Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2016-3573

Опубликовано: 13 июн. 2016
Источник: oracle-oval
Платформа: Oracle Linux 6
Платформа: Oracle Linux 7

Описание

ELSA-2016-3573: Unbreakable Enterprise kernel security update (IMPORTANT)

kernel-uek [3.8.13-118.7.1]

  • megaraid_sas : Update threshold based reply post host index register (Sumit.Saxena@avagotech.com) [Orabug: 23562756]
  • xen/events: Don't move disabled irqs (Ross Lagerwall) [Orabug: 23055234]
  • xen/events: Mask a moving irq (Boris Ostrovsky) [Orabug: 23055234]
  • xen/pciback: Save the number of MSI-X entries to be copied later. (Dongli Zhang) [Orabug: 23202410]
  • xen/pciback: Save xen_pci_op commands before processing it (Dongli Zhang) [Orabug: 23202410]
  • xen-blkback: read from indirect descriptors only once (Dongli Zhang) [Orabug: 23202410]
  • xen-blkback: only read request operation from shared ring once (Dongli Zhang) [Orabug: 23202410]
  • xen-netback: use RING_COPY_REQUEST() throughout (Dongli Zhang) [Orabug: 23202410]
  • xen-netback: don't use last request to determine minimum Tx credit (Dongli Zhang) [Orabug: 23202410]
  • xen: Add RING_COPY_REQUEST() (Dongli Zhang) [Orabug: 23202410]
  • IB/security: Restrict use of the write() interface (Jason Gunthorpe) [Orabug: 23283925] {CVE-2016-4565}

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

dtrace-modules-3.8.13-118.7.1.el6uek

0.4.5-3.el6

kernel-uek

3.8.13-118.7.1.el6uek

kernel-uek-debug

3.8.13-118.7.1.el6uek

kernel-uek-debug-devel

3.8.13-118.7.1.el6uek

kernel-uek-devel

3.8.13-118.7.1.el6uek

kernel-uek-doc

3.8.13-118.7.1.el6uek

kernel-uek-firmware

3.8.13-118.7.1.el6uek

Oracle Linux 7

Oracle Linux x86_64

dtrace-modules-3.8.13-118.7.1.el7uek

0.4.5-3.el7

kernel-uek

3.8.13-118.7.1.el7uek

kernel-uek-debug

3.8.13-118.7.1.el7uek

kernel-uek-debug-devel

3.8.13-118.7.1.el7uek

kernel-uek-devel

3.8.13-118.7.1.el7uek

kernel-uek-doc

3.8.13-118.7.1.el7uek

kernel-uek-firmware

3.8.13-118.7.1.el7uek

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 9 лет назад

The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI interface.

CVSS3: 7.8
redhat
около 9 лет назад

The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI interface.

CVSS3: 7.8
nvd
около 9 лет назад

The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI interface.

CVSS3: 7.8
debian
около 9 лет назад

The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorre ...

CVSS3: 7.8
github
около 3 лет назад

The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI interface.