Описание
ELSA-2013-0747: kernel security and bug fix update (MODERATE)
kernel [2.6.18-348.4.1]
- [virt] xen-netback: backports (Andrew Jones) [910884 910885] {CVE-2013-0216}
- [virt] xen-netback: netif_schedulable should take a netif (Andrew Jones) [910884 910885] {CVE-2013-0216}
- [virt] pciback: rate limit error mess from pciback_enable_msi() (Igor Mammedov) [910876 910877] {CVE-2013-0231}
- [net] be2net: remove BUG_ON() in be_mcc_compl_is_new() (Ivan Vecera) [923910 907524]
- [net] ipv4: Update MTU to all related cache entries (Amerigo Wang) [923353 905190]
- [net] annotate rt_hash_code() users (Amerigo Wang) [923353 905190]
- [net] xfrm_user: fix info leak in copy_to_user_state() (Thomas Graf) [922426 922427] {CVE-2012-6537}
- [net] xfrm_user: fix info leak in copy_to_user_policy() (Thomas Graf) [922426 922427] {CVE-2012-6537}
- [net] xfrm_user: fix info leak in copy_to_user_tmpl() (Thomas Graf) [922426 922427] {CVE-2012-6537}
- [net] atm: fix info leak in getsockopt(SO_ATMPVC) (Thomas Graf) [922384 922385] {CVE-2012-6546}
- [net] atm: fix info leak via getsockname() (Thomas Graf) [922384 922385] {CVE-2012-6546}
- [net] tun: fix ioctl() based info leaks (Thomas Graf) [922348 922349] {CVE-2012-6547}
- [net] llc, zero sockaddr_llc struct (Thomas Graf) [922327 922329] {CVE-2012-6542}
- [net] llc: fix info leak via getsockname() (Thomas Graf) [922327 922329] {CVE-2012-6542}
- [net] xfrm_user: return error pointer instead of NULL (Thomas Graf) [919386 919387] {CVE-2013-1826}
- [net] ixgbevf: allocate room for mailbox MSI-X interrupt's name (Laszlo Ersek) [924134 862862]
- [fs] knfsd: allow nfsd READDIR to return 64bit cookies (Niels de Vos) [924087 918952]
Обновленные пакеты
Oracle Linux 5
Oracle Linux ia64
kernel
2.6.18-348.4.1.el5
kernel-debug
2.6.18-348.4.1.el5
kernel-debug-devel
2.6.18-348.4.1.el5
kernel-devel
2.6.18-348.4.1.el5
kernel-doc
2.6.18-348.4.1.el5
kernel-headers
2.6.18-348.4.1.el5
kernel-xen
2.6.18-348.4.1.el5
kernel-xen-devel
2.6.18-348.4.1.el5
ocfs2-2.6.18-348.4.1.el5
1.4.10-1.el5
ocfs2-2.6.18-348.4.1.el5debug
1.4.10-1.el5
ocfs2-2.6.18-348.4.1.el5xen
1.4.10-1.el5
oracleasm-2.6.18-348.4.1.el5
2.0.5-1.el5
oracleasm-2.6.18-348.4.1.el5debug
2.0.5-1.el5
oracleasm-2.6.18-348.4.1.el5xen
2.0.5-1.el5
Oracle Linux x86_64
kernel
2.6.18-348.4.1.el5
kernel-debug
2.6.18-348.4.1.el5
kernel-debug-devel
2.6.18-348.4.1.el5
kernel-devel
2.6.18-348.4.1.el5
kernel-doc
2.6.18-348.4.1.el5
kernel-headers
2.6.18-348.4.1.el5
kernel-xen
2.6.18-348.4.1.el5
kernel-xen-devel
2.6.18-348.4.1.el5
ocfs2-2.6.18-348.4.1.el5
1.4.10-1.el5
ocfs2-2.6.18-348.4.1.el5debug
1.4.10-1.el5
ocfs2-2.6.18-348.4.1.el5xen
1.4.10-1.el5
oracleasm-2.6.18-348.4.1.el5
2.0.5-1.el5
oracleasm-2.6.18-348.4.1.el5debug
2.0.5-1.el5
oracleasm-2.6.18-348.4.1.el5xen
2.0.5-1.el5
Oracle Linux i386
kernel
2.6.18-348.4.1.el5
kernel-PAE
2.6.18-348.4.1.el5
kernel-PAE-devel
2.6.18-348.4.1.el5
kernel-debug
2.6.18-348.4.1.el5
kernel-debug-devel
2.6.18-348.4.1.el5
kernel-devel
2.6.18-348.4.1.el5
kernel-doc
2.6.18-348.4.1.el5
kernel-headers
2.6.18-348.4.1.el5
kernel-xen
2.6.18-348.4.1.el5
kernel-xen-devel
2.6.18-348.4.1.el5
ocfs2-2.6.18-348.4.1.el5
1.4.10-1.el5
ocfs2-2.6.18-348.4.1.el5PAE
1.4.10-1.el5
ocfs2-2.6.18-348.4.1.el5debug
1.4.10-1.el5
ocfs2-2.6.18-348.4.1.el5xen
1.4.10-1.el5
oracleasm-2.6.18-348.4.1.el5
2.0.5-1.el5
oracleasm-2.6.18-348.4.1.el5PAE
2.0.5-1.el5
oracleasm-2.6.18-348.4.1.el5debug
2.0.5-1.el5
oracleasm-2.6.18-348.4.1.el5xen
2.0.5-1.el5
Ссылки на источники
Связанные уязвимости
ELSA-2013-0747-1: kernel security and bug fix update (MODERATE)
The pciback_enable_msi function in the PCI backend driver (drivers/xen/pciback/conf_space_capability_msi.c) in Xen for the Linux kernel 2.6.18 and 3.8 allows guest OS users with PCI device access to cause a denial of service via a large number of kernel log messages. NOTE: some of these details are obtained from third party information.
The pciback_enable_msi function in the PCI backend driver (drivers/xen/pciback/conf_space_capability_msi.c) in Xen for the Linux kernel 2.6.18 and 3.8 allows guest OS users with PCI device access to cause a denial of service via a large number of kernel log messages. NOTE: some of these details are obtained from third party information.
The pciback_enable_msi function in the PCI backend driver (drivers/xen/pciback/conf_space_capability_msi.c) in Xen for the Linux kernel 2.6.18 and 3.8 allows guest OS users with PCI device access to cause a denial of service via a large number of kernel log messages. NOTE: some of these details are obtained from third party information.
The pciback_enable_msi function in the PCI backend driver (drivers/xen ...