I am in the process of testing SLES 12 SP1 and have found that the network security scanner Qualys (www.qualys.com) detects an older version of the kernel ( lower than 3.14.9/3.15.2 ) and thinks the kernel is vulnerable to the LZO memory Corruption Vulnerability (QID 122360 ). I have not tested to see if the kernel is actually vulnerable but i am pretty confident it’s not and that SUSE has back ported the kernel without that vulnerability. The problem is that Qualys, being the sticklers that they are want a published website from SUSE that states the kernel is not vulnerable. Here’s where it get’s a bit tricky. The vulnerability was published (July 2014) before the release date of SLES 12 (October 2014) and there’s not going to be a website that details that the kernel has been back ported. Sigh… That being said, is there someone out there that can reference a doc that states SLES 12 is not vulnerable to this?
I am in the process of testing SLES 12 SP1 and have found that the network security scanner Qualys (www.qualys.com) detects an older version of the kernel ( lower than 3.14.9/3.15.2 ) and thinks the kernel is vulnerable to the LZO memory Corruption Vulnerability (QID 122360 ). I have not tested to see if the kernel is actually vulnerable but i am pretty confident it’s not and that SUSE has back ported the kernel without that vulnerability. The problem is that Qualys, being the sticklers that they are want a published website from SUSE that states the kernel is not vulnerable. Here’s where it get’s a bit tricky. The vulnerability was published (July 2014) before the release date of SLES 12 (October 2014) and there’s not going to be a website that details that the kernel has been back ported. Sigh… That being said, is there someone out there that can reference a doc that states SLES 12 is not vulnerable to this?
Thanks![/QUOTE]
Hi
Do you have a CVE reference? If so you can use the CVE as a search reference at https://bugzilla.suse.com/ or grep for it in the changelogs (rpm -qa --changelog | grep “CVE…”) or have a look at https://www.suse.com/support/update/
[QUOTE=malcolmlewis;31523]Hi
Do you have a CVE reference? If so you can use the CVE as a search reference at https://bugzilla.suse.com/ or grep for it in the changelogs (rpm -qa --changelog | grep “CVE…”) or have a look at https://www.suse.com/support/update/[/QUOTE]
That’s the problem. There is no CVE since SLES 12 was released months after the CVE was released. Yes, i have checked the support site and can only find references to SLES 11 and the fix.