SLES 12 and dirty cow

Hi,

i have a SLES 12 64bit system. On this webpage there is no information to SLES 12, just to SLES 12 LTSS: https://www.suse.com/de-de/security/cve/CVE-2016-5195.html
zypper up offers a lot of packages, among others kernel-default-4.1.12-1.1
Is the patch included in this kernel ? Currently i’m running 3.12.43-52.6-default.

Bernd

Hi
SLES 12 has been out of general support for awhile, so unless you have LTSS I don’t think you will see a fix.

You must have some non-standard repos active if your seeing a 4.1 kernel and likely to break your system if it’s installed.

Hi Malcom,

and if i update the system to SP1 (or maybe to SP2) ?

Bernd

Hi
Yes, it’s fixed in SP1;

cat /etc/os-release
NAME="SLES"
VERSION="12-SP1"
VERSION_ID="12.1"
PRETTY_NAME="SUSE Linux Enterprise Server 12 SP1"
ID="sles"
ANSI_COLOR="0;32"
CPE_NAME="cpe:/o:suse:sles:12:sp1"

uname -a
Linux fozzie-bear 3.12.62-60.64.8-default #1 SMP Tue Oct 18 12:21:38
UTC 2016 (42e0a66) x86_64 x86_64 x86_64 GNU/Linux

rpm -qa --changelog kernel-default|grep CVE-2016-5195 -
patches.fixes/mm-remove-gup_flags-FOLL_WRITE-games-from-__get_user_pages.patch:
(bnc1004418, CVE-2016-5195).


Cheers Malcolm °¿° LFCS, SUSE Knowledge Partner (Linux Counter #276890)
openSUSE Leap 42.1|GNOME 3.16.2|4.1.34-33-default
If you find this post helpful and are logged into the web interface,
please show your appreciation and click on the star below… Thanks!