Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2016-3589

Опубликовано: 01 авг. 2016
Источник: oracle-oval
Платформа: Oracle Linux 5
Платформа: Oracle Linux 6

Описание

ELSA-2016-3589: Unbreakable Enterprise kernel security update (IMPORTANT)

[2.6.39-400.283.1]

  • atl2: Disable unimplemented scatter/gather feature (Ben Hutchings) [Orabug: 23703990] {CVE-2016-2117}
  • mlx4_core: add module parameter to disable background init (Mukesh Kacker) [Orabug: 23292107]
  • NFSv4: Don't decode fs_locations if we didn't ask for them... (Trond Myklebust) [Orabug: 23633714]
  • mm/slab: Improve performance of slabinfo stats gathering (Aruna Ramakrishna) [Orabug: 23050884]
  • offload ib subnet manager port and node get info query handling. (Rama Nichanamatlu) [Orabug: 22521735]

Обновленные пакеты

Oracle Linux 5

Oracle Linux x86_64

kernel-uek

2.6.39-400.283.1.el5uek

kernel-uek-debug

2.6.39-400.283.1.el5uek

kernel-uek-debug-devel

2.6.39-400.283.1.el5uek

kernel-uek-devel

2.6.39-400.283.1.el5uek

kernel-uek-doc

2.6.39-400.283.1.el5uek

kernel-uek-firmware

2.6.39-400.283.1.el5uek

Oracle Linux i386

kernel-uek

2.6.39-400.283.1.el5uek

kernel-uek-debug

2.6.39-400.283.1.el5uek

kernel-uek-debug-devel

2.6.39-400.283.1.el5uek

kernel-uek-devel

2.6.39-400.283.1.el5uek

kernel-uek-doc

2.6.39-400.283.1.el5uek

kernel-uek-firmware

2.6.39-400.283.1.el5uek

Oracle Linux 6

Oracle Linux x86_64

kernel-uek

2.6.39-400.283.1.el6uek

kernel-uek-debug

2.6.39-400.283.1.el6uek

kernel-uek-debug-devel

2.6.39-400.283.1.el6uek

kernel-uek-devel

2.6.39-400.283.1.el6uek

kernel-uek-doc

2.6.39-400.283.1.el6uek

kernel-uek-firmware

2.6.39-400.283.1.el6uek

Oracle Linux i686

kernel-uek

2.6.39-400.283.1.el6uek

kernel-uek-debug

2.6.39-400.283.1.el6uek

kernel-uek-debug-devel

2.6.39-400.283.1.el6uek

kernel-uek-devel

2.6.39-400.283.1.el6uek

kernel-uek-doc

2.6.39-400.283.1.el6uek

kernel-uek-firmware

2.6.39-400.283.1.el6uek

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 9 лет назад

The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c in the Linux kernel through 4.5.2 incorrectly enables scatter/gather I/O, which allows remote attackers to obtain sensitive information from kernel memory by reading packet data.

redhat
больше 9 лет назад

The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c in the Linux kernel through 4.5.2 incorrectly enables scatter/gather I/O, which allows remote attackers to obtain sensitive information from kernel memory by reading packet data.

CVSS3: 7.5
nvd
около 9 лет назад

The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c in the Linux kernel through 4.5.2 incorrectly enables scatter/gather I/O, which allows remote attackers to obtain sensitive information from kernel memory by reading packet data.

CVSS3: 7.5
debian
около 9 лет назад

The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c in ...

CVSS3: 7.5
github
около 3 лет назад

The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c in the Linux kernel through 4.5.2 incorrectly enables scatter/gather I/O, which allows remote attackers to obtain sensitive information from kernel memory by reading packet data.