Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2018-4017

Опубликовано: 18 янв. 2018
Источник: oracle-oval
Платформа: Oracle Linux 6
Платформа: Oracle Linux 7

Описание

ELSA-2018-4017: Unbreakable Enterprise kernel security update (IMPORTANT)

[4.1.12-112.14.13]

  • Revert 'kernel.spec: Require the new microcode_ctl.' (Brian Maly)

[4.1.12-112.14.12]

  • xen-blkback: add pending_req allocation stats (Ankur Arora) [Orabug: 27386890]
  • xen-blkback: move indirect req allocation out-of-line (Ankur Arora) [Orabug: 27386890]
  • xen-blkback: pull nseg validation out in a function (Ankur Arora) [Orabug: 27386890]
  • xen-blkback: make struct pending_req less monolithic (Ankur Arora) [Orabug: 27386890]
  • x86: Clean up IBRS functionality resident in common code (Kanth Ghatraju) [Orabug: 27403317]
  • x86: Display correct settings for the SPECTRE_V2 bug (Kanth Ghatraju) [Orabug: 27403317]
  • Set CONFIG_GENERIC_CPU_VULNERABILITIES flag (Kanth Ghatraju) [Orabug: 27403317]
  • x86/cpu: Implement CPU vulnerabilites sysfs functions (Thomas Gleixner) [Orabug: 27403317]
  • sysfs/cpu: Fix typos in vulnerability documentation (David Woodhouse) [Orabug: 27403317]
  • sysfs/cpu: Add vulnerability folder (Thomas Gleixner) [Orabug: 27403317]
  • x86/cpufeatures: Add X86_BUG_SPECTRE_V[12] (David Woodhouse) [Orabug: 27403317]
  • x86/cpufeatures: Add X86_BUG_CPU_MELTDOWN (Kanth Ghatraju) [Orabug: 27403317]
  • KVM: x86: Add memory barrier on vmcs field lookup (Andrew Honig) {CVE-2017-5753}
  • KVM: VMX: remove I/O port 0x80 bypass on Intel hosts (Andrew Honig) [Orabug: 27402301] {CVE-2017-1000407} {CVE-2017-1000407}
  • xfs: give all workqueues rescuer threads (Chris Mason) [Orabug: 27397568]
  • ixgbevf: handle mbox_api_13 in ixgbevf_change_mtu (Joao Martins) [Orabug: 27397001]

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

kernel-uek

4.1.12-112.14.13.el6uek

kernel-uek-debug

4.1.12-112.14.13.el6uek

kernel-uek-debug-devel

4.1.12-112.14.13.el6uek

kernel-uek-devel

4.1.12-112.14.13.el6uek

kernel-uek-doc

4.1.12-112.14.13.el6uek

kernel-uek-firmware

4.1.12-112.14.13.el6uek

Oracle Linux 7

Oracle Linux x86_64

kernel-uek

4.1.12-112.14.13.el7uek

kernel-uek-debug

4.1.12-112.14.13.el7uek

kernel-uek-debug-devel

4.1.12-112.14.13.el7uek

kernel-uek-devel

4.1.12-112.14.13.el7uek

kernel-uek-doc

4.1.12-112.14.13.el7uek

kernel-uek-firmware

4.1.12-112.14.13.el7uek

Связанные CVE

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 7 лет назад

The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic.

CVSS3: 6.1
redhat
больше 7 лет назад

The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic.

CVSS3: 7.4
nvd
больше 7 лет назад

The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic.

CVSS3: 7.4
debian
больше 7 лет назад

The Linux Kernel 2.6.32 and later are affected by a denial of service, ...

CVSS3: 7.4
github
около 3 лет назад

The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic.