CVE-2017-2636 mitigation?

Trying to get some feedback on whether or not the redhat suggested mitigation for this CVE will work the same on SLES 11sp4 and SLES 12sp2, I think it should, but would like some confirmation or feedback. I tried searching but found no specific references to SLES.

echo “install n_hdlc /bin/true” >> /etc/modprobe.d/disable-n_hdlc.conf

reboot

Thanks,
Matt

Hi
There is work in progress for this;
https://bugzilla.suse.com/show_bug.cgi?id=1027565

Add a comment to ask if the fix will be backported to SLE 11 SP4.

FYI, you can search for CVE’s in bugzilla :wink:

On 28/03/17 16:14, skunkboy wrote:
[color=blue]

Trying to get some feedback on whether or not the redhat suggested
mitigation for this CVE will work the same on SLES 11sp4 and SLES 12sp2,
I think it should, but would like some confirmation or feedback. I
tried searching but found no specific references to SLES.

echo “install n_hdlc /bin/true” >> /etc/modprobe.d/disable-n_hdlc.conf[/color]

I think this should also work with SUSE Linux Enterprise Server.

FYI updates for currently supported releases are either in QA or planned

HTH.

Simon
SUSE Knowledge Partner


If you find this post helpful and are logged into the web interface,
please show your appreciation and click on the star below. Thanks.

Hey,

I know they are working on new releases to address this, but due to my patch schedule I might need the mitigation unless the updates come out very soon… :slight_smile:

Matt

skunkboy Wrote in message:
[color=blue]

I know they are working on new releases to address this, but due to my
patch schedule I might need the mitigation unless the updates come out
very soon… :)[/color]

Updated kernel packages are now available for SLES12 SP2 but not
yet for SLES11 SP4.

HTH.

Simon Flood
SUSE Knowledge Partner

----Android NewsGroup Reader----
http://usenet.sinaapp.com/