ELSA-2009-0014

ELSA-2009-0014 - kernel security and bug fix update

Type:SECURITY
Severity:IMPORTANT
Release Date:2009-01-15

Description



[2.6.9-78.0.13.0.1.EL]
- fix entropy flag in bnx2 driver to generate entropy pool (John Sobecki)
[orabug 5931647]
- fix skb alignment that was causing sendto() to fail with EFAULT (Olaf Kirch)
[orabug 6845794]
- fix enomem due to larger mtu size page alloc (Zach Brown) [orabug 5486128]
- fix per_cpu() api bug_on with rds (Zach Brown) [orabug 5760648]
- backout patch sysrq-b that queues upto keventd thread (Guru Anbalagane)
[orabug 6125546]
- netrx/netpoll race avoidance (Tina Yang) [orabug 6143381]
- fix guest spinning in xen (Herbert van den Bergh) [orabug 7004010]
- fix serial port lock recursion (Herbert van den Bergh) [orabug 6761872]
- [XEN] Fix elf_core_dump (Tina Yang) [orabug 6995928]
- fix in nfs_attribute_timeout() (Trond Myklebust) [orabug 7378108]
- use lfence instead of cpuid instruction to implement memory barriers
(Herbert van den Bergh) [orabug 7452412]
- add netpoll support to xen netfront (Tina Yang) [orabz 7261]
- [xen] execshield: fix endless GPF fault loop (Stephen Tweedie) [orabug 7175395]
- port Red Hat bug 472572: HVM crash in net/core/dev.c during boot [orabug 7653948]
The following Red Hat patches were ported from the source RPM at:
http://people.redhat.com/vgoyal/rhel4/SRPMS.kernel/kernel-2.6.9-78.22.EL.src.rpm
linux-2.6.9-xen-fix-netfront-mem-leak.patch
linux-2.6.9-xen-xen-vnif-stops-working-on-reception-of-duplicat.patch
linux-2.6.9-xen-guest-will-crash-if-rtl8139-nic-is-only-one-spe.patch
- fix kernel null dereference in ap_suspend() during migration [orabug 7635625]
Ported from the el5u2 xenpv-0.1-9.0.1.el5 patch
ovs-bugz7262-fix-migration-hang-due-to-write-lock-starvation.patch.
In el5u2, the fix is to the xenpv driver. For el4u7, the xenpv driver
was moved into the kernel.
- port el4u6 xenpv patch (orabug 7442030) for live migration hang
[orabug 7458244]
- [xen]: port el5u2 patch that allows 64-bit PVHVM guest to boot with 32-bit
dom0 [orabug 7452107]
- [mm] update shrink_zone patch to allow 100% swap utilization (John Sobecki,
Chris Mason, Chuck Anderson, Dave McCracken) [orabug 7566319,6086839]
- [nfs] update fix for attribute caching when using actimeo=0 (Chuck Lever,
John Sobecki) [ORABUG 7131141,7156607,7388056] [RHBZ 446083,476726]
- [kernel] backport report_lost_ticks patch from EL5.2 (John Sobecki)
[orabug 6110605]

[2.6.9-78.0.13]
-net: fix unix socket panic patch missing hunk (Neil Horman) [473267 473268] {CVE-2008-5300}

[2.6.9-78.0.12]
-revert: fix race between poll_napi and net_rx_action (Andy Gospodarek) [475970 463815]

[2.6.9-78.0.11]
-net: fix unix socket panic patch regression (Neil Horman) [470433 470434 473267 473268] {CVE-2008-5029 CVE-2008-5300}
-net: fix race between poll_napi and net_rx_action (Andy Gospodarek) [475970 463815]
-kernel: watchdog: fix buffer_underflow bug (Eugene Teo) [475738 475739]
-xen: fix lost packets when live migrating (Don Dutile) [469891 460874]
-xen: remove /proc/xen from fv and bare metal kernels (Don Dutile) [476534 460984]

[2.6.9-78.0.10]
-fix cpuspeed not working on intel based servers (Tony Camuso) [458156 440267]
-fix regression in cpuspeed (Prarit Bhargava) [458156 440267]
-cpuspeed: fix transition of p-states (Tony Camuso) [458156 440267]
-net: fix unix socket panic (Neil Horman) [470433 470434] {CVE-2008-5029}
-hfsplus: fix buffer overflow with a corrupted image (Anton Arapov) [469635 469636] {CVE-2008-4933}
-hfsplus: check read_mapping_page return value (Anton Arapov) [469642 469643] {CVE-2008-4934}
-hfs: fix namelength memory corruption (Anton Arapov) [470770 470771] {CVE-2008-5025}
-add range_is_allowed check to mmap_mem (Eugene Teo) [460862 460859]
-fix add range_is_allowed check regression (Vitaly Mayatskikh) [460862 460859]

[2.6.9-78.0.9]
-atkbd: cancel delayed work before freeing its structure (Jiri Pirko) [461239 461240]
-atkbd: delay executing of led switching request (Jiri Pirko) [461239 461240]
-kernel: fix copy_user on x86_64 for read of < 8 bytes (Larry Woodman) [471015 453053]
-fix diskdump failure when numa is on (Takao Indoh) [470034 457736]
-ipv4: fix byte value boundary check in ip_getsockopt (Jiri Pirko) [470196 462741]
-fix linux kernel local filesystem dos (Eugene Teo) [457863 457864] {CVE-2008-3275}
-netpoll: play nicely with bonding (Andy Gospodarek) [471391 248374]
-sched: fix isolcpus vs balance bug (Peter Zijlstra) [471222 461156]


Related CVEs


CVE-2008-3275
CVE-2008-4933
CVE-2008-4934
CVE-2008-5025
CVE-2008-5029
CVE-2008-5300
CVE-2008-5702

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 4 (i386) kernel-2.6.9-78.0.13.0.1.EL.src.rpma6e227de7d0ba9465773b16d86800ac7ELBA-2011-1796
ocfs2-2.6.9-78.0.13.0.1.EL-1.2.9-1.el4.src.rpm81ad6060dc0faf732ada177eaaa80e6c-
oracleasm-2.6.9-78.0.13.0.1.EL-2.0.5-1.el4.src.rpm7513e1523dc4750a187315b1deddebd6-
kernel-2.6.9-78.0.13.0.1.EL.i686.rpm9289a1dac99edc93967e33d58b7d013eELBA-2011-1796
kernel-devel-2.6.9-78.0.13.0.1.EL.i686.rpm2f36e741250f3fcf46eb81272cb2d433ELBA-2011-1796
kernel-doc-2.6.9-78.0.13.0.1.EL.noarch.rpmf853a764e2b1550be4b3aefc8282e146ELBA-2011-1796
kernel-hugemem-2.6.9-78.0.13.0.1.EL.i686.rpmb177f88f0fb72d2af5a513b1cbfa1b15ELBA-2011-1796
kernel-hugemem-devel-2.6.9-78.0.13.0.1.EL.i686.rpm94ffc47abd732d5451122138476617f9ELBA-2011-1796
kernel-smp-2.6.9-78.0.13.0.1.EL.i686.rpm35c8bb681037eb3394728822231d2229ELBA-2011-1796
kernel-smp-devel-2.6.9-78.0.13.0.1.EL.i686.rpma084d422764cf7b22d2146e4d7bb30beELBA-2011-1796
kernel-xenU-2.6.9-78.0.13.0.1.EL.i686.rpmeb333483c0665ca5dd13423d090dd106ELBA-2011-1796
kernel-xenU-devel-2.6.9-78.0.13.0.1.EL.i686.rpm19dd2a06dc5a863deae2becbc1318fa2ELBA-2011-1796
ocfs2-2.6.9-78.0.13.0.1.EL-1.2.9-1.el4.i686.rpme9190b58c3610ae62eb8456be31881b2-
ocfs2-2.6.9-78.0.13.0.1.ELhugemem-1.2.9-1.el4.i686.rpm2d2c92186f471a7b0eafc22adf5da216-
ocfs2-2.6.9-78.0.13.0.1.ELsmp-1.2.9-1.el4.i686.rpm484ada6817abe6e2d549e8be7eed8bac-
ocfs2-2.6.9-78.0.13.0.1.ELxenU-1.2.9-1.el4.i686.rpmc321c13900b952a69f07c2e8c997f08e-
oracleasm-2.6.9-78.0.13.0.1.EL-2.0.5-1.el4.i686.rpm00c0b0b2e86c66dcf695f4cbbcdb87d1-
oracleasm-2.6.9-78.0.13.0.1.ELhugemem-2.0.5-1.el4.i686.rpm84e066515229c9194604a9cd4f0b349b-
oracleasm-2.6.9-78.0.13.0.1.ELsmp-2.0.5-1.el4.i686.rpm955e24a6473a316f329ace6dd0dc59a6-
oracleasm-2.6.9-78.0.13.0.1.ELxenU-2.0.5-1.el4.i686.rpm13b7fccb0016831972982d6d1fd39e76-
Oracle Linux 4 (ia64) kernel-2.6.9-78.0.13.0.1.EL.src.rpma6e227de7d0ba9465773b16d86800ac7ELBA-2011-1796
ocfs2-2.6.9-78.0.13.0.1.EL-1.2.9-1.el4.src.rpm81ad6060dc0faf732ada177eaaa80e6c-
