Oracle alert ELSA-2013-2585 (kernel)
| From: | Errata Announcements for Oracle Linux <el-errata@oss.oracle.com> | |
| To: | el-errata@oss.oracle.com | |
| Subject: | [El-errata] ELSA-2013-2585 Important: Oracle Linux 6 unbreakable enterprise kernel security update | |
| Date: | Thu, 28 Nov 2013 15:43:02 -0800 | |
| Message-ID: | <5297D506.6020601@oracle.com> |
Oracle Linux Security Advisory ELSA-2013-2585 The following updated rpms for Oracle Linux 6 have been uploaded to the Unbreakable Linux Network: i386: kernel-uek-2.6.32-400.33.3.el6uek.i686.rpm kernel-uek-debug-2.6.32-400.33.3.el6uek.i686.rpm kernel-uek-debug-devel-2.6.32-400.33.3.el6uek.i686.rpm kernel-uek-headers-2.6.32-400.33.3.el6uek.i686.rpm kernel-uek-devel-2.6.32-400.33.3.el6uek.i686.rpm kernel-uek-doc-2.6.32-400.33.3.el6uek.noarch.rpm kernel-uek-firmware-2.6.32-400.33.3.el6uek.noarch.rpm ofa-2.6.32-400.33.3.el6uek-1.5.1-4.0.58.i686.rpm ofa-2.6.32-400.33.3.el6uekdebug-1.5.1-4.0.58.i686.rpm mlnx_en-2.6.32-400.33.3.el6uek-1.5.7-0.1.i686.rpm mlnx_en-2.6.32-400.33.3.el6uekdebug-1.5.7-0.1.i686.rpm x86_64: kernel-uek-firmware-2.6.32-400.33.3.el6uek.noarch.rpm kernel-uek-doc-2.6.32-400.33.3.el6uek.noarch.rpm kernel-uek-2.6.32-400.33.3.el6uek.x86_64.rpm kernel-uek-headers-2.6.32-400.33.3.el6uek.x86_64.rpm kernel-uek-devel-2.6.32-400.33.3.el6uek.x86_64.rpm kernel-uek-debug-devel-2.6.32-400.33.3.el6uek.x86_64.rpm kernel-uek-debug-2.6.32-400.33.3.el6uek.x86_64.rpm ofa-2.6.32-400.33.3.el6uek-1.5.1-4.0.58.x86_64.rpm ofa-2.6.32-400.33.3.el6uekdebug-1.5.1-4.0.58.x86_64.rpm mlnx_en-2.6.32-400.33.3.el6uek-1.5.7-0.1.x86_64.rpm mlnx_en-2.6.32-400.33.3.el6uekdebug-1.5.7-0.1.x86_64.rpm SRPMS: http://oss.oracle.com/ol6/SRPMS-updates/kernel-uek-2.6.32... http://oss.oracle.com/ol6/SRPMS-updates/ofa-2.6.32-400.33... http://oss.oracle.com/ol6/SRPMS-updates/mlnx_en-2.6.32-40... Description of changes: kernel-uek [2.6.32-400.33.3.el6uek] - af_key: fix info leaks in notify messages (Mathias Krause) [Orabug: 17837974] {CVE-2013-2234} - drivers/cdrom/cdrom.c: use kzalloc() for failing hardware (Jonathan Salwan) [Orabug: 17837971] {CVE-2013-2164} - fs/compat_ioctl.c: VIDEO_SET_SPU_PALETTE missing error check (Kees Cook) [Orabug: 17837966] {CVE-2013-1928} - Bluetooth: RFCOMM - Fix info leak in ioctl(RFCOMMGETDEVLIST) (Mathias Krause) [Orabug: 17837959] {CVE-2012-6545} - Bluetooth: RFCOMM - Fix info leak via getsockname() (Mathias Krause) [Orabug: 17838023] {CVE-2012-6545} - llc: Fix missing msg_namelen update in llc_ui_recvmsg() (Mathias Krause) [Orabug: 17837945] {CVE-2013-3231} - HID: pantherlord: validate output report details (Kees Cook) [Orabug: 17837942] {CVE-2013-2892} - HID: zeroplus: validate output report details (Kees Cook) [Orabug: 17837936] {CVE-2013-2889} - HID: provide a helper for validating hid reports (Kees Cook) [Orabug: 17837936] - NFSv4: Check for buffer length in __nfs4_get_acl_uncached (Sven Wegener) [Orabug: 17837931] {CVE-2013-4591} - ansi_cprng: Fix off by one error in non-block size request (Neil Horman) [Orabug: 17837999] {CVE-2013-4345} - HID: validate HID report id size (Kees Cook) [Orabug: 17837925] {CVE-2013-2888} - ipv6: remove max_addresses check from ipv6_create_tempaddr (Hannes Frederic Sowa) [Orabug: 17837923] {CVE-2013-0343} _______________________________________________ El-errata mailing list El-errata@oss.oracle.com https://oss.oracle.com/mailman/listinfo/el-errata
