LWN.net Logo

Oracle alert ELSA-2012-2013 (kernel)

From:  Errata Announcements for Oracle Linux <el-errata@oss.oracle.com>
To:  el-errata@oss.oracle.com
Subject:  [El-errata] ELSA-2012-2013 Moderate: Oracle Linux 5 Unbreakable Enterprise kernel security update
Date:  Mon, 21 May 2012 16:03:04 -0700
Message-ID:  <4FBAC9A8.8050401@oracle.com>
Archive-link:  Article, Thread

Oracle Linux Security Advisory ELSA-2012-2013 The following updated rpms for Oracle Linux 5 have been uploaded to the Unbreakable Linux Network: i386: kernel-uek-2.6.39-100.7.1.el5uek.i686.rpm kernel-uek-debug-2.6.39-100.7.1.el5uek.i686.rpm kernel-uek-debug-devel-2.6.39-100.7.1.el5uek.i686.rpm kernel-uek-devel-2.6.39-100.7.1.el5uek.i686.rpm kernel-uek-doc-2.6.39-100.7.1.el5uek.noarch.rpm kernel-uek-firmware-2.6.39-100.7.1.el5uek.noarch.rpm x86_64: kernel-uek-firmware-2.6.39-100.7.1.el5uek.noarch.rpm kernel-uek-doc-2.6.39-100.7.1.el5uek.noarch.rpm kernel-uek-2.6.39-100.7.1.el5uek.x86_64.rpm kernel-uek-devel-2.6.39-100.7.1.el5uek.x86_64.rpm kernel-uek-debug-devel-2.6.39-100.7.1.el5uek.x86_64.rpm kernel-uek-debug-2.6.39-100.7.1.el5uek.x86_64.rpm SRPMS: http://oss.oracle.com/ol5/SRPMS-updates/kernel-uek-2.6.39... Users with Oracle Linux Premier Support can now use Ksplice to patch against this Security Advisory. We recommend that all users of Oracle Linux 5 install these updates. Users of Ksplice Uptrack can install these updates by running : # /usr/sbin/uptrack-upgrade -y On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf, these updates will be installed automatically and you do not need to take any additional action. Description of changes: * CVE-2011-4086: Denial of service in journaling block device. The journal block device assumed that a buffer marked as unwritten or delay could be live without checking if the buffer was mapped. An unprivileged local user could use this flaw to crash the system. * CVE-2012-1601: Denial of service in KVM VCPU creation. Inconsistent state in the creation of KVM virtual CPU's could lead to NULL pointer dereferences. A unprivileged local user could use this flaw to crash the system. [2.6.39-100.7.1.el5uek] - KVM: Ensure all vcpus are consistent with in-kernel irqchip settings (Avi Kivity) [Bugdb: 13871] {CVE-2012-1601} - jbd2: clear BH_Delay & BH_Unwritten in journal_unmap_buffer (Eric Sandeen) [Bugdb: 13871] {CVE-2011-4086} _______________________________________________ El-errata mailing list El-errata@oss.oracle.com http://oss.oracle.com/mailman/listinfo/el-errata


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds