ELSA-2011-1189

ELSA-2011-1189 - kernel security, bug fix, and enhancement update

Type:SECURITY
Severity:IMPORTANT
Release Date:2011-08-23

Description



[2.6.32-131.12.1.el6]
- [netdrv] be2net: clear intr bit in be_probe() (Ivan Vecera) [726308 722596]

[2.6.32-131.11.1.el6]
- [mm] hold the page lock until after set_page_stable_node (Andrea Arcangeli) [726095 683658]
- [netdrv] be2net: remove certain cmd failure logging (Ivan Vecera) [725329 719304]
- [net] nl80211: missing check for valid SSID size in scan operation (Stanislaw Gruszka) [718157 718158] {CVE-2011-2517}
- [net] bluetooth: l2cap and rfcomm: fix 1 byte infoleak to userspace. (Thomas Graf) [703022 703023] {CVE-2011-2492}
- [net] inet_diag: fix validation of user data in inet_diag_bc_audit() (Thomas Graf) [714540 714541] {CVE-2011-2213}
- [fs] proc: restrict access to /proc/PID/io (Oleg Nesterov) [716829 716830] {CVE-2011-2495}
- [fs] validate size of EFI GUID partition entries (Anton Arapov) [703029 703030] {CVE-2011-1776}
- [fs] ext4: Fix max file size and logical block counting of extent format file (Lukas Czerner) [722568 722569] {CVE-2011-2695}
- [virt] kvm: Disable device assignment without interrupt remapping (Alex Williamson) [716306 711504] {CVE-2011-1898}
- [virt] iommu-api: Extension to check for interrupt remapping (Alex Williamson) [716306 711504] {CVE-2011-1898}
- [netdrv] r8169: fix Rx checksum offloading bugs (Ivan Vecera) [723807 635596]
- [netdrv] be2net: changes for BE3 native mode support (Ivan Vecera) [723820 695231]

[2.6.32-131.10.1.el6]
- [virt] ksm: fix race between ksmd and exiting task (Andrea Arcangeli) [710340 710341] {CVE-2011-2183}
- [kernel] proc: signedness issue in next_pidmap() (Jerome Marchand) [697824 697825] {CVE-2011-1593}
- [net] bluetooth: Prevent buffer overflow in l2cap config request (Jiri Pirko) [716809 716810] {CVE-2011-2497}
- [fs] NLM: Don't hang forever on NLM unlock requests (Jeff Layton) [709548 709549] {CVE-2011-2491}
- [fs] NFS: Fix NFSv3 exclusive open semantics (Jeff Layton) [719925 694210]
- [fs] GFS2: Incorrect inode state during deallocation (Steven Whitehouse) [714982 712139]
- [virt] KVM: Fix register corruption in pvclock_scale_delta (Avi Kivity) [719910 712102]
- [netdrv] ehea: Fix memory hotplug oops (Steve Best) [720914 702036]
- [net] Fix memory leak/corruption on VLAN GRO_DROP (Herbert Xu) [695175 695176] {CVE-2011-1576}
- [md] Fix resync hang after surprise removal (James Paradis) [719928 707268]
- GFS2: make sure fallocate bytes is a multiple of blksize (Benjamin Marzinski) [720863 695763] {CVE-2011-2689}
- [kernel] Prevent rt_sigqueueinfo and rt_tgsigqueueinfo from spoofing the signal code (Oleg Nesterov) [715521 690033] {CVE-2011-1182}
- [redhat] config: enable parallel port printer support (Aristeu Rozanski) [713827 635968]

[2.6.32-131.9.1.el6]
- [scsi] cciss: Annotate cciss_kdump_soft_reset and cciss_sent_reset as __devinit (Tomas Henzl) [715397 698268]
- [scsi] cciss: Don't wait forever for soft reset to complete, give up after awhile (Tomas Henzl) [715397 698268]
- [scsi] cciss: use cmd_alloc not cmd_special_alloc for the kdump soft reset command (Tomas Henzl) [715397 698268]
- [scsi] cciss: do not use bit 2 doorbell reset (Tomas Henzl) [715397 698268]
- [scsi] cciss: do not attempt PCI power management reset method if we know it won't work (Tomas Henzl) [715397 698268]
- [scsi] cciss: increase timeouts for post-reset no-ops (Tomas Henzl) [715397 698268]
- [scsi] cciss: remove superfluous sleeps around reset code (Tomas Henzl) [715397 698268]
- [scsi] cciss: do soft reset if hard reset is broken (Tomas Henzl) [715397 698268]
- [scsi] cciss: clarify messages around reset behavior (Tomas Henzl) [715397 698268]
- [scsi] cciss: increase time to wait for board reset to start (Tomas Henzl) [715397 698268]
- [scsi] cciss: factor out irq_request code (Tomas Henzl) [715397 698268]
- [scsi] cciss: factor out scatterlist allocation functions (Tomas Henzl) [715397 698268]
- [scsi] cciss: factor out command pool allocation functions (Tomas Henzl) [715397 698268]
- [scsi] cciss: use new doorbell-bit-5 reset method (Tomas Henzl) [715397 698268]
- [scsi] cciss: wait longer for no-op to complete after resetting controller (Tomas Henzl) [715397 698268]
- [scsi] cciss: do a better job of detecting controller reset failure (Tomas Henzl) [715397 698268]
- [scsi] hpsa: do not attempt PCI PM reset if we know it will not work (Tomas Henzl) [715397 698268]
- [scsi] hpsa: remove superfluous sleeps around reset code (Tomas Henzl) [715397 698268]
- [scsi] hpsa: do soft reset if hard reset is broken (Tomas Henzl) [715397 698268]
- [scsi] hpsa: clarify messages around reset behavior (Tomas Henzl) [715397 698268]
- [scsi] hpsa: factor out irq request code (Tomas Henzl) [715397 698268]
- [scsi] hpsa: factor out cmd_pool allocation functions (Tomas Henzl) [715397 698268]
- [scsi] hpsa: do not use bit 2 doorbell reset, it causes NMIs (Tomas Henzl) [715397 698268]
- [scsi] hpsa: wait longer for no-op to complete after resetting controller (Tomas Henzl) [715397 698268]
- [scsi] hpsa: use new doorbell-bit-5 reset method (Tomas Henzl) [715397 698268]
- [scsi] hpsa: adjust timing of post-reset sleeps (Tomas Henzl) [715397 698268]
- [scsi] hpsa: do a better job of detecting controller reset failure (Tomas Henzl) [715397 698268]

[2.6.32-131.8.1.el6]
- [fs] GFS2: force a log flush when invalidating the rindex glock (Benjamin Marzinski) [717018 702263]

[2.6.32-131.7.1.el6]
- [virt] xen: bump memory limit for x86_64 domU PV guest to 128Gb (Igor Mammedov) [716539 669739]


Related CVEs


CVE-2011-1182
CVE-2011-1576
CVE-2011-1593
CVE-2011-1776
CVE-2011-1898
CVE-2011-2183
CVE-2011-2213
CVE-2011-2491
CVE-2011-2492
CVE-2011-2495
CVE-2011-2497
CVE-2011-2517
CVE-2011-2689
CVE-2011-2695

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 6 (i386) kernel-2.6.32-131.12.1.el6.src.rpm9ea904f1fd8e5f35e3eb1f9186f0558bELSA-2021-9212
kernel-2.6.32-131.12.1.el6.i686.rpm6a4727b4e78b6678db9b22932060d89dELSA-2021-9212
kernel-debug-2.6.32-131.12.1.el6.i686.rpm0337d41fbc9c13b082f7abf37f41abc4ELSA-2021-9212
kernel-debug-devel-2.6.32-131.12.1.el6.i686.rpm5b4429f4345ffb5121f46ce6c20c88e9ELSA-2021-9212
kernel-devel-2.6.32-131.12.1.el6.i686.rpm75c4942bd08f66ba2217c7813e52842aELSA-2021-9212
kernel-doc-2.6.32-131.12.1.el6.noarch.rpmdee424852f72f2ae4e7a63edd3781e05ELSA-2021-9212
kernel-firmware-2.6.32-131.12.1.el6.noarch.rpm2485bfb18a674d77a1fd359a9dcb377dELSA-2021-9212
kernel-headers-2.6.32-131.12.1.el6.i686.rpm74c1a7df6877032a27ad23e6b359f0b7ELSA-2021-9212
perf-2.6.32-131.12.1.el6.i686.rpmdd0a01b8b070a6e541f71bb9104f441bELSA-2021-9212
Oracle Linux 6 (x86_64) kernel-2.6.32-131.12.1.el6.src.rpm9ea904f1fd8e5f35e3eb1f9186f0558bELSA-2021-9212
kernel-2.6.32-131.12.1.el6.x86_64.rpm786063463a58bfdc3b52c3041476ceacELSA-2021-9212
kernel-debug-2.6.32-131.12.1.el6.x86_64.rpm21339522029d32a5b8d2c962be4c1936ELSA-2021-9212
kernel-debug-devel-2.6.32-131.12.1.el6.x86_64.rpma75feef2232be74432748bed9d7dce40ELSA-2021-9212
kernel-devel-2.6.32-131.12.1.el6.x86_64.rpm1982948aec30194fc3ebc957d13c134dELSA-2021-9212
kernel-doc-2.6.32-131.12.1.el6.noarch.rpmdee424852f72f2ae4e7a63edd3781e05ELSA-2021-9212
kernel-firmware-2.6.32-131.12.1.el6.noarch.rpm2485bfb18a674d77a1fd359a9dcb377dELSA-2021-9212
kernel-headers-2.6.32-131.12.1.el6.x86_64.rpm777c400e17de5b5b046ccb86325b4a2cELSA-2021-9212
perf-2.6.32-131.12.1.el6.x86_64.rpm977e3fe91e83c8db3a4bc013578d2cbbELSA-2021-9212



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete