Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2019-4710

Опубликовано: 10 июл. 2019
Источник: oracle-oval
Платформа: Oracle Linux 6
Платформа: Oracle Linux 7

Описание

ELSA-2019-4710: Unbreakable Enterprise kernel security update (IMPORTANT)

[4.1.12-124.28.6]

  • scsi: libfc: Fixup disc_mutex handling in fcoe module (Hannes Reinecke) [Orabug: 29511036]
  • scsi: libfc: sanitize E_D_TOV and R_A_TOV setting in fcp (Hannes Reinecke) [Orabug: 29511036]
  • sysctl: Fix kabi breakage (Shuning Zhang) [Orabug: 29689925]
  • proc: Fix proc_sys_prune_dcache to hold a sb reference (Eric W. Biederman) [Orabug: 29689925]
  • proc/sysctl: Don't grab i_lock under sysctl_lock. (Eric W. Biederman) [Orabug: 29689925]
  • proc/sysctl: prune stale dentries during unregistering (Konstantin Khlebnikov) [Orabug: 29689925]
  • scsi: smartpqi: correct lun reset issues (Kevin Barnett) [Orabug: 29848621]
  • fork: record start_time late (David Herrmann) [Orabug: 29850581] {CVE-2019-6133}
  • mm: avoid taking zone lock in pagetypeinfo_showmixed() (Vinayak Menon) [Orabug: 29905302]
  • x86/retpoline/ia32entry: Convert to non-speculative calls (Ankur Arora) [Orabug: 29909295] {CVE-2017-5715}
  • tun: call dev_get_valid_name() before register_netdevice() (Cong Wang) [Orabug: 29925555] {CVE-2018-7191}
  • mm/madvise.c: fix madvise() infinite loop under special circumstances (chenjie) [Orabug: 29925610] {CVE-2017-18208}

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

kernel-uek

4.1.12-124.28.6.el6uek

kernel-uek-debug

4.1.12-124.28.6.el6uek

kernel-uek-debug-devel

4.1.12-124.28.6.el6uek

kernel-uek-devel

4.1.12-124.28.6.el6uek

kernel-uek-doc

4.1.12-124.28.6.el6uek

kernel-uek-firmware

4.1.12-124.28.6.el6uek

Oracle Linux 7

Oracle Linux x86_64

kernel-uek

4.1.12-124.28.6.el7uek

kernel-uek-debug

4.1.12-124.28.6.el7uek

kernel-uek-debug-devel

4.1.12-124.28.6.el7uek

kernel-uek-devel

4.1.12-124.28.6.el7uek

kernel-uek-doc

4.1.12-124.28.6.el7uek

kernel-uek-firmware

4.1.12-124.28.6.el7uek

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

The madvise_willneed function in mm/madvise.c in the Linux kernel before 4.14.4 allows local users to cause a denial of service (infinite loop) by triggering use of MADVISE_WILLNEED for a DAX mapping.

CVSS3: 5.5
redhat
больше 7 лет назад

The madvise_willneed function in mm/madvise.c in the Linux kernel before 4.14.4 allows local users to cause a denial of service (infinite loop) by triggering use of MADVISE_WILLNEED for a DAX mapping.

CVSS3: 5.5
nvd
больше 7 лет назад

The madvise_willneed function in mm/madvise.c in the Linux kernel before 4.14.4 allows local users to cause a denial of service (infinite loop) by triggering use of MADVISE_WILLNEED for a DAX mapping.

CVSS3: 5.5
debian
больше 7 лет назад

The madvise_willneed function in mm/madvise.c in the Linux kernel befo ...

CVSS3: 5.5
github
около 3 лет назад

The madvise_willneed function in mm/madvise.c in the Linux kernel before 4.14.4 allows local users to cause a denial of service (infinite loop) by triggering use of MADVISE_WILLNEED for a DAX mapping.