Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2018-4134

Опубликовано: 15 июн. 2018
Источник: oracle-oval
Платформа: Oracle Linux 6
Платформа: Oracle Linux 7

Описание

ELSA-2018-4134: Unbreakable Enterprise kernel security update (IMPORTANT)

kernel-uek [3.8.13-118.21.4]

  • x86/fpu: Make eager FPU default (Mihai Carabas) [Orabug: 28156176] {CVE-2018-3665}

[3.8.13-118.21.3]

  • KVM: Fix stack-out-of-bounds read in write_mmio (Wanpeng Li) [Orabug: 27951287] {CVE-2017-17741} {CVE-2017-17741}
  • xfs: set format back to extents if xfs_bmap_extents_to_btree (Eric Sandeen) [Orabug: 27989498] {CVE-2018-10323}
  • Bluetooth: Prevent stack info leak from the EFS element. (Ben Seri) [Orabug: 28030520] {CVE-2017-1000410} {CVE-2017-1000410}
  • ALSA: hrtimer: Fix stall by hrtimer_cancel() (Takashi Iwai) [Orabug: 28058229] {CVE-2016-2549}
  • ALSA: timer: Harden slave timer list handling (Takashi Iwai) [Orabug: 28058229] {CVE-2016-2547} {CVE-2016-2548}
  • ALSA: timer: Fix double unlink of active_list (Takashi Iwai) [Orabug: 28058229] {CVE-2016-2545}
  • ALSA: seq: Fix missing NULL check at remove_events ioctl (Takashi Iwai) [Orabug: 28058229] {CVE-2016-2543}
  • ALSA: seq: Fix race at timer setup and close (Takashi Iwai) [Orabug: 28058229] {CVE-2016-2544}
  • ALSA: usb-audio: avoid freeing umidi object twice (Andrey Konovalov) [Orabug: 28058229] {CVE-2016-2384}

[3.8.13-118.21.2]

  • perf/hwbp: Simplify the perf-hwbp code, fix documentation (Linus Torvalds) [Orabug: 27947608] {CVE-2018-1000199}
  • Revert 'perf/hwbp: Simplify the perf-hwbp code, fix documentation' (Brian Maly) [Orabug: 27947608]

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

dtrace-modules-3.8.13-118.21.4.el6uek

0.4.5-3.el6

kernel-uek

3.8.13-118.21.4.el6uek

kernel-uek-debug

3.8.13-118.21.4.el6uek

kernel-uek-debug-devel

3.8.13-118.21.4.el6uek

kernel-uek-devel

3.8.13-118.21.4.el6uek

kernel-uek-doc

3.8.13-118.21.4.el6uek

kernel-uek-firmware

3.8.13-118.21.4.el6uek

Oracle Linux 7

Oracle Linux x86_64

dtrace-modules-3.8.13-118.21.4.el7uek

0.4.5-3.el7

kernel-uek

3.8.13-118.21.4.el7uek

kernel-uek-debug

3.8.13-118.21.4.el7uek

kernel-uek-debug-devel

3.8.13-118.21.4.el7uek

kernel-uek-devel

3.8.13-118.21.4.el7uek

kernel-uek-doc

3.8.13-118.21.4.el7uek

kernel-uek-firmware

3.8.13-118.21.4.el7uek

Связанные уязвимости

oracle-oval
около 7 лет назад

ELSA-2018-4145: Unbreakable Enterprise kernel security update (IMPORTANT)

CVSS3: 6.2
ubuntu
около 9 лет назад

The snd_seq_ioctl_remove_events function in sound/core/seq/seq_clientmgr.c in the Linux kernel before 4.4.1 does not verify FIFO assignment before proceeding with FIFO clearing, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a crafted ioctl call.

redhat
больше 9 лет назад

The snd_seq_ioctl_remove_events function in sound/core/seq/seq_clientmgr.c in the Linux kernel before 4.4.1 does not verify FIFO assignment before proceeding with FIFO clearing, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a crafted ioctl call.

CVSS3: 6.2
nvd
около 9 лет назад

The snd_seq_ioctl_remove_events function in sound/core/seq/seq_clientmgr.c in the Linux kernel before 4.4.1 does not verify FIFO assignment before proceeding with FIFO clearing, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a crafted ioctl call.

CVSS3: 6.2
debian
около 9 лет назад

The snd_seq_ioctl_remove_events function in sound/core/seq/seq_clientm ...