OVMSA-2017-0040

OVMSA-2017-0040 - Unbreakable Enterprise kernel security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2017-02-09

Description


[3.8.13-118.16.3]
- crypto: algif_hash - Only export and import on sockets with data (Herbert Xu) [Orabug: 25417805] {CVE-2016-8646}
- USB: usbfs: fix potential infoleak in devio (Kangjie Lu) [Orabug: 25462760] {CVE-2016-4482}
- net: fix infoleak in llc (Kangjie Lu) [Orabug: 25462807] {CVE-2016-4485}
- af_unix: Guard against other == sk in unix_dgram_sendmsg (Rainer Weikusat) [Orabug: 25463996] {CVE-2013-7446}
- unix: avoid use-after-free in ep_remove_wait_queue (Rainer Weikusat) [Orabug: 25463996] {CVE-2013-7446}


Related CVEs


CVE-2013-7446
CVE-2016-4482
CVE-2016-8646
CVE-2016-4485

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle VM 3.3 (x86_64) kernel-uek-3.8.13-118.16.3.el6uek.src.rpmc99f44dd3c5d64cd707d56a6ee7bff20701551fd09abbd71ba1f14dda440359dOVMSA-2025-0001ovm3_x86_64_3.3_patch
kernel-uek-3.8.13-118.16.3.el6uek.x86_64.rpmf4850b60abfb5a3e820693b8a21844f9bfe922bf6983e5b7ad2bf73b1258816dOVMSA-2025-0001ovm3_x86_64_3.3_patch
kernel-uek-firmware-3.8.13-118.16.3.el6uek.noarch.rpmb252a4ff692e36d520057d1c250a1b8fa7219c10de9381cc3f168c418303de27OVMSA-2025-0001ovm3_x86_64_3.3_patch



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete