ELSA-2017-3565

ELSA-2017-3565 - Unbreakable Enterprise kernel security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2017-05-16

Description


kernel-uek
[4.1.12-94.3.4]
- ipv6: catch a null skb before using it in a DTRACE (Shannon Nelson) [Orabug: 26075879]
- sparc64: Do not retain old VM_SPARC_ADI flag when protection changes on page (Khalid Aziz) [Orabug: 26038830]

[4.1.12-94.3.3]
- nfsd: stricter decoding of write-like NFSv2/v3 ops (J. Bruce Fields) [Orabug: 25986971] {CVE-2017-7895}

[4.1.12-94.3.2]
- sparc64: Detect DAX ra+pgsz when hvapi minor doesn't indicate it (Rob Gardner) [Orabug: 25997533]
- sparc64: DAX memory will use RA+PGSZ feature in HV (Rob Gardner) [Orabug: 25997533] [Orabug: 25931417]
- sparc64: Disable DAX flow control (Rob Gardner) [Orabug: 25997226]
- sparc64: DAX memory needs persistent mappings (Rob Gardner) [Orabug: 25997137]
- sparc64: Fix incorrect error print in DAX driver when validating ccb (Sanath Kumar) [Orabug: 25996975]
- sparc64: DAX request for non 4MB memory should return with unique errno (Sanath Kumar) [Orabug: 25996823]
- sparc64: DAX request to mmap non 4MB memory should fail with a debug print (Sanath Kumar) [Orabug: 25996823]
- sparc64: DAX request for non 4MB memory should return with unique errno (Sanath Kumar) [Orabug: 25996823]
- sparc64: Incorrect print by DAX driver when old driver API is used (Sanath Kumar) [Orabug: 25996790]
- sparc64: DAX request to dequeue half of a long CCB should not succeed (Sanath Kumar) [Orabug: 25996747]
- sparc64: dax_overflow_check reports incorrect data (Sanath Kumar) [Orabug: 25996655]
- sparc64: Ignored DAX ref count causes lockup (Rob Gardner) [Orabug: 25996628]
- sparc64: disable dax page range checking on RA (Rob Gardner) [Orabug: 25996546]
- sparc64: Oracle Data Analytics Accelerator (DAX) driver (Sanath Kumar) [Orabug: 25996522]
- sparc64: Add DAX hypervisor services (Allen Pais) [Orabug: 25996475]
- sparc64: create/destroy cpu sysfs dynamically (Atish Patra) [Orabug: 21775890] [Orabug: 25216469]
- megaraid: Fix unaligned warning (Allen Pais) [Orabug: 24817799]

[4.1.12-94.3.1]
- Re-enable SDP for uek-nano kernel (Ashok Vairavan) [Orabug: 25968572]
- xsigo: Compute node crash on FC failover (Pradeep Gopanapalli) [Orabug: 25946533]
- NVMe: Set affinity after allocating request queues (Keith Busch) [Orabug: 25945973]
- nvme: use an integer value to Linux errno values (Christoph Hellwig) [Orabug: 25945973]
- blk-mq: fix racy updates of rq->errors (Christoph Hellwig) [Orabug: 25945973]
- x86/apic: Handle zero vector gracefully in clear_vector_irq() (Keith Busch) [Orabug: 24515998]
- PCI: Prevent VPD access for QLogic ISP2722 (Ethan Zhao) [Orabug: 24819170]
- PCI: Prevent VPD access for buggy devices (Babu Moger) [Orabug: 24819170]
- ipv6: Skip XFRM lookup if dst_entry in socket cache is valid (Jakub Sitnicki) [Orabug: 25525433]
- Btrfs: don't BUG_ON() in btrfs_orphan_add (Josef Bacik) [Orabug: 25534945]
- Btrfs: clarify do_chunk_alloc()'s return value (Liu Bo) [Orabug: 25534945]
- btrfs: flush_space: treat return value of do_chunk_alloc properly (Alex Lyakas) [Orabug: 25534945]
- Revert '[SCSI] libiscsi: Reduce locking contention in fast path' (Ashish Samant) [Orabug: 25721518]
- qla2xxx: Allow vref count to timeout on vport delete. (Joe Carnuccio) [Orabug: 25862953]
- Drivers: hv: kvp: fix IP Failover (Vitaly Kuznetsov) [Orabug: 25866691]
- Drivers: hv: util: Pass the channel information during the init call (K. Y. Srinivasan) [Orabug: 25866691]
- Drivers: hv: utils: run polling callback always in interrupt context (Olaf Hering) [Orabug: 25866691]
- Drivers: hv: util: Increase the timeout for util services (K. Y. Srinivasan) [Orabug: 25866691]
- Drivers: hv: kvp: check kzalloc return value (Vitaly Kuznetsov) [Orabug: 25866691]
- Drivers: hv: fcopy: dynamically allocate smsg_out in fcopy_send_data() (Vitaly Kuznetsov)
- Drivers: hv: vss: full handshake support (Vitaly Kuznetsov) [Orabug: 25866691]
- xen: Make VPMU init message look less scary (Juergen Gross) [Orabug: 25873416]
- udp: properly support MSG_PEEK with truncated buffers (Eric Dumazet) [Orabug: 25876652] {CVE-2016-10229}


Related CVEs


CVE-2017-7895

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 6 (x86_64) dtrace-modules-4.1.12-94.3.4.el6uek-0.6.0-4.el6.src.rpmb18318996fb26b70175b232a84e8e738-
kernel-uek-4.1.12-94.3.4.el6uek.src.rpm10e0812a7509c33f9a30a344f3c4ae9dELSA-2017-3605
dtrace-modules-4.1.12-94.3.4.el6uek-0.6.0-4.el6.x86_64.rpme2cfd79998102a6e67c00843dbad75fc-
kernel-uek-4.1.12-94.3.4.el6uek.x86_64.rpm81eee79c21708069820be0b1378f3753ELSA-2017-3605
kernel-uek-debug-4.1.12-94.3.4.el6uek.x86_64.rpm905fdb0013fc13c51e098092bb6138ceELSA-2017-3605
kernel-uek-debug-devel-4.1.12-94.3.4.el6uek.x86_64.rpmba7971373c677d8459af3bfcd7b59009ELSA-2017-3605
kernel-uek-devel-4.1.12-94.3.4.el6uek.x86_64.rpm2a555681cbca6420eac6cfd02f5aa494ELSA-2017-3605
kernel-uek-doc-4.1.12-94.3.4.el6uek.noarch.rpm1303e164ea1f4c500fe065f15a462d35ELSA-2017-3605
kernel-uek-firmware-4.1.12-94.3.4.el6uek.noarch.rpm3e39bb671b0c60130fdd62ce84a5a6a0ELSA-2017-3605
Oracle Linux 7 (x86_64) dtrace-modules-4.1.12-94.3.4.el7uek-0.6.0-4.el7.src.rpm5d0a01fb575e7df4e885e909c880445b-
kernel-uek-4.1.12-94.3.4.el7uek.src.rpmc026ffd42636fdf7f9425ca5c09682c4ELSA-2017-3605
dtrace-modules-4.1.12-94.3.4.el7uek-0.6.0-4.el7.x86_64.rpm323ac97611eee92114928a866ef3b52b-
kernel-uek-4.1.12-94.3.4.el7uek.x86_64.rpmc585afbb14d20d88485ae637d2c0bc73ELSA-2017-3605
kernel-uek-debug-4.1.12-94.3.4.el7uek.x86_64.rpm84b516f6b0100e26cb845793687739b3ELSA-2017-3605
kernel-uek-debug-devel-4.1.12-94.3.4.el7uek.x86_64.rpm12c7d108b5c5e21982855aac51a919ceELSA-2017-3605
kernel-uek-devel-4.1.12-94.3.4.el7uek.x86_64.rpmcd4512d10b6a9c4d5fa438a9bc9d09b3ELSA-2017-3605
kernel-uek-doc-4.1.12-94.3.4.el7uek.noarch.rpm842ed9e79aca2ac09a5e067a5b8795f0ELSA-2017-3605
kernel-uek-firmware-4.1.12-94.3.4.el7uek.noarch.rpm7f43b9c4f34ecddc6f62734c2e3c8803ELSA-2017-3605



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete