Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2010-0998

Опубликовано: 20 дек. 2010
Источник: oracle-oval
Платформа: Oracle Linux 5

Описание

ELSA-2010-0998: kvm security and bug fix update (LOW)

[kvm-83-164.0.1.el5_5.30]

  • Added kvm-add-oracle-workaround-for-libvirt-bug.patch to replace RHEL with OEL
  • Added kvm-Introduce-oel-machine-type.patch so that OEL is a recognized VM

[kvm-83-164.el5_5.30]

  • Revert the bz#661397 patches as they are not enough
    • kvm-kernel-Revert-KVM-VMX-Return-0-from-a-failed-VMREAD.patch [bz#661397]
    • kvm-kernel-Revert-KVM-Don-t-spin-on-virt-instruction-faults-dur.patch [bz#661397]
  • Related: bz#661397 (reboot(RB_AUTOBOOT) fails if kvm instance is running)
  • kvm-kernel-KVM-fix-AMD-initial-TSC-offset-problems-additional-f.patch [bz#656984]
  • Resolves: bz#656984 (TSC offset of virtual machines is not initialized correctly by 'kvm_amd' kernel module.)

[kvm-83-164.el5_5.29]

  • kvm-kernel-KVM-Don-t-spin-on-virt-instruction-faults-during-reb.patch [bz#661397]
  • kvm-kernel-KVM-VMX-Return-0-from-a-failed-VMREAD.patch [bz#661397]
  • Resolves: bz#661397 (reboot(RB_AUTOBOOT) fails if kvm instance is running)

[kvm-83-164.el5_5.28]

  • kvm-implement-dummy-PnP-support.patch [bz#659850]
  • kvm-load-registers-after-restoring-pvclock-msrs.patch [bz#660239]
  • Resolves: bz#659850 (If VM boot seq. is set up as nc (PXE then disk) the VM is always stuck on trying to PXE boot)
  • Resolves: bz#660239 (clock drift when migrating a guest between mis-matched CPU clock speed)

[kvm-83-164.el5_5.27]

  • kvm-kernel-KVM-fix-AMD-initial-TSC-offset-problems.patch [bz#656984]
  • Resolves: bz#656984 (TSC offset of virtual machines is not initialized correctly by 'kvm_amd' kernel module.)

[kvm-83-164.el5_5.26]

  • Updated kversion to 2.6.18-194.26.1.el5 to match build root
  • kvm-kernel-KVM-x86-fix-information-leak-to-userland.patch [bz#649832]
  • Resolves: bz#649832 (CVE-2010-3881 kvm: arch/x86/kvm/x86.c: reading uninitialized stack memory [5.5.z])
  • CVE: CVE-2010-3881

Обновленные пакеты

Oracle Linux 5

Oracle Linux x86_64

kmod-kvm

83-164.0.1.el5_5.30

kvm

83-164.0.1.el5_5.30

kvm-qemu-img

83-164.0.1.el5_5.30

kvm-tools

83-164.0.1.el5_5.30

Связанные CVE

Связанные уязвимости

ubuntu
больше 14 лет назад

arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on the /dev/kvm device.

redhat
больше 14 лет назад

arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on the /dev/kvm device.

nvd
больше 14 лет назад

arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on the /dev/kvm device.

debian
больше 14 лет назад

arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initia ...

github
около 3 лет назад

arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on the /dev/kvm device.

Уязвимость ELSA-2010-0998