Описание
ELSA-2015-1137: kernel security and bug fix update (IMPORTANT)
[3.10.0-229.7.2]
- Oracle Linux certificates (Alexey Petrenko)
[3.10.0-229.7.2]
- [fs] pipe: fix pipe corruption and iovec overrun on partial copy (Seth Jennings) [1202861 1198843] {CVE-2015-1805}
[3.10.0-229.7.1]
- [scsi] storvsc: get rid of overly verbose warning messages (Vitaly Kuznetsov) [1215770 1206437]
- [scsi] storvsc: force discovery of LUNs that may have been removed (Vitaly Kuznetsov) [1215770 1206437]
- [scsi] storvsc: in responce to a scan event, scan the host (Vitaly Kuznetsov) [1215770 1206437]
- [scsi] storvsc: NULL pointer dereference fix (Vitaly Kuznetsov) [1215770 1206437]
- [virtio] defer config changed notifications (David Gibson) [1220278 1196009]
- [virtio] unify config_changed handling (David Gibson) [1220278 1196009]
- [x86] kernel: Remove a bogus 'ret_from_fork' optimization (Mateusz Guzik) [1209234 1209235] {CVE-2015-2830}
- [kernel] futex: Mention key referencing differences between shared and private futexes (Larry Woodman) [1219169 1205862]
- [kernel] futex: Ensure get_futex_key_refs() always implies a barrier (Larry Woodman) [1219169 1205862]
- [scsi] megaraid_sas: revert: Add release date and update driver version (Tomas Henzl) [1216213 1207175]
- [kernel] module: set nx before marking module MODULE_STATE_COMING (Hendrik Brueckner) [1214788 1196977]
- [kernel] module: Clean up ro/nx after early module load failures (Pratyush Anand) [1214403 1202866]
- [drm] radeon: fix kernel segfault in hwmonitor (Jerome Glisse) [1213467 1187817]
- [fs] btrfs: make xattr replace operations atomic (Eric Sandeen) [1205086 1205873]
- [x86] mm: Linux stack ASLR implementation (Jacob Tanenbaum) [1195684 1195685] {CVE-2015-1593}
- [net] netfilter: nf_tables: fix flush ruleset chain dependencies (Jiri Pirko) [1192880 1192881] {CVE-2015-1573}
- [fs] isofs: Fix unchecked printing of ER records (Mateusz Guzik) [1180482 1180483] {CVE-2014-9584}
- [security] keys: memory corruption or panic during key garbage collection (Jacob Tanenbaum) [1179851 1179852] {CVE-2014-9529}
- [fs] isofs: infinite loop in CE record entries (Jacob Tanenbaum) [1175246 1175248] {CVE-2014-9420}
[3.10.0-229.6.1]
- [net] tcp: abort orphan sockets stalling on zero window probes (Florian Westphal) [1215924 1151756]
- [x86] crypto: aesni - fix memory usage in GCM decryption (Kurt Stutsman) [1213331 1212178] {CVE-2015-3331}
[3.10.0-229.5.1]
- [powerpc] mm: thp: Add tracepoints to track hugepage invalidate (Gustavo Duarte) [1212977 1199016]
- [powerpc] mm: Use read barrier when creating real_pte (Gustavo Duarte) [1212977 1199016]
- [powerpc] mm: thp: Use ACCESS_ONCE when loading pmdp (Gustavo Duarte) [1212977 1199016]
- [powerpc] mm: thp: Invalidate with vpn in loop (Gustavo Duarte) [1212977 1199016]
- [powerpc] mm: thp: Handle combo pages in invalidate (Gustavo Duarte) [1212977 1199016]
- [powerpc] mm: thp: Invalidate old 64K based hash page mapping before insert of 4k pte (Gustavo Duarte) [1212977 1199016]
- [powerpc] mm: thp: Don't recompute vsid and ssize in loop on invalidate (Gustavo Duarte) [1212977 1199016]
- [powerpc] mm: thp: Add write barrier after updating the valid bit (Gustavo Duarte) [1212977 1199016]
Обновленные пакеты
Oracle Linux 7
Oracle Linux x86_64
kernel
3.10.0-229.7.2.el7
kernel-abi-whitelists
3.10.0-229.7.2.el7
kernel-debug
3.10.0-229.7.2.el7
kernel-debug-devel
3.10.0-229.7.2.el7
kernel-devel
3.10.0-229.7.2.el7
kernel-doc
3.10.0-229.7.2.el7
kernel-headers
3.10.0-229.7.2.el7
kernel-tools
3.10.0-229.7.2.el7
kernel-tools-libs
3.10.0-229.7.2.el7
kernel-tools-libs-devel
3.10.0-229.7.2.el7
perf
3.10.0-229.7.2.el7
python-perf
3.10.0-229.7.2.el7
Ссылки на источники
Связанные уязвимости
The nft_flush_table function in net/netfilter/nf_tables_api.c in the Linux kernel before 3.18.5 mishandles the interaction between cross-chain jumps and ruleset flushes, which allows local users to cause a denial of service (panic) by leveraging the CAP_NET_ADMIN capability.
The nft_flush_table function in net/netfilter/nf_tables_api.c in the Linux kernel before 3.18.5 mishandles the interaction between cross-chain jumps and ruleset flushes, which allows local users to cause a denial of service (panic) by leveraging the CAP_NET_ADMIN capability.
The nft_flush_table function in net/netfilter/nf_tables_api.c in the Linux kernel before 3.18.5 mishandles the interaction between cross-chain jumps and ruleset flushes, which allows local users to cause a denial of service (panic) by leveraging the CAP_NET_ADMIN capability.
The nft_flush_table function in net/netfilter/nf_tables_api.c in the L ...
The nft_flush_table function in net/netfilter/nf_tables_api.c in the Linux kernel before 3.18.5 mishandles the interaction between cross-chain jumps and ruleset flushes, which allows local users to cause a denial of service (panic) by leveraging the CAP_NET_ADMIN capability.