Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2019-4528

Опубликовано: 31 янв. 2019
Источник: oracle-oval
Платформа: Oracle Linux 6
Платформа: Oracle Linux 7

Описание

ELSA-2019-4528: Unbreakable Enterprise kernel security update (IMPORTANT)

[4.1.12-124.24.5]

  • rds: congestion updates can be missed when kernel low on memory (Mukesh Kacker) [Orabug: 28425811]
  • net/rds: ib: Fix endless RNR Retries caused by memory allocation failures (Venkat Venkatsubra) [Orabug: 28127993]
  • net: rds: fix excess initialization of the recv SGEs (Zhu Yanjun) [Orabug: 29004503]
  • xhci: fix usb2 resume timing and races. (Mathias Nyman) [Orabug: 29028940]
  • xhci: Fix a race in usb2 LPM resume, blocking U3 for usb2 devices (Mathias Nyman) [Orabug: 29028940]
  • userfaultfd: check VM_MAYWRITE was set after verifying the uffd is registered (Andrea Arcangeli) [Orabug: 29163750] {CVE-2018-18397}
  • userfaultfd: shmem/hugetlbfs: only allow to register VM_MAYWRITE vmas (Andrea Arcangeli) [Orabug: 29163750] {CVE-2018-18397}
  • x86/apic/x2apic: set affinity of a single interrupt to one cpu (Jianchao Wang) [Orabug: 29196396]
  • xen/blkback: rework validate_io_op() (Dongli Zhang) [Orabug: 29199843]
  • xen/blkback: optimize validate_io_op() to filter BLKIF_OP_RESERVED_1 operation (Dongli Zhang) [Orabug: 29199843]
  • xen/blkback: do not BUG() for invalid blkif_request from frontend (Dongli Zhang) [Orabug: 29199843]
  • net/rds: WARNING: at net/rds/recv.c:222 rds_recv_hs_exthdrs+0xf8/0x1e0 (Venkat Venkatsubra) [Orabug: 29201779]
  • xen-netback: wake up xenvif_dealloc_kthread when it should stop (Dongli Zhang) [Orabug: 29217927]
  • Revert 'xfs: remove nonblocking mode from xfs_vm_writepage' (Wengang Wang) [Orabug: 29279692]
  • Revert 'xfs: remove xfs_cancel_ioend' (Wengang Wang) [Orabug: 29279692]
  • Revert 'xfs: Introduce writeback context for writepages' (Wengang Wang) [Orabug: 29279692]
  • Revert 'xfs: xfs_cluster_write is redundant' (Wengang Wang) [Orabug: 29279692]
  • Revert 'xfs: factor mapping out of xfs_do_writepage' (Wengang Wang) [Orabug: 29279692]
  • Revert 'xfs: dont chain ioends during writepage submission' (Wengang Wang) [Orabug: 29279692]

[4.1.12-124.24.4]

  • mstflint: Fix coding style issues - left with LINUX_VERSION_CODE (Idan Mehalel) [Orabug: 28878697]
  • mstflint: Fix coding-style issues (Idan Mehalel) [Orabug: 28878697]
  • mstflint: Fix errors found with checkpatch script (Idan Mehalel) [Orabug: 28878697]
  • Added support for 5th Gen devices in Secure Boot module and mtcr (Adham Masarwah) [Orabug: 28878697]
  • Fix typos in mst_kernel (Adham Masarwah) [Orabug: 28878697]
  • bnxt_en: Report PCIe link properties with pcie_print_link_status() (Brian Maly) [Orabug: 28942099]
  • selinux: Perform both commoncap and selinux xattr checks (Eric W. Biederman) [Orabug: 28951521]
  • Introduce v3 namespaced file capabilities (Serge E. Hallyn) [Orabug: 28951521]
  • rds: ib: Use a delay when reconnecting to the very same IP address (Hakon Bugge) [Orabug: 29138813]
  • Change mincore() to count 'mapped' pages rather than 'cached' pages (Linus Torvalds) [Orabug: 29187415] {CVE-2019-5489}
  • NFSD: Set the attributes used to store the verifier for EXCLUSIVE4_1 (Kinglong Mee) [Orabug: 29204157]

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

kernel-uek

4.1.12-124.24.5.el6uek

kernel-uek-debug

4.1.12-124.24.5.el6uek

kernel-uek-debug-devel

4.1.12-124.24.5.el6uek

kernel-uek-devel

4.1.12-124.24.5.el6uek

kernel-uek-doc

4.1.12-124.24.5.el6uek

kernel-uek-firmware

4.1.12-124.24.5.el6uek

Oracle Linux 7

Oracle Linux x86_64

kernel-uek

4.1.12-124.24.5.el7uek

kernel-uek-debug

4.1.12-124.24.5.el7uek

kernel-uek-debug-devel

4.1.12-124.24.5.el7uek

kernel-uek-devel

4.1.12-124.24.5.el7uek

kernel-uek-doc

4.1.12-124.24.5.el7uek

kernel-uek-firmware

4.1.12-124.24.5.el7uek

Связанные CVE

Связанные уязвимости

oracle-oval
больше 6 лет назад

ELSA-2019-4541: Unbreakable Enterprise kernel security update (IMPORTANT)

CVSS3: 5.5
ubuntu
больше 6 лет назад

The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user has read-only access to that file, and that file contains holes), related to fs/userfaultfd.c and mm/userfaultfd.c.

CVSS3: 6.1
redhat
больше 6 лет назад

The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user has read-only access to that file, and that file contains holes), related to fs/userfaultfd.c and mm/userfaultfd.c.

CVSS3: 5.5
nvd
больше 6 лет назад

The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user has read-only access to that file, and that file contains holes), related to fs/userfaultfd.c and mm/userfaultfd.c.

CVSS3: 5.5
debian
больше 6 лет назад

The userfaultfd implementation in the Linux kernel before 4.19.7 misha ...