Описание
ELSA-2019-4777: Unbreakable Enterprise kernel security update (IMPORTANT)
[2.6.39-400.314.1]
- x86/speculation: Exclude ATOMs from speculation through SWAPGS (Thomas Gleixner) [Orabug: 30165287] {CVE-2019-1125}
- x86/speculation: Enable Spectre v1 swapgs mitigations (Josh Poimboeuf) [Orabug: 30165287] {CVE-2019-1125}
- x86/speculation: Prepare entry code for Spectre v1 swapgs mitigations (Josh Poimboeuf) [Orabug: 30165287] {CVE-2019-1125}
Обновленные пакеты
Oracle Linux 5
Oracle Linux x86_64
kernel-uek
2.6.39-400.314.1.el5uek
kernel-uek-debug
2.6.39-400.314.1.el5uek
kernel-uek-debug-devel
2.6.39-400.314.1.el5uek
kernel-uek-devel
2.6.39-400.314.1.el5uek
kernel-uek-doc
2.6.39-400.314.1.el5uek
kernel-uek-firmware
2.6.39-400.314.1.el5uek
Oracle Linux i386
kernel-uek
2.6.39-400.314.1.el5uek
kernel-uek-debug
2.6.39-400.314.1.el5uek
kernel-uek-debug-devel
2.6.39-400.314.1.el5uek
kernel-uek-devel
2.6.39-400.314.1.el5uek
kernel-uek-doc
2.6.39-400.314.1.el5uek
kernel-uek-firmware
2.6.39-400.314.1.el5uek
Oracle Linux 6
Oracle Linux x86_64
kernel-uek
2.6.39-400.314.1.el6uek
kernel-uek-debug
2.6.39-400.314.1.el6uek
kernel-uek-debug-devel
2.6.39-400.314.1.el6uek
kernel-uek-devel
2.6.39-400.314.1.el6uek
kernel-uek-doc
2.6.39-400.314.1.el6uek
kernel-uek-firmware
2.6.39-400.314.1.el6uek
Oracle Linux i686
kernel-uek
2.6.39-400.314.1.el6uek
kernel-uek-debug
2.6.39-400.314.1.el6uek
kernel-uek-debug-devel
2.6.39-400.314.1.el6uek
kernel-uek-devel
2.6.39-400.314.1.el6uek
kernel-uek-doc
2.6.39-400.314.1.el6uek
kernel-uek-firmware
2.6.39-400.314.1.el6uek
Связанные CVE
Связанные уязвимости
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an attacker to elevate user rights directly, but it could be used to obtain information that could be used to try to compromise the affected system further. On January 3, 2018, Microsoft released an advisory and security updates related to a newly-discovered class of hardware vulnerabilities (known as Spectre) involving speculative execution side channels that affect AMD, ARM, and Intel CPUs to varying degrees. This vulnerability, released on August 6, 2019, is a variant of the Spectre Variant 1 speculative execution side channel vulnerability and has been assigned CVE-2019-1125. Microsoft released a...
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an attacker to elevate user rights directly, but it could be used to obtain information that could be used to try to compromise the affected system further. On January 3, 2018, Microsoft released an advisory and security updates related to a newly-discovered class of hardware vulnerabilities (known as Spectre) involving speculative execution side channels that affect AMD, ARM, and Intel CPUs to varying degrees. This vulnerability, released on August 6, 2019, is a variant of the Spectre Variant 1 speculative execution side channel vulnerability and has been assigned CVE-2019-1125. Microsoft released...
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an attacker to elevate user rights directly, but it could be used to obtain information that could be used to try to compromise the affected system further. On January 3, 2018, Microsoft released an advisory and security updates related to a newly-discovered class of hardware vulnerabilities (known as Spectre) involving speculative execution side channels that affect AMD, ARM, and Intel CPUs to varying degrees. This vulnerability, released on August 6, 2019, is a variant of the Spectre Variant 1 speculative execution side channel vulnerability and has been assigned CVE-2019-1125. Microsoft released a
An information disclosure vulnerability exists when certain central pr ...