp1.x86-64 sle11-sp1-hae.x86-64 sles11-sp1.x86-64 SAT Patch Nr: 5732 |
| SUSE Linux Enterprise High Availability Extension 11 SP1 |
| sles11-sp1-vmware.x86-64 sled11-sp1.x86-64 sle11-sp1-hae.x86-64 sles11-sp1.x86-64 SAT Patch Nr: 5732 |
| SUSE Linux Enterprise Desktop 11 SP1 |
| sles11-sp1-vmware.x86-64 sled11-sp1.x86-64 sle11-sp1-hae.x86-64 sles11-sp1.x86-64 SAT Patch Nr: 5732 |
| SUSE Linux Enterprise Server 11 SP1 for VMware |
| sles11-sp1-vmware.x86-64 sled11-sp1.x86-64 sle11-sp1-hae.x86-64 sles11-sp1.x86-64 SAT Patch Nr: 5732 |
| SUSE Linux Enterprise Server 11 SP1 |
| sles11-sp1-vmware.x86-64 sled11-sp1.x86-64 sle11-sp1-hae.x86-64 sles11-sp1.x86-64 SAT Patch Nr: 5732 |
| SLE 11 SP1 DEBUGINFO |
| sles11-sp1.x86 sle11-sp1-hae.x86 sles11-sp1-vmware.x86 sled11-sp1.x86 SAT Patch Nr: 5723 |
| SUSE Linux Enterprise High Availability Extension 11 SP1 |
| sles11-sp1.x86 sle11-sp1-hae.x86 sles11-sp1-vmware.x86 sled11-sp1.x86 SAT Patch Nr: 5723 |
| SUSE Linux Enterprise Desktop 11 SP1 |
| sles11-sp1.x86 sle11-sp1-hae.x86 sles11-sp1-vmware.x86 sled11-sp1.x86 SAT Patch Nr: 5723 |
| SUSE Linux Enterprise Server 11 SP1 for VMware |
| sles11-sp1.x86 sle11-sp1-hae.x86 sles11-sp1-vmware.x86 sled11-sp1.x86 SAT Patch Nr: 5723 |
| SUSE Linux Enterprise Server 11 SP1 |
| sles11-sp1.x86 sle11-sp1-hae.x86 sles11-sp1-vmware.x86 sled11-sp1.x86 SAT Patch Nr: 5723 |
| SLE 11 SERVER Unsupported Extras |
| Builds SAT Patch Nr: 5727 |
| SLE 11 SP1 DEBUGINFO |
| sles11-sp1.ia64 sle11-sp1-hae.ia64 SAT Patch Nr: 5729 |
| SUSE Linux Enterprise High Availability Extension 11 SP1 |
| sles11-sp1.ia64 sle11-sp1-hae.ia64 SAT Patch Nr: 5729 |
| SUSE Linux Enterprise Server 11 SP1 |
| sles11-sp1.ia64 sle11-sp1-hae.ia64 SAT Patch Nr: 5729 |
| SUSE Linux Enterprise Real Time 11 SP1 |
| slert11-sp1.x86-64 SAT Patch Nr: 6677 |
| SLE 11 SERVER Unsupported Extras |
| Builds SAT Patch Nr: 5730 |
| SLE 11 SP1 DEBUGINFO |
| sles11-sp1.ppc sle11-sp1-hae.ppc SAT Patch Nr: 5724 |
| SUSE Linux Enterprise High Availability Extension 11 SP1 |
| sles11-sp1.ppc sle11-sp1-hae.ppc SAT Patch Nr: 5724 |
| SUSE Linux Enterprise Server 11 SP1 |
| sles11-sp1.ppc sle11-sp1-hae.ppc SAT Patch Nr: 5724 |
| SUSE Linux Enterprise 10 SP4 DEBUGINFO for IPF |
| Builds ZYPP Patch Nr: 8160 |
| SLE SDK 10 SP4 for IPF |
| Builds ZYPP Patch Nr: 8160 |
| SUSE Linux Enterprise Server 10 SP4 for IPF |
| Builds ZYPP Patch Nr: 8160 |
| SLE 11 SP1 DEBUGINFO |
| sle11-sp1-hae.s390x sles11-sp1.s390x SAT Patch Nr: 5725 |
| SUSE Linux Enterprise High Availability Extension 11 SP1 |
| sle11-sp1-hae.s390x sles11-sp1.s390x SAT Patch Nr: 5725 |
| SUSE Linux Enterprise Server 11 SP1 |
| sle11-sp1-hae.s390x sles11-sp1.s390x SAT Patch Nr: 5725 |
| SUSE Linux Enterprise Desktop 10 SP4 for AMD64 and Intel EM64T |
| Builds ZYPP Patch Nr: 8161 |
| SUSE Linux Enterprise 10 SP4 DEBUGINFO for AMD64 and Intel EM64T |
| Builds ZYPP Patch Nr: 8161 |
| SLE SDK 10 SP4 for X86-64 |
| Builds ZYPP Patch Nr: 8161 |
| SUSE Linux Enterprise Server 10 SP4 for AMD64 and Intel EM64T |
| Builds ZYPP Patch Nr: 8161 |
| SUSE Linux Enterprise 10 SP4 DEBUGINFO for IBM POWER |
| Builds ZYPP Patch Nr: 8163 |
| SLE SDK 10 SP4 for IBM iSeries and IBM pSeries |
| Builds ZYPP Patch Nr: 8163 |
| SUSE Linux Enterprise Server 10 SP4 for IBM POWER |
| Builds ZYPP Patch Nr: 8163 |
| SLE 11 SERVER Unsupported Extras |
| Builds SAT Patch Nr: 5731 |
| SUSE CORE 9 for AMD64 and Intel EM64T |
| Builds YOU Patch Nr: 12874 |
| SLE 11 SERVER Unsupported Extras |
| Builds SAT Patch Nr: 5728 |
