ELSA-2015-1137

ELSA-2015-1137 - kernel security and bug fix update

Type:SECURITY
Severity:IMPORTANT
Release Date:2015-06-23

Description


[3.10.0-229.7.2]
- Oracle Linux certificates (Alexey Petrenko)

[3.10.0-229.7.2]
- [fs] pipe: fix pipe corruption and iovec overrun on partial copy (Seth Jennings) [1202861 1198843] {CVE-2015-1805}

[3.10.0-229.7.1]
- [scsi] storvsc: get rid of overly verbose warning messages (Vitaly Kuznetsov) [1215770 1206437]
- [scsi] storvsc: force discovery of LUNs that may have been removed (Vitaly Kuznetsov) [1215770 1206437]
- [scsi] storvsc: in responce to a scan event, scan the host (Vitaly Kuznetsov) [1215770 1206437]
- [scsi] storvsc: NULL pointer dereference fix (Vitaly Kuznetsov) [1215770 1206437]
- [virtio] defer config changed notifications (David Gibson) [1220278 1196009]
- [virtio] unify config_changed handling (David Gibson) [1220278 1196009]
- [x86] kernel: Remove a bogus 'ret_from_fork' optimization (Mateusz Guzik) [1209234 1209235] {CVE-2015-2830}
- [kernel] futex: Mention key referencing differences between shared and private futexes (Larry Woodman) [1219169 1205862]
- [kernel] futex: Ensure get_futex_key_refs() always implies a barrier (Larry Woodman) [1219169 1205862]
- [scsi] megaraid_sas: revert: Add release date and update driver version (Tomas Henzl) [1216213 1207175]
- [kernel] module: set nx before marking module MODULE_STATE_COMING (Hendrik Brueckner) [1214788 1196977]
- [kernel] module: Clean up ro/nx after early module load failures (Pratyush Anand) [1214403 1202866]
- [drm] radeon: fix kernel segfault in hwmonitor (Jerome Glisse) [1213467 1187817]
- [fs] btrfs: make xattr replace operations atomic (Eric Sandeen) [1205086 1205873]
- [x86] mm: Linux stack ASLR implementation (Jacob Tanenbaum) [1195684 1195685] {CVE-2015-1593}
- [net] netfilter: nf_tables: fix flush ruleset chain dependencies (Jiri Pirko) [1192880 1192881] {CVE-2015-1573}
- [fs] isofs: Fix unchecked printing of ER records (Mateusz Guzik) [1180482 1180483] {CVE-2014-9584}
- [security] keys: memory corruption or panic during key garbage collection (Jacob Tanenbaum) [1179851 1179852] {CVE-2014-9529}
- [fs] isofs: infinite loop in CE record entries (Jacob Tanenbaum) [1175246 1175248] {CVE-2014-9420}

[3.10.0-229.6.1]
- [net] tcp: abort orphan sockets stalling on zero window probes (Florian Westphal) [1215924 1151756]
- [x86] crypto: aesni - fix memory usage in GCM decryption (Kurt Stutsman) [1213331 1212178] {CVE-2015-3331}

[3.10.0-229.5.1]
- [powerpc] mm: thp: Add tracepoints to track hugepage invalidate (Gustavo Duarte) [1212977 1199016]
- [powerpc] mm: Use read barrier when creating real_pte (Gustavo Duarte) [1212977 1199016]
- [powerpc] mm: thp: Use ACCESS_ONCE when loading pmdp (Gustavo Duarte) [1212977 1199016]
- [powerpc] mm: thp: Invalidate with vpn in loop (Gustavo Duarte) [1212977 1199016]
- [powerpc] mm: thp: Handle combo pages in invalidate (Gustavo Duarte) [1212977 1199016]
- [powerpc] mm: thp: Invalidate old 64K based hash page mapping before insert of 4k pte (Gustavo Duarte) [1212977 1199016]
- [powerpc] mm: thp: Don't recompute vsid and ssize in loop on invalidate (Gustavo Duarte) [1212977 1199016]
- [powerpc] mm: thp: Add write barrier after updating the valid bit (Gustavo Duarte) [1212977 1199016]


Related CVEs


CVE-2014-9529
CVE-2014-9584
CVE-2015-1805
CVE-2014-9420
CVE-2015-1573
CVE-2015-1593
CVE-2015-2830

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 7 (x86_64) kernel-3.10.0-229.7.2.el7.src.rpm313f2ec58cf3b9d9c967d46c011989f9ELSA-2017-2473-1
kernel-3.10.0-229.7.2.el7.x86_64.rpme6e7779118278d7dd4fbe8ca780a43d0ELSA-2017-2473-1
kernel-abi-whitelists-3.10.0-229.7.2.el7.noarch.rpmdf9312452e5e3ecd5c1f7a30b8e8f29cELSA-2017-2473-1
kernel-debug-3.10.0-229.7.2.el7.x86_64.rpm9e0d1dd4997a73f4b915e995e8cce3daELSA-2017-2473-1
kernel-debug-devel-3.10.0-229.7.2.el7.x86_64.rpm0051c9fe012e16249771f60b6b47c07dELSA-2017-2473-1
kernel-devel-3.10.0-229.7.2.el7.x86_64.rpm95cd1132e93da18caf80c72af659f8e3ELSA-2017-2473-1
kernel-doc-3.10.0-229.7.2.el7.noarch.rpma57b3279e5a4e9de9ce2b798ef1f357aELSA-2017-2473-1
kernel-headers-3.10.0-229.7.2.el7.x86_64.rpm8b895e59ceb0d6ff69b836b689d7fe67ELSA-2017-2473-1
kernel-tools-3.10.0-229.7.2.el7.x86_64.rpme3f34f3978a01e52cacb5a992eac9c8cELSA-2017-2473-1
kernel-tools-libs-3.10.0-229.7.2.el7.x86_64.rpm86f242e341f122ac548e5a9240cc4880ELSA-2017-2473-1
kernel-tools-libs-devel-3.10.0-229.7.2.el7.x86_64.rpm3f9645151ea08dc6f9b99ff586f0bed4ELSA-2017-2473-1
perf-3.10.0-229.7.2.el7.x86_64.rpm2bc1b5e8c38c0b831ab3204d3c9f80b8ELSA-2017-2473-1
python-perf-3.10.0-229.7.2.el7.x86_64.rpm0ac1158ed08245b6e74f65bc35dac5a6ELSA-2017-2473-1



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete