SUSE 5107 Published by

The following updates has been released for SUSE Linux Enterprise:

SUSE-SU-2017:3103-1: important: Security update for the Linux Kernel (Live Patch 23 for SLE 12)
SUSE-SU-2017:3104-1: important: Security update for samba
SUSE-SU-2017:3106-1: important: Security update for kernel-firmware



SUSE-SU-2017:3103-1: important: Security update for the Linux Kernel (Live Patch 23 for SLE 12)

SUSE Security Update: Security update for the Linux Kernel (Live Patch 23 for SLE 12)
______________________________________________________________________________

Announcement ID: SUSE-SU-2017:3103-1
Rating: important
References: #1063671 #1064392 #1066471 #1066472
Cross-References: CVE-2017-13080 CVE-2017-15649
Affected Products:
SUSE Linux Enterprise Server 12-LTSS
______________________________________________________________________________

An update that solves two vulnerabilities and has two fixes
is now available.

Description:

This update for the Linux Kernel 3.12.61-52_80 fixes several issues.

The following security issues were fixed:

- CVE-2017-15649: net/packet/af_packet.c in the Linux kernel allowed local
users to gain privileges via crafted system calls that trigger
mishandling of packet_fanout data structures, because of a race
condition (involving fanout_add and packet_do_bind) that leads to a
use-after-free, a different vulnerability than CVE-2017-6346
(bsc#1064392)
- CVE-2017-13080: Wi-Fi Protected Access (WPA and WPA2) allowed
reinstallation of the Group Temporal Key (GTK) during the group key
handshake, allowing an attacker within radio range to replay frames from
access points to clients (bsc#1063671, bsc#1066472, bsc#1066471)


Patch Instructions:

To install this SUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:

- SUSE Linux Enterprise Server 12-LTSS:

zypper in -t patch SUSE-SLE-SERVER-12-2017-1921=1

To bring your system up-to-date, use "zypper patch".


Package List:

- SUSE Linux Enterprise Server 12-LTSS (x86_64):

kgraft-patch-3_12_61-52_80-default-5-2.1
kgraft-patch-3_12_61-52_80-xen-5-2.1


References:

https://www.suse.com/security/cve/CVE-2017-13080.html
https://www.suse.com/security/cve/CVE-2017-15649.html
https://bugzilla.suse.com/1063671
https://bugzilla.suse.com/1064392
https://bugzilla.suse.com/1066471
https://bugzilla.suse.com/1066472

SUSE-SU-2017:3104-1: important: Security update for samba

SUSE Security Update: Security update for samba
______________________________________________________________________________

Announcement ID: SUSE-SU-2017:3104-1
Rating: important
References: #1027593 #1060427 #1063008
Cross-References: CVE-2017-14746 CVE-2017-15275
Affected Products:
SUSE Linux Enterprise Software Development Kit 12-SP2
SUSE Linux Enterprise Server for Raspberry Pi 12-SP2
SUSE Linux Enterprise Server 12-SP2
SUSE Linux Enterprise High Availability 12-SP2
SUSE Linux Enterprise Desktop 12-SP2
______________________________________________________________________________

An update that solves two vulnerabilities and has one
errata is now available.

Description:

This update for samba fixes the following issues:

Security issues fixed:

- CVE-2017-14746: Use-after-free vulnerability (bsc#1060427).
- CVE-2017-15275: Server heap memory information leak (bsc#1063008).

Bug fixes:

- Update 'winbind expand groups' doc in smb.conf man page (bsc#1027593).


Patch Instructions:

To install this SUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:

- SUSE Linux Enterprise Software Development Kit 12-SP2:

zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-1919=1

- SUSE Linux Enterprise Server for Raspberry Pi 12-SP2:

zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1919=1

- SUSE Linux Enterprise Server 12-SP2:

zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1919=1

- SUSE Linux Enterprise High Availability 12-SP2:

zypper in -t patch SUSE-SLE-HA-12-SP2-2017-1919=1

- SUSE Linux Enterprise Desktop 12-SP2:

zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1919=1

To bring your system up-to-date, use "zypper patch".


Package List:

- SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 ppc64le s390x x86_64):

libsmbclient-devel-4.4.2-38.14.1
libwbclient-devel-4.4.2-38.14.1
samba-debuginfo-4.4.2-38.14.1
samba-debugsource-4.4.2-38.14.1

- SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64):

libdcerpc-binding0-4.4.2-38.14.1
libdcerpc-binding0-debuginfo-4.4.2-38.14.1
libdcerpc0-4.4.2-38.14.1
libdcerpc0-debuginfo-4.4.2-38.14.1
libndr-krb5pac0-4.4.2-38.14.1
libndr-krb5pac0-debuginfo-4.4.2-38.14.1
libndr-nbt0-4.4.2-38.14.1
libndr-nbt0-debuginfo-4.4.2-38.14.1
libndr-standard0-4.4.2-38.14.1
libndr-standard0-debuginfo-4.4.2-38.14.1
libndr0-4.4.2-38.14.1
libndr0-debuginfo-4.4.2-38.14.1
libnetapi0-4.4.2-38.14.1
libnetapi0-debuginfo-4.4.2-38.14.1
libsamba-credentials0-4.4.2-38.14.1
libsamba-credentials0-debuginfo-4.4.2-38.14.1
libsamba-errors0-4.4.2-38.14.1
libsamba-errors0-debuginfo-4.4.2-38.14.1
libsamba-hostconfig0-4.4.2-38.14.1
libsamba-hostconfig0-debuginfo-4.4.2-38.14.1
libsamba-passdb0-4.4.2-38.14.1
libsamba-passdb0-debuginfo-4.4.2-38.14.1
libsamba-util0-4.4.2-38.14.1
libsamba-util0-debuginfo-4.4.2-38.14.1
libsamdb0-4.4.2-38.14.1
libsamdb0-debuginfo-4.4.2-38.14.1
libsmbclient0-4.4.2-38.14.1
libsmbclient0-debuginfo-4.4.2-38.14.1
libsmbconf0-4.4.2-38.14.1
libsmbconf0-debuginfo-4.4.2-38.14.1
libsmbldap0-4.4.2-38.14.1
libsmbldap0-debuginfo-4.4.2-38.14.1
libtevent-util0-4.4.2-38.14.1
libtevent-util0-debuginfo-4.4.2-38.14.1
libwbclient0-4.4.2-38.14.1
libwbclient0-debuginfo-4.4.2-38.14.1
samba-4.4.2-38.14.1
samba-client-4.4.2-38.14.1
samba-client-debuginfo-4.4.2-38.14.1
samba-debuginfo-4.4.2-38.14.1
samba-debugsource-4.4.2-38.14.1
samba-libs-4.4.2-38.14.1
samba-libs-debuginfo-4.4.2-38.14.1
samba-winbind-4.4.2-38.14.1
samba-winbind-debuginfo-4.4.2-38.14.1

- SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (noarch):

samba-doc-4.4.2-38.14.1

- SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le s390x x86_64):

libdcerpc-binding0-4.4.2-38.14.1
libdcerpc-binding0-debuginfo-4.4.2-38.14.1
libdcerpc0-4.4.2-38.14.1
libdcerpc0-debuginfo-4.4.2-38.14.1
libndr-krb5pac0-4.4.2-38.14.1
libndr-krb5pac0-debuginfo-4.4.2-38.14.1
libndr-nbt0-4.4.2-38.14.1
libndr-nbt0-debuginfo-4.4.2-38.14.1
libndr-standard0-4.4.2-38.14.1
libndr-standard0-debuginfo-4.4.2-38.14.1
libndr0-4.4.2-38.14.1
libndr0-debuginfo-4.4.2-38.14.1
libnetapi0-4.4.2-38.14.1
libnetapi0-debuginfo-4.4.2-38.14.1
libsamba-credentials0-4.4.2-38.14.1
libsamba-credentials0-debuginfo-4.4.2-38.14.1
libsamba-errors0-4.4.2-38.14.1
libsamba-errors0-debuginfo-4.4.2-38.14.1
libsamba-hostconfig0-4.4.2-38.14.1
libsamba-hostconfig0-debuginfo-4.4.2-38.14.1
libsamba-passdb0-4.4.2-38.14.1
libsamba-passdb0-debuginfo-4.4.2-38.14.1
libsamba-util0-4.4.2-38.14.1
libsamba-util0-debuginfo-4.4.2-38.14.1
libsamdb0-4.4.2-38.14.1
libsamdb0-debuginfo-4.4.2-38.14.1
libsmbclient0-4.4.2-38.14.1
libsmbclient0-debuginfo-4.4.2-38.14.1
libsmbconf0-4.4.2-38.14.1
libsmbconf0-debuginfo-4.4.2-38.14.1
libsmbldap0-4.4.2-38.14.1
libsmbldap0-debuginfo-4.4.2-38.14.1
libtevent-util0-4.4.2-38.14.1
libtevent-util0-debuginfo-4.4.2-38.14.1
libwbclient0-4.4.2-38.14.1
libwbclient0-debuginfo-4.4.2-38.14.1
samba-4.4.2-38.14.1
samba-client-4.4.2-38.14.1
samba-client-debuginfo-4.4.2-38.14.1
samba-debuginfo-4.4.2-38.14.1
samba-debugsource-4.4.2-38.14.1
samba-libs-4.4.2-38.14.1
samba-libs-debuginfo-4.4.2-38.14.1
samba-winbind-4.4.2-38.14.1
samba-winbind-debuginfo-4.4.2-38.14.1

- SUSE Linux Enterprise Server 12-SP2 (s390x x86_64):

libdcerpc-binding0-32bit-4.4.2-38.14.1
libdcerpc-binding0-debuginfo-32bit-4.4.2-38.14.1
libdcerpc0-32bit-4.4.2-38.14.1
libdcerpc0-debuginfo-32bit-4.4.2-38.14.1
libndr-krb5pac0-32bit-4.4.2-38.14.1
libndr-krb5pac0-debuginfo-32bit-4.4.2-38.14.1
libndr-nbt0-32bit-4.4.2-38.14.1
libndr-nbt0-debuginfo-32bit-4.4.2-38.14.1
libndr-standard0-32bit-4.4.2-38.14.1
libndr-standard0-debuginfo-32bit-4.4.2-38.14.1
libndr0-32bit-4.4.2-38.14.1
libndr0-debuginfo-32bit-4.4.2-38.14.1
libnetapi0-32bit-4.4.2-38.14.1
libnetapi0-debuginfo-32bit-4.4.2-38.14.1
libsamba-credentials0-32bit-4.4.2-38.14.1
libsamba-credentials0-debuginfo-32bit-4.4.2-38.14.1
libsamba-errors0-32bit-4.4.2-38.14.1
libsamba-errors0-debuginfo-32bit-4.4.2-38.14.1
libsamba-hostconfig0-32bit-4.4.2-38.14.1
libsamba-hostconfig0-debuginfo-32bit-4.4.2-38.14.1
libsamba-passdb0-32bit-4.4.2-38.14.1
libsamba-passdb0-debuginfo-32bit-4.4.2-38.14.1
libsamba-util0-32bit-4.4.2-38.14.1
libsamba-util0-debuginfo-32bit-4.4.2-38.14.1
libsamdb0-32bit-4.4.2-38.14.1
libsamdb0-debuginfo-32bit-4.4.2-38.14.1
libsmbclient0-32bit-4.4.2-38.14.1
libsmbclient0-debuginfo-32bit-4.4.2-38.14.1
libsmbconf0-32bit-4.4.2-38.14.1
libsmbconf0-debuginfo-32bit-4.4.2-38.14.1
libsmbldap0-32bit-4.4.2-38.14.1
libsmbldap0-debuginfo-32bit-4.4.2-38.14.1
libtevent-util0-32bit-4.4.2-38.14.1
libtevent-util0-debuginfo-32bit-4.4.2-38.14.1
libwbclient0-32bit-4.4.2-38.14.1
libwbclient0-debuginfo-32bit-4.4.2-38.14.1
samba-client-32bit-4.4.2-38.14.1
samba-client-debuginfo-32bit-4.4.2-38.14.1
samba-libs-32bit-4.4.2-38.14.1
samba-libs-debuginfo-32bit-4.4.2-38.14.1
samba-winbind-32bit-4.4.2-38.14.1
samba-winbind-debuginfo-32bit-4.4.2-38.14.1

- SUSE Linux Enterprise Server 12-SP2 (noarch):

samba-doc-4.4.2-38.14.1

- SUSE Linux Enterprise High Availability 12-SP2 (ppc64le s390x x86_64):

ctdb-4.4.2-38.14.1
ctdb-debuginfo-4.4.2-38.14.1
samba-debuginfo-4.4.2-38.14.1
samba-debugsource-4.4.2-38.14.1

- SUSE Linux Enterprise Desktop 12-SP2 (x86_64):

libdcerpc-binding0-32bit-4.4.2-38.14.1
libdcerpc-binding0-4.4.2-38.14.1
libdcerpc-binding0-debuginfo-32bit-4.4.2-38.14.1
libdcerpc-binding0-debuginfo-4.4.2-38.14.1
libdcerpc0-32bit-4.4.2-38.14.1
libdcerpc0-4.4.2-38.14.1
libdcerpc0-debuginfo-32bit-4.4.2-38.14.1
libdcerpc0-debuginfo-4.4.2-38.14.1
libndr-krb5pac0-32bit-4.4.2-38.14.1
libndr-krb5pac0-4.4.2-38.14.1
libndr-krb5pac0-debuginfo-32bit-4.4.2-38.14.1
libndr-krb5pac0-debuginfo-4.4.2-38.14.1
libndr-nbt0-32bit-4.4.2-38.14.1
libndr-nbt0-4.4.2-38.14.1
libndr-nbt0-debuginfo-32bit-4.4.2-38.14.1
libndr-nbt0-debuginfo-4.4.2-38.14.1
libndr-standard0-32bit-4.4.2-38.14.1
libndr-standard0-4.4.2-38.14.1
libndr-standard0-debuginfo-32bit-4.4.2-38.14.1
libndr-standard0-debuginfo-4.4.2-38.14.1
libndr0-32bit-4.4.2-38.14.1
libndr0-4.4.2-38.14.1
libndr0-debuginfo-32bit-4.4.2-38.14.1
libndr0-debuginfo-4.4.2-38.14.1
libnetapi0-32bit-4.4.2-38.14.1
libnetapi0-4.4.2-38.14.1
libnetapi0-debuginfo-32bit-4.4.2-38.14.1
libnetapi0-debuginfo-4.4.2-38.14.1
libsamba-credentials0-32bit-4.4.2-38.14.1
libsamba-credentials0-4.4.2-38.14.1
libsamba-credentials0-debuginfo-32bit-4.4.2-38.14.1
libsamba-credentials0-debuginfo-4.4.2-38.14.1
libsamba-errors0-32bit-4.4.2-38.14.1
libsamba-errors0-4.4.2-38.14.1
libsamba-errors0-debuginfo-32bit-4.4.2-38.14.1
libsamba-errors0-debuginfo-4.4.2-38.14.1
libsamba-hostconfig0-32bit-4.4.2-38.14.1
libsamba-hostconfig0-4.4.2-38.14.1
libsamba-hostconfig0-debuginfo-32bit-4.4.2-38.14.1
libsamba-hostconfig0-debuginfo-4.4.2-38.14.1
libsamba-passdb0-32bit-4.4.2-38.14.1
libsamba-passdb0-4.4.2-38.14.1
libsamba-passdb0-debuginfo-32bit-4.4.2-38.14.1
libsamba-passdb0-debuginfo-4.4.2-38.14.1
libsamba-util0-32bit-4.4.2-38.14.1
libsamba-util0-4.4.2-38.14.1
libsamba-util0-debuginfo-32bit-4.4.2-38.14.1
libsamba-util0-debuginfo-4.4.2-38.14.1
libsamdb0-32bit-4.4.2-38.14.1
libsamdb0-4.4.2-38.14.1
libsamdb0-debuginfo-32bit-4.4.2-38.14.1
libsamdb0-debuginfo-4.4.2-38.14.1
libsmbclient0-32bit-4.4.2-38.14.1
libsmbclient0-4.4.2-38.14.1
libsmbclient0-debuginfo-32bit-4.4.2-38.14.1
libsmbclient0-debuginfo-4.4.2-38.14.1
libsmbconf0-32bit-4.4.2-38.14.1
libsmbconf0-4.4.2-38.14.1
libsmbconf0-debuginfo-32bit-4.4.2-38.14.1
libsmbconf0-debuginfo-4.4.2-38.14.1
libsmbldap0-32bit-4.4.2-38.14.1
libsmbldap0-4.4.2-38.14.1
libsmbldap0-debuginfo-32bit-4.4.2-38.14.1
libsmbldap0-debuginfo-4.4.2-38.14.1
libtevent-util0-32bit-4.4.2-38.14.1
libtevent-util0-4.4.2-38.14.1
libtevent-util0-debuginfo-32bit-4.4.2-38.14.1
libtevent-util0-debuginfo-4.4.2-38.14.1
libwbclient0-32bit-4.4.2-38.14.1
libwbclient0-4.4.2-38.14.1
libwbclient0-debuginfo-32bit-4.4.2-38.14.1
libwbclient0-debuginfo-4.4.2-38.14.1
samba-4.4.2-38.14.1
samba-client-32bit-4.4.2-38.14.1
samba-client-4.4.2-38.14.1
samba-client-debuginfo-32bit-4.4.2-38.14.1
samba-client-debuginfo-4.4.2-38.14.1
samba-debuginfo-4.4.2-38.14.1
samba-debugsource-4.4.2-38.14.1
samba-libs-32bit-4.4.2-38.14.1
samba-libs-4.4.2-38.14.1
samba-libs-debuginfo-32bit-4.4.2-38.14.1
samba-libs-debuginfo-4.4.2-38.14.1
samba-winbind-32bit-4.4.2-38.14.1
samba-winbind-4.4.2-38.14.1
samba-winbind-debuginfo-32bit-4.4.2-38.14.1
samba-winbind-debuginfo-4.4.2-38.14.1

- SUSE Linux Enterprise Desktop 12-SP2 (noarch):

samba-doc-4.4.2-38.14.1


References:

https://www.suse.com/security/cve/CVE-2017-14746.html
https://www.suse.com/security/cve/CVE-2017-15275.html
https://bugzilla.suse.com/1027593
https://bugzilla.suse.com/1060427
https://bugzilla.suse.com/1063008

SUSE-SU-2017:3106-1: important: Security update for kernel-firmware

SUSE Security Update: Security update for kernel-firmware
______________________________________________________________________________

Announcement ID: SUSE-SU-2017:3106-1
Rating: important
References: #1066295
Cross-References: CVE-2017-13080 CVE-2017-13081
Affected Products:
SUSE Linux Enterprise Server for Raspberry Pi 12-SP2
SUSE Linux Enterprise Server 12-SP3
SUSE Linux Enterprise Server 12-SP2
SUSE Linux Enterprise Desktop 12-SP3
SUSE Linux Enterprise Desktop 12-SP2
SUSE Container as a Service Platform ALL
______________________________________________________________________________

An update that fixes two vulnerabilities is now available.

Description:

This update for kernel-firmware fixes the following issues:

- Update Intel WiFi firmwares for the 3160, 7260 and 7265 adapters.

Security issues fixed are part of the "KRACK" attacks affecting the
firmware:

- CVE-2017-13080: The reinstallation of the Group Temporal key could be
used for replay attacks (bsc#1066295):
- CVE-2017-13081: The reinstallation of the Integrity Group Temporal key
could be used for replay attacks (bsc#1066295):


Patch Instructions:

To install this SUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:

- SUSE Linux Enterprise Server for Raspberry Pi 12-SP2:

zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1918=1

- SUSE Linux Enterprise Server 12-SP3:

zypper in -t patch SUSE-SLE-SERVER-12-SP3-2017-1918=1

- SUSE Linux Enterprise Server 12-SP2:

zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1918=1

- SUSE Linux Enterprise Desktop 12-SP3:

zypper in -t patch SUSE-SLE-DESKTOP-12-SP3-2017-1918=1

- SUSE Linux Enterprise Desktop 12-SP2:

zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1918=1

- SUSE Container as a Service Platform ALL:

zypper in -t patch SUSE-CAASP-ALL-2017-1918=1

To bring your system up-to-date, use "zypper patch".


Package List:

- SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (noarch):

kernel-firmware-20170530-21.13.1

- SUSE Linux Enterprise Server 12-SP3 (noarch):

kernel-firmware-20170530-21.13.1
ucode-amd-20170530-21.13.1

- SUSE Linux Enterprise Server 12-SP2 (noarch):

kernel-firmware-20170530-21.13.1
ucode-amd-20170530-21.13.1

- SUSE Linux Enterprise Desktop 12-SP3 (noarch):

kernel-firmware-20170530-21.13.1
ucode-amd-20170530-21.13.1

- SUSE Linux Enterprise Desktop 12-SP2 (noarch):

kernel-firmware-20170530-21.13.1
ucode-amd-20170530-21.13.1

- SUSE Container as a Service Platform ALL (noarch):

kernel-firmware-20170530-21.13.1


References:

https://www.suse.com/security/cve/CVE-2017-13080.html
https://www.suse.com/security/cve/CVE-2017-13081.html
https://bugzilla.suse.com/1066295