Описание
ELSA-2019-4854: Unbreakable Enterprise kernel security update (IMPORTANT)
kernel-uek [3.8.13-118.40.1]
- USB: check usb_get_extra_descriptor for proper size (Mathias Payer) [Orabug: 30045797] {CVE-2018-20169}
- scsi: sg: fixup infoleak when using SG_GET_REQUEST_TABLE (Hannes Reinecke) [Orabug: 30393902] {CVE-2017-14991}
- usb: misc: legousbtower: Fix NULL pointer deference (Greg Kroah-Hartman) [Orabug: 30412151] {CVE-2017-15102}
- floppy: fix div-by-zero in setup_format_params (Denis Efremov) [Orabug: 30447844] {CVE-2019-14284}
- i2c: core-smbus: prevent stack corruption on read I2C_BLOCK_DATA (Jeremy Compostella) [Orabug: 30468842] {CVE-2017-18551}
Обновленные пакеты
Oracle Linux 6
Oracle Linux x86_64
dtrace-modules-3.8.13-118.40.1.el6uek
0.4.5-3.el6
kernel-uek
3.8.13-118.40.1.el6uek
kernel-uek-debug
3.8.13-118.40.1.el6uek
kernel-uek-debug-devel
3.8.13-118.40.1.el6uek
kernel-uek-devel
3.8.13-118.40.1.el6uek
kernel-uek-doc
3.8.13-118.40.1.el6uek
kernel-uek-firmware
3.8.13-118.40.1.el6uek
Oracle Linux 7
Oracle Linux x86_64
dtrace-modules-3.8.13-118.40.1.el7uek
0.4.5-3.el7
kernel-uek
3.8.13-118.40.1.el7uek
kernel-uek-debug
3.8.13-118.40.1.el7uek
kernel-uek-debug-devel
3.8.13-118.40.1.el7uek
kernel-uek-devel
3.8.13-118.40.1.el7uek
kernel-uek-doc
3.8.13-118.40.1.el7uek
kernel-uek-firmware
3.8.13-118.40.1.el7uek
Ссылки на источники
Связанные уязвимости
ELSA-2019-4855: Unbreakable Enterprise kernel security update (IMPORTANT)
An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading of an extra descriptor, related to __usb_get_extra_descriptor in drivers/usb/core/usb.c.
An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading of an extra descriptor, related to __usb_get_extra_descriptor in drivers/usb/core/usb.c.
An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading of an extra descriptor, related to __usb_get_extra_descriptor in drivers/usb/core/usb.c.