OVMSA-2017-0144

OVMSA-2017-0144 - Unbreakable Enterprise kernel security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2017-08-18

Description


[3.8.13-118.19.4]
- l2tp: fix racy SOCK_ZAPPED flag check in l2tp_ip{,6}_bind() (Guillaume Nault) [Orabug: 26586047] {CVE-2016-10200}
- xfs: fix two memory leaks in xfs_attr_list.c error paths (Mateusz Guzik) [Orabug: 26586022] {CVE-2016-9685}
- KEYS: Disallow keyrings beginning with '.' to be joined as session keyrings (David Howells) [Orabug: 26585994] {CVE-2016-9604}
- ipv6: fix out of bound writes in __ip6_append_data() (Eric Dumazet) [Orabug: 26578198] {CVE-2017-9242}


Related CVEs


CVE-2016-10200
CVE-2016-9604
CVE-2017-9242
CVE-2016-9685

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle VM 3.3 (x86_64) kernel-uek-3.8.13-118.19.4.el6uek.src.rpm046a24aa6c5f2dc5f4fbf93eb32973bbOVMSA-2021-0016
kernel-uek-3.8.13-118.19.4.el6uek.x86_64.rpmc90f4cbb6653858262e943536c1c6ab6OVMSA-2021-0016
kernel-uek-firmware-3.8.13-118.19.4.el6uek.noarch.rpmbd0115a5df304a5a4e766d181e999357OVMSA-2021-0016



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete