This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Is UTM 9 affected by CVE-2016-10229?

CVE-2016-10229 is a remotely executable Linux kernel vulnerability. I would like to know if UTM 9 is vulnerable (evidently some kernel configurations aren't as RHEL 7 isn't), and if so, when should we see an update remedying this?



This thread was automatically locked due to age.
Parents
  • As far as I know UTM is still based on SLES. Here is their advisory and kernel 3.12.53 and above seems to be fixed. https://www.suse.com/security/cve/CVE-2016-10229/

    On my 9.411 install my kernel version is 3.12.58-0.247785862.g17c1041.rb7-smp64

  • While UTM is based on SLES, the kernel is custom I believe. i.e. Sophos builds and maintains their own kernel with it's own unique build features and tweaks. So, whether or not SLES is vulnerable isn't pertinent.

    I can obtain the kernel build options from /boot, however it isn't clear from that whether or not udp.c is patched to remove this vulnerability as it is definitely present in the kernel upstream from SUSE upon which 3.12.58 is based. So, just because the kernel version on UTM 9.441 states the kernel version is > 3.12.53, doesn't mean it is definitely free of this vulnerability. I would hope Sophos would put out info as to the status of UTM vs CVE-2016-10229, especially as a remote code execution vulnerability in the kernel is a big deal.

Reply
  • While UTM is based on SLES, the kernel is custom I believe. i.e. Sophos builds and maintains their own kernel with it's own unique build features and tweaks. So, whether or not SLES is vulnerable isn't pertinent.

    I can obtain the kernel build options from /boot, however it isn't clear from that whether or not udp.c is patched to remove this vulnerability as it is definitely present in the kernel upstream from SUSE upon which 3.12.58 is based. So, just because the kernel version on UTM 9.441 states the kernel version is > 3.12.53, doesn't mean it is definitely free of this vulnerability. I would hope Sophos would put out info as to the status of UTM vs CVE-2016-10229, especially as a remote code execution vulnerability in the kernel is a big deal.

Children