Upstream information
Description
crypto/ghash-generic.c in the Linux kernel before 3.1 allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact by triggering a failed or missing ghash_setkey function call, followed by a (1) ghash_update function call or (2) ghash_final function call, as demonstrated by a write operation on an AF_ALG socket.NVD CVSS v2 Base Score: 4.9 (AV:L/AC:L/Au:N/C:N/I:N/A:C)
Novell/SUSE information
Note from the SUSE Security Team
The gcrypto hash module was added in the 2.6.32 kernel so older kernels are not affected by this problem. SUSE Linux Enterprise 10 and older are not affected. Novell Bugzilla entry: 726788 SUSE Security Advisories:- SUSE-SU-2012:0153-1, published Mon, 6 Feb 2012 15:08:23 +0100 (CET)
- SUSE-SU-2012:0153-2, published Mon, 6 Feb 2012 23:08:27 +0100 (CET)
- SUSE-SU-2012:0364-1, published Wed, 14 Mar 2012 00:08:32 +0100 (CET)
- openSUSE-SU-2012:0206-1, published Thu, 9 Feb 2012 19:09:19 +0100 (CET)
- openSUSE-SU-2012:0236-1, published Thu, 9 Feb 2012 19:10:55 +0100 (CET)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SLE 11 SERVER Unsupported Extras |
| Builds SAT Patch Nr: 5726 |
| openSUSE 11.4 DEBUGINFO |
| |
| openSUSE 11.4 |
| |
| openSUSE 11.3 |
| |
| openSUSE 11.3 |
| |
| SUSE Linux Enterprise Real Time 11 SP1 |
| slert11-sp1.x86-64 SAT Patch Nr: 5802 |
| SLE 11 SP1 DEBUGINFO |
| sles11-sp1-vmware.x86-64 sled11-sp1.x86-64 sle11-sp1-hae.x86-64 sles11-sp1.x86-64 SAT Patch Nr: 5732 |
| SUSE Linux Enterprise High Availability Extension 11 SP1 |
| sles11-sp1-vmware.x86-64 sled11-sp1.x86-64 sle11-sp1-hae.x86-64 sles11-sp1.x86-64 SAT Patch Nr: 5732 |
| SUSE Linux Enterprise Desktop 11 SP1 |
| sles11-sp1-vmware.x86-64 sled11-sp1.x86-64 sle11-sp1-hae.x86-64 sles11-sp1.x86-64 SAT Patch Nr: 5732 |
| SUSE Linux Enterprise Server 11 SP1 for VMware |
| sles11-sp1-vmware.x86-64 sled11-sp1.x86-64 sle11-sp1-hae.x86-64 sles11-sp1.x86-64 SAT Patch Nr: 5732 |
| SUSE Linux Enterprise Server 11 SP1 |
| sles11-sp1-vmware.x86-64 sled11-sp1.x86-64 sle11-sp1-hae.x86-64 sles11-sp1.x86-64 SAT Patch Nr: 5732 |
| SLE 11 SP1 DEBUGINFO |
| sles11-sp1.x86 sle11-sp1-hae.x86 sles11-sp1-vmware.x86 sled11-sp1.x86 SAT Patch Nr: 5723 |
| SUSE Linux Enterprise High Availability Extension 11 SP1 |
| sles11-sp1.x86 sle11-sp1-hae.x86 sles11-sp1-vmware.x86 sled11-sp1.x86 SAT Patch Nr: 5723 |
| SUSE Linux Enterprise Desktop 11 SP1 |
| sles11-sp1.x86 sle11-sp1-hae.x86 sles11-sp1-vmware.x86 sled11-sp1.x86 SAT Patch Nr: 5723 |
| SUSE Linux Enterprise Server 11 SP1 for VMware |
| sles11-sp1.x86 sle11-sp1-hae.x86 sles11-sp1-vmware.x86 sled11-sp1.x86 SAT Patch Nr: 5723 |
| SUSE Linux Enterprise Server 11 SP1 |
| sles11-sp1.x86 sle11-sp1-hae.x86 sles11-sp1-vmware.x86 sled11-sp1.x86 SAT Patch Nr: 5723 |
| SLE 11 SERVER Unsupported Extras |
| Builds SAT Patch Nr: 5727 |
| SLE 11 SP1 DEBUGINFO |
| sles11-sp1.ia64 sle11-sp1-hae.ia64 SAT Patch Nr: 5729 |
| SUSE Linux Enterprise High Availability Extension 11 SP1 |
| sles11-sp1.ia64 sle11-sp1-hae.ia64 SAT Patch Nr: 5729 |
| SUSE Linux Enterprise Server 11 SP1 |
| sles11-sp1.ia64 sle11-sp1-hae.ia64 SAT Patch Nr: 5729 |
| SLE 11 SERVER Unsupported Extras |
| Builds SAT Patch Nr: 5730 |
| SLE 11 SP1 DEBUGINFO |
| sles11-sp1.ppc sle11-sp1-hae.ppc SAT Patch Nr: 5724 |
| SUSE Linux Enterprise High Availability Extension 11 SP1 |
| sles11-sp1.ppc sle11-sp1-hae.ppc SAT Patch Nr: 5724 |
| SUSE Linux Enterprise Server 11 SP1 |
| sles11-sp1.ppc sle11-sp1-hae.ppc SAT Patch Nr: 5724 |
| SLE 11 SP1 DEBUGINFO |
| sle11-sp1-hae.s390x sles11-sp1.s390x SAT Patch Nr: 5725 |
| SUSE Linux Enterprise High Availability Extension 11 SP1 |
| sle11-sp1-hae.s390x sles11-sp1.s390x SAT Patch Nr: 5725 |
| SUSE Linux Enterprise Server 11 SP1 |
| sle11-sp1-hae.s390x sles11-sp1.s390x SAT Patch Nr: 5725 |
| SLE 11 SERVER Unsupported Extras |
| Builds SAT Patch Nr: 5731 |
| SLE 11 SERVER Unsupported Extras |
| Builds SAT Patch Nr: 5728 |
