Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2019-4854

Опубликовано: 20 нояб. 2019
Источник: oracle-oval
Платформа: Oracle Linux 6
Платформа: Oracle Linux 7

Описание

ELSA-2019-4854: Unbreakable Enterprise kernel security update (IMPORTANT)

kernel-uek [3.8.13-118.40.1]

  • USB: check usb_get_extra_descriptor for proper size (Mathias Payer) [Orabug: 30045797] {CVE-2018-20169}
  • scsi: sg: fixup infoleak when using SG_GET_REQUEST_TABLE (Hannes Reinecke) [Orabug: 30393902] {CVE-2017-14991}
  • usb: misc: legousbtower: Fix NULL pointer deference (Greg Kroah-Hartman) [Orabug: 30412151] {CVE-2017-15102}
  • floppy: fix div-by-zero in setup_format_params (Denis Efremov) [Orabug: 30447844] {CVE-2019-14284}
  • i2c: core-smbus: prevent stack corruption on read I2C_BLOCK_DATA (Jeremy Compostella) [Orabug: 30468842] {CVE-2017-18551}

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

dtrace-modules-3.8.13-118.40.1.el6uek

0.4.5-3.el6

kernel-uek

3.8.13-118.40.1.el6uek

kernel-uek-debug

3.8.13-118.40.1.el6uek

kernel-uek-debug-devel

3.8.13-118.40.1.el6uek

kernel-uek-devel

3.8.13-118.40.1.el6uek

kernel-uek-doc

3.8.13-118.40.1.el6uek

kernel-uek-firmware

3.8.13-118.40.1.el6uek

Oracle Linux 7

Oracle Linux x86_64

dtrace-modules-3.8.13-118.40.1.el7uek

0.4.5-3.el7

kernel-uek

3.8.13-118.40.1.el7uek

kernel-uek-debug

3.8.13-118.40.1.el7uek

kernel-uek-debug-devel

3.8.13-118.40.1.el7uek

kernel-uek-devel

3.8.13-118.40.1.el7uek

kernel-uek-doc

3.8.13-118.40.1.el7uek

kernel-uek-firmware

3.8.13-118.40.1.el7uek

Связанные уязвимости

oracle-oval
больше 5 лет назад

ELSA-2019-4855: Unbreakable Enterprise kernel security update (IMPORTANT)

CVSS3: 6.8
ubuntu
больше 6 лет назад

An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading of an extra descriptor, related to __usb_get_extra_descriptor in drivers/usb/core/usb.c.

CVSS3: 6.4
redhat
больше 6 лет назад

An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading of an extra descriptor, related to __usb_get_extra_descriptor in drivers/usb/core/usb.c.

CVSS3: 6.8
nvd
больше 6 лет назад

An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading of an extra descriptor, related to __usb_get_extra_descriptor in drivers/usb/core/usb.c.

CVSS3: 6.8
msrc
больше 1 года назад

Описание отсутствует