Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2011-2015

Опубликовано: 11 мая 2011
Источник: oracle-oval
Платформа: Oracle Linux 5
Платформа: Oracle Linux 6

Описание

ELSA-2011-2015: Oracle Linux 6 Unbreakable Enterprise kernel security fix update (IMPORTANT)

[2.6.32-100.28.15.el6]

  • sctp: fix to calc the INIT/INIT-ACK chunk length correctly is set {CVE-2011-1573}
  • dccp: fix oops on Reset after close {CVE-2011-1093}
  • bridge: netfilter: fix information leak {CVE-2011-1080}
  • Bluetooth: bnep: fix buffer overflow {CVE-2011-1079}
  • net: don't allow CAP_NET_ADMIN to load non-netdev kernel modules {CVE-2011-1019}
  • ipip: add module alias for tunl0 tunnel device
  • gre: add module alias for gre0 tunnel device
  • drm/radeon/kms: check AA resolve registers on r300 {CVE-2011-1016}
  • drm/radeon: fix regression with AA resolve checking {CVE-2011-1016}
  • drm: fix unsigned vs signed comparison issue in modeset ctl ioctl {CVE-2011-1013}
  • proc: protect mm start_code/end_code in /proc/pid/stat {CVE-2011-0726}
  • ALSA: caiaq - Fix possible string-buffer overflow {CVE-2011-0712}
  • xfs: zero proper structure size for geometry calls {CVE-2011-0711}
  • xfs: prevent leaking uninitialized stack memory in FSGEOMETRY_V1 {CVE-2011-0711}
  • ima: fix add LSM rule bug {CVE-2011-0006}
  • IB/uverbs: Handle large number of entries in poll CQ {CVE-2010-4649, CVE-2011-1044}
  • CAN: Use inode instead of kernel address for /proc file {CVE-2010-4565}

[2.6.32-100.28.14.el6]

  • IB/qib: fix qib compile warning.
  • IB/core: Allow device-specific per-port sysfs files.
  • dm crypt: add plain64 iv.
  • firmware: add firmware for qib.
  • Infiniband: Add QLogic PCIe QLE InfiniBand host channel adapters support.

Обновленные пакеты

Oracle Linux 5

Oracle Linux x86_64

kernel-uek

2.6.32-100.28.15.el5

kernel-uek-debug

2.6.32-100.28.15.el5

kernel-uek-debug-devel

2.6.32-100.28.15.el5

kernel-uek-devel

2.6.32-100.28.15.el5

kernel-uek-doc

2.6.32-100.28.15.el5

kernel-uek-firmware

2.6.32-100.28.15.el5

kernel-uek-headers

2.6.32-100.28.15.el5

ofa-2.6.32-100.28.15.el5

1.5.1-4.0.28

ofa-2.6.32-100.28.15.el5debug

1.5.1-4.0.28

Oracle Linux 6

Oracle Linux x86_64

kernel-uek

2.6.32-100.28.15.el6

kernel-uek-debug

2.6.32-100.28.15.el6

kernel-uek-debug-devel

2.6.32-100.28.15.el6

kernel-uek-devel

2.6.32-100.28.15.el6

kernel-uek-doc

2.6.32-100.28.15.el6

kernel-uek-firmware

2.6.32-100.28.15.el6

kernel-uek-headers

2.6.32-100.28.15.el6

Связанные уязвимости

oracle-oval
около 14 лет назад

ELSA-2011-0498: kernel security, bug fix, and enhancement update (IMPORTANT)

ubuntu
почти 13 лет назад

The bnep_sock_ioctl function in net/bluetooth/bnep/sock.c in the Linux kernel before 2.6.39 does not ensure that a certain device field ends with a '\0' character, which allows local users to obtain potentially sensitive information from kernel stack memory, or cause a denial of service (BUG and system crash), via a BNEPCONNADD command.

redhat
больше 14 лет назад

The bnep_sock_ioctl function in net/bluetooth/bnep/sock.c in the Linux kernel before 2.6.39 does not ensure that a certain device field ends with a '\0' character, which allows local users to obtain potentially sensitive information from kernel stack memory, or cause a denial of service (BUG and system crash), via a BNEPCONNADD command.

nvd
почти 13 лет назад

The bnep_sock_ioctl function in net/bluetooth/bnep/sock.c in the Linux kernel before 2.6.39 does not ensure that a certain device field ends with a '\0' character, which allows local users to obtain potentially sensitive information from kernel stack memory, or cause a denial of service (BUG and system crash), via a BNEPCONNADD command.

debian
почти 13 лет назад

The bnep_sock_ioctl function in net/bluetooth/bnep/sock.c in the Linux ...