Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2015-1137

Опубликовано: 23 июн. 2015
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2015-1137: kernel security and bug fix update (IMPORTANT)

[3.10.0-229.7.2]

  • Oracle Linux certificates (Alexey Petrenko)

[3.10.0-229.7.2]

  • [fs] pipe: fix pipe corruption and iovec overrun on partial copy (Seth Jennings) [1202861 1198843] {CVE-2015-1805}

[3.10.0-229.7.1]

  • [scsi] storvsc: get rid of overly verbose warning messages (Vitaly Kuznetsov) [1215770 1206437]
  • [scsi] storvsc: force discovery of LUNs that may have been removed (Vitaly Kuznetsov) [1215770 1206437]
  • [scsi] storvsc: in responce to a scan event, scan the host (Vitaly Kuznetsov) [1215770 1206437]
  • [scsi] storvsc: NULL pointer dereference fix (Vitaly Kuznetsov) [1215770 1206437]
  • [virtio] defer config changed notifications (David Gibson) [1220278 1196009]
  • [virtio] unify config_changed handling (David Gibson) [1220278 1196009]
  • [x86] kernel: Remove a bogus 'ret_from_fork' optimization (Mateusz Guzik) [1209234 1209235] {CVE-2015-2830}
  • [kernel] futex: Mention key referencing differences between shared and private futexes (Larry Woodman) [1219169 1205862]
  • [kernel] futex: Ensure get_futex_key_refs() always implies a barrier (Larry Woodman) [1219169 1205862]
  • [scsi] megaraid_sas: revert: Add release date and update driver version (Tomas Henzl) [1216213 1207175]
  • [kernel] module: set nx before marking module MODULE_STATE_COMING (Hendrik Brueckner) [1214788 1196977]
  • [kernel] module: Clean up ro/nx after early module load failures (Pratyush Anand) [1214403 1202866]
  • [drm] radeon: fix kernel segfault in hwmonitor (Jerome Glisse) [1213467 1187817]
  • [fs] btrfs: make xattr replace operations atomic (Eric Sandeen) [1205086 1205873]
  • [x86] mm: Linux stack ASLR implementation (Jacob Tanenbaum) [1195684 1195685] {CVE-2015-1593}
  • [net] netfilter: nf_tables: fix flush ruleset chain dependencies (Jiri Pirko) [1192880 1192881] {CVE-2015-1573}
  • [fs] isofs: Fix unchecked printing of ER records (Mateusz Guzik) [1180482 1180483] {CVE-2014-9584}
  • [security] keys: memory corruption or panic during key garbage collection (Jacob Tanenbaum) [1179851 1179852] {CVE-2014-9529}
  • [fs] isofs: infinite loop in CE record entries (Jacob Tanenbaum) [1175246 1175248] {CVE-2014-9420}

[3.10.0-229.6.1]

  • [net] tcp: abort orphan sockets stalling on zero window probes (Florian Westphal) [1215924 1151756]
  • [x86] crypto: aesni - fix memory usage in GCM decryption (Kurt Stutsman) [1213331 1212178] {CVE-2015-3331}

[3.10.0-229.5.1]

  • [powerpc] mm: thp: Add tracepoints to track hugepage invalidate (Gustavo Duarte) [1212977 1199016]
  • [powerpc] mm: Use read barrier when creating real_pte (Gustavo Duarte) [1212977 1199016]
  • [powerpc] mm: thp: Use ACCESS_ONCE when loading pmdp (Gustavo Duarte) [1212977 1199016]
  • [powerpc] mm: thp: Invalidate with vpn in loop (Gustavo Duarte) [1212977 1199016]
  • [powerpc] mm: thp: Handle combo pages in invalidate (Gustavo Duarte) [1212977 1199016]
  • [powerpc] mm: thp: Invalidate old 64K based hash page mapping before insert of 4k pte (Gustavo Duarte) [1212977 1199016]
  • [powerpc] mm: thp: Don't recompute vsid and ssize in loop on invalidate (Gustavo Duarte) [1212977 1199016]
  • [powerpc] mm: thp: Add write barrier after updating the valid bit (Gustavo Duarte) [1212977 1199016]

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

kernel

3.10.0-229.7.2.el7

kernel-abi-whitelists

3.10.0-229.7.2.el7

kernel-debug

3.10.0-229.7.2.el7

kernel-debug-devel

3.10.0-229.7.2.el7

kernel-devel

3.10.0-229.7.2.el7

kernel-doc

3.10.0-229.7.2.el7

kernel-headers

3.10.0-229.7.2.el7

kernel-tools

3.10.0-229.7.2.el7

kernel-tools-libs

3.10.0-229.7.2.el7

kernel-tools-libs-devel

3.10.0-229.7.2.el7

perf

3.10.0-229.7.2.el7

python-perf

3.10.0-229.7.2.el7

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 9 лет назад

The nft_flush_table function in net/netfilter/nf_tables_api.c in the Linux kernel before 3.18.5 mishandles the interaction between cross-chain jumps and ruleset flushes, which allows local users to cause a denial of service (panic) by leveraging the CAP_NET_ADMIN capability.

redhat
больше 10 лет назад

The nft_flush_table function in net/netfilter/nf_tables_api.c in the Linux kernel before 3.18.5 mishandles the interaction between cross-chain jumps and ruleset flushes, which allows local users to cause a denial of service (panic) by leveraging the CAP_NET_ADMIN capability.

CVSS3: 5.5
nvd
около 9 лет назад

The nft_flush_table function in net/netfilter/nf_tables_api.c in the Linux kernel before 3.18.5 mishandles the interaction between cross-chain jumps and ruleset flushes, which allows local users to cause a denial of service (panic) by leveraging the CAP_NET_ADMIN capability.

CVSS3: 5.5
debian
около 9 лет назад

The nft_flush_table function in net/netfilter/nf_tables_api.c in the L ...

CVSS3: 5.5
github
около 3 лет назад

The nft_flush_table function in net/netfilter/nf_tables_api.c in the Linux kernel before 3.18.5 mishandles the interaction between cross-chain jumps and ruleset flushes, which allows local users to cause a denial of service (panic) by leveraging the CAP_NET_ADMIN capability.