ELSA-2017-3640

ELSA-2017-3640 - Unbreakable Enterprise kernel security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2017-11-13

Description


[4.1.12-103.9.4]
- thp: run vma_adjust_trans_huge() outside i_mmap_rwsem (Kirill A. Shutemov) [Orabug: 27026180]

[4.1.12-103.9.3]
- selinux: fix off-by-one in setprocattr (Stephen Smalley) [Orabug: 27001717] {CVE-2017-2618} {CVE-2017-2618} {CVE-2017-2618}
- sysctl: Drop reference added by grab_header in proc_sys_readdir (Zhou Chengming) [Orabug: 27036903] {CVE-2016-9191} {CVE-2016-9191} {CVE-2016-9191}
- KEYS: prevent KEYCTL_READ on negative key (Eric Biggers) [Orabug: 27050248] {CVE-2017-12192}
- IB/ipoib: For sendonly join free the multicast group on leave (Christoph Lameter) [Orabug: 27077718]
- IB/ipoib: increase the max mcast backlog queue (Doug Ledford) [Orabug: 27077718]
- IB/ipoib: Make sendonly multicast joins create the mcast group (Doug Ledford) [Orabug: 27077718]
- IB/ipoib: Expire sendonly multicast joins (Christoph Lameter) [Orabug: 27077718]
- IB/ipoib: Suppress warning for send only join failures (Jason Gunthorpe) [Orabug: 27077718]
- IB/ipoib: Clean up send-only multicast joins (Doug Ledford) [Orabug: 27077718]
- netlink: allow to listen 'all' netns (Nicolas Dichtel) [Orabug: 27077944]
- netlink: rename private flags and states (Nicolas Dichtel) [Orabug: 27077944]
- netns: use a spin_lock to protect nsid management (Nicolas Dichtel) [Orabug: 27077944]
- netns: notify new nsid outside __peernet2id() (Nicolas Dichtel) [Orabug: 27077944]
- netns: rename peernet2id() to peernet2id_alloc() (Nicolas Dichtel) [Orabug: 27077944]
- netns: always provide the id to rtnl_net_fill() (Nicolas Dichtel) [Orabug: 27077944]
- netns: returns always an id in __peernet2id() (Nicolas Dichtel) [Orabug: 27077944]
- Hang/soft lockup in d_invalidate with simultaneous calls (Al Viro) [Orabug: 27052681]


Related CVEs


CVE-2017-2618
CVE-2016-9191
CVE-2017-12192

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 6 (x86_64) kernel-uek-4.1.12-103.9.4.el6uek.src.rpm7fb62caf769494b866b4ef70bd92f02bELSA-2021-9215
kernel-uek-4.1.12-103.9.4.el6uek.x86_64.rpma1d80ed2c41e40e965eb56d69d79b3a0ELSA-2021-9215
kernel-uek-debug-4.1.12-103.9.4.el6uek.x86_64.rpmd0471f45e97c89bd30767fa72dfd7933ELSA-2021-9215
kernel-uek-debug-devel-4.1.12-103.9.4.el6uek.x86_64.rpmc87ea61b7a43f169836f4d78d7a562dfELSA-2021-9215
kernel-uek-devel-4.1.12-103.9.4.el6uek.x86_64.rpm7f5582d150233f62f7f11caaf7d7204fELSA-2021-9215
kernel-uek-doc-4.1.12-103.9.4.el6uek.noarch.rpm129667cf92e623aae1d17350375e9c85ELSA-2021-9215
kernel-uek-firmware-4.1.12-103.9.4.el6uek.noarch.rpm6e0d7b8bb1c2652894d20f730c0f3b06ELSA-2021-9215
Oracle Linux 7 (x86_64) kernel-uek-4.1.12-103.9.4.el7uek.src.rpm564ae51b15ea02defb95670bb4b0da46ELSA-2021-9220
kernel-uek-4.1.12-103.9.4.el7uek.x86_64.rpm0b4672973698f900c3fd1a79cccc923cELSA-2021-9220
kernel-uek-debug-4.1.12-103.9.4.el7uek.x86_64.rpmb3f4de591cefad3c7cb57f7f47c85451ELSA-2021-9220
kernel-uek-debug-devel-4.1.12-103.9.4.el7uek.x86_64.rpmad94de2f6e361706898d317def7ead30ELSA-2021-9220
kernel-uek-devel-4.1.12-103.9.4.el7uek.x86_64.rpmd5ef9dafb995dc8ad67f8e3a80f2af09ELSA-2021-9220
kernel-uek-doc-4.1.12-103.9.4.el7uek.noarch.rpm5eb89791e34b8e618c28c1cdfd1932f7ELSA-2021-9220
kernel-uek-firmware-4.1.12-103.9.4.el7uek.noarch.rpmd25018a9a44885d83c554bf250c951d7ELSA-2021-9215



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete