Upstream information
Description
net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass intended access restrictions via packets with disallowed port numbers.SUSE information
Overall state of this security issue: Does not affect SUSE products
Note from the SUSE Security Team on the kernel-default package
SUSE will no longer fix all CVEs in the Linux Kernel anymore, but declare some bug classes as won't fix. Please refer to TID 21496 for more details.Note from the SUSE Security Team on the xen package
This issue likely only affects the XEN hypervisor itself, unless otherwise stated. The userland utilities in -tools and libraries in -libs are shipped together with the xen hypervisor as they are built from one source and do not contain hypervisor specific fixes. SUSE Bugzilla entries: 857643 [RESOLVED / FIXED], 913059 [RESOLVED / FIXED]SUSE Security Advisories:
- SUSE-SU-2015:0529-1, published Wed Mar 18 15:04:55 MDT 2015
- SUSE-SU-2015:0581-1, published Tue Mar 24 00:04:46 MDT 2015
- SUSE-SU-2015:0652-1, published Wed Apr 1 18:06:32 MDT 2015
- SUSE-SU-2015:0736-1, published Mon Apr 20 13:04:58 MDT 2015
- TID7016668, published Tue Aug 18 01:08:01 CEST 2015
- openSUSE-SU-2015:0713-1, published Fri Dec 8 15:48:33 2023
- openSUSE-SU-2015:0714-1, published Fri Dec 8 15:48:33 2023
List of released packages
Product(s) | Fixed package version(s) | References |
---|---|---|
SUSE Liberty Linux 7 |
| Patchnames: RHSA-2015:0290 |
SUSE Linux Enterprise Desktop 11 SP3 |
| Patchnames: sledsp3-kernel |
SUSE Linux Enterprise Desktop 11 SP4 SUSE Linux Enterprise Server for SAP Applications 11 SP4 SUSE Linux Enterprise Software Development Kit 11 SP4 |
| Patchnames: SUSE Linux Enterprise Software Development Kit 11 SP4 GA kernel-docs-3.0.101-63.1 |
SUSE Linux Enterprise Desktop 12 SP1 |
| Patchnames: SUSE Linux Enterprise Desktop 12 SP1 GA kernel-default-3.12.49-11.1 SUSE Linux Enterprise Software Development Kit 12 SP1 GA kernel-docs-3.12.49-11.1 SUSE Linux Enterprise Workstation Extension 12 SP1 GA kernel-default-extra-3.12.49-11.1 |
SUSE Linux Enterprise Desktop 12 |
| Patchnames: SUSE-SLE-DESKTOP-12-2015-130 SUSE-SLE-SDK-12-2015-130 SUSE-SLE-WE-12-2015-130 |
SUSE Linux Enterprise High Availability Extension 11 SP3 |
| Patchnames: slehasp3-kernel |
SUSE Linux Enterprise High Performance Computing 12 SUSE Linux Enterprise Module for Public Cloud 12 SUSE Linux Enterprise Server 12 SP3 SUSE Linux Enterprise Server 12 SP4 SUSE Linux Enterprise Server 12 SP5 SUSE Linux Enterprise Server for SAP Applications 12 SP3 SUSE Linux Enterprise Server for SAP Applications 12 SP4 SUSE Linux Enterprise Server for SAP Applications 12 SP5 |
| Patchnames: SUSE-SLE-Module-Public-Cloud-12-2015-130 |
SUSE Linux Enterprise Live Patching 12 | Patchnames: SUSE-SLE-Live-Patching-12-2015-130 | |
SUSE Linux Enterprise Real Time 11 SP3 |
| Patchnames: slertesp3-kernel |
SUSE Linux Enterprise Server 11 SP1-LTSS |
| Patchnames: slessp1-kernel |
SUSE Linux Enterprise Server 11 SP3 SUSE Linux Enterprise Server for SAP Applications 11 SP3 |
| Patchnames: slessp3-kernel |
SUSE Linux Enterprise Server 11 SP4 |
| Patchnames: SUSE Linux Enterprise Server 11 SP4 GA kernel-default-3.0.101-63.1 SUSE Linux Enterprise Software Development Kit 11 SP4 GA kernel-docs-3.0.101-63.1 |
SUSE Linux Enterprise Server 12 SP1 |
| Patchnames: SUSE Linux Enterprise Server 12 SP1 GA kernel-default-3.12.49-11.1 SUSE Linux Enterprise Software Development Kit 12 SP1 GA kernel-docs-3.12.49-11.1 SUSE Linux Enterprise Workstation Extension 12 SP1 GA kernel-default-extra-3.12.49-11.1 |
SUSE Linux Enterprise Server 12 SUSE Linux Enterprise Server for SAP Applications 12 |
| Patchnames: SUSE-SLE-Module-Public-Cloud-12-2015-130 SUSE-SLE-SDK-12-2015-130 SUSE-SLE-SERVER-12-2015-130 SUSE-SLE-WE-12-2015-130 |
SUSE Linux Enterprise Server for SAP Applications 12 SP1 |
| Patchnames: SUSE Linux Enterprise Software Development Kit 12 SP1 GA kernel-docs-3.12.49-11.1 SUSE Linux Enterprise Workstation Extension 12 SP1 GA kernel-default-extra-3.12.49-11.1 |
SUSE Linux Enterprise Software Development Kit 12 SP1 |
| Patchnames: SUSE Linux Enterprise Software Development Kit 12 SP1 GA kernel-docs-3.12.49-11.1 |
SUSE Linux Enterprise Software Development Kit 12 |
| Patchnames: SUSE-SLE-SDK-12-2015-130 |
SUSE Linux Enterprise Workstation Extension 12 SP1 |
| Patchnames: SUSE Linux Enterprise Workstation Extension 12 SP1 GA kernel-default-extra-3.12.49-11.1 |
SUSE Linux Enterprise Workstation Extension 12 |
| Patchnames: SUSE-SLE-WE-12-2015-130 |
SUSE Timeline for this CVE
CVE page created: Mon Jan 6 19:15:16 2014CVE page last modified: Mon Feb 3 11:21:10 2025