oracleasm-2.6.9-78.0.13.0.1.EL-2.0.5-1.el4.src.rpm7513e1523dc4750a187315b1deddebd6-
kernel-2.6.9-78.0.13.0.1.EL.ia64.rpm5cfc20972aa196088f5fa673e6c00376ELBA-2011-1796
kernel-devel-2.6.9-78.0.13.0.1.EL.ia64.rpmb8cc293b2cb2085269956e5f59f3ccedELBA-2011-1796
kernel-doc-2.6.9-78.0.13.0.1.EL.noarch.rpmf853a764e2b1550be4b3aefc8282e146ELBA-2011-1796
kernel-largesmp-2.6.9-78.0.13.0.1.EL.ia64.rpm961194cee164197e8d5043bad1081cf0ELBA-2011-1796
kernel-largesmp-devel-2.6.9-78.0.13.0.1.EL.ia64.rpme7644b475e45296ccd52aecff460e9a2ELBA-2011-1796
ocfs2-2.6.9-78.0.13.0.1.EL-1.2.9-1.el4.ia64.rpma47d77cb094bd2c04a157bd626c2b011-
ocfs2-2.6.9-78.0.13.0.1.ELlargesmp-1.2.9-1.el4.ia64.rpm2059ada7a397739016550c07f543a796-
oracleasm-2.6.9-78.0.13.0.1.EL-2.0.5-1.el4.ia64.rpme9b2bed2215072d73e596a2805dcf2e3-
oracleasm-2.6.9-78.0.13.0.1.ELlargesmp-2.0.5-1.el4.ia64.rpm1707f9d4cf62ed4f4c24fa92835e7c16-
Oracle Linux 4 (x86_64) kernel-2.6.9-78.0.13.0.1.EL.src.rpma6e227de7d0ba9465773b16d86800ac7ELBA-2011-1796
ocfs2-2.6.9-78.0.13.0.1.EL-1.2.9-1.el4.src.rpm81ad6060dc0faf732ada177eaaa80e6c-
oracleasm-2.6.9-78.0.13.0.1.EL-2.0.5-1.el4.src.rpm7513e1523dc4750a187315b1deddebd6-
kernel-2.6.9-78.0.13.0.1.EL.x86_64.rpm1a904efe75a08c3168ef80bd8d7e0509ELBA-2011-1796
kernel-devel-2.6.9-78.0.13.0.1.EL.x86_64.rpm6483430b7b9e16d69bed6017711e6b51ELBA-2011-1796
kernel-doc-2.6.9-78.0.13.0.1.EL.noarch.rpmf853a764e2b1550be4b3aefc8282e146ELBA-2011-1796
kernel-largesmp-2.6.9-78.0.13.0.1.EL.x86_64.rpme864d5e8285f8e2cc1304117e453b76bELBA-2011-1796
kernel-largesmp-devel-2.6.9-78.0.13.0.1.EL.x86_64.rpmc0a223294b2b259ea036aa73f94c53ffELBA-2011-1796
kernel-smp-2.6.9-78.0.13.0.1.EL.x86_64.rpmd5ab9df76eaa1cdfc1bbb49b6fa1ff8cELBA-2011-1796
kernel-smp-devel-2.6.9-78.0.13.0.1.EL.x86_64.rpmd69250369e062c84e4d420c1377154c3ELBA-2011-1796
kernel-xenU-2.6.9-78.0.13.0.1.EL.x86_64.rpm541fecd68d241993044d32146d66506aELBA-2011-1796
kernel-xenU-devel-2.6.9-78.0.13.0.1.EL.x86_64.rpmf2c94ab870b677a650db2414c5e10a71ELBA-2011-1796
ocfs2-2.6.9-78.0.13.0.1.EL-1.2.9-1.el4.x86_64.rpm537d50d63f232477bb9f52700ec6f2a4-
ocfs2-2.6.9-78.0.13.0.1.ELlargesmp-1.2.9-1.el4.x86_64.rpmabb609d16cc63360f6ac85e9e7c7f738-
ocfs2-2.6.9-78.0.13.0.1.ELsmp-1.2.9-1.el4.x86_64.rpma36e5c9e6c330c9045ece610393fcd0b-
ocfs2-2.6.9-78.0.13.0.1.ELxenU-1.2.9-1.el4.x86_64.rpm305a01fa0f93c2f768db864724101fad-
oracleasm-2.6.9-78.0.13.0.1.EL-2.0.5-1.el4.x86_64.rpm32665adc90de593be218dccd562d2067-
oracleasm-2.6.9-78.0.13.0.1.ELlargesmp-2.0.5-1.el4.x86_64.rpm3d945489ea3f7cc12fac6e968f898e67-
oracleasm-2.6.9-78.0.13.0.1.ELsmp-2.0.5-1.el4.x86_64.rpmb41a15b36826a5f38824fbc153b42fe0-
oracleasm-2.6.9-78.0.13.0.1.ELxenU-2.0.5-1.el4.x86_64.rpm45a5ae30b81c369030f8f7c10755425a-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete