Oracle alert ELSA-2016-3565 (kernel 3.8.13)
| From: | Errata Announcements for Oracle Linux <el-errata@oss.oracle.com> | |
| To: | el-errata@oss.oracle.com | |
| Subject: | [El-errata] ELSA-2016-3565 Important: Oracle Linux 7 Unbreakable Enterprise kernel security update | |
| Date: | Fri, 20 May 2016 10:07:23 -0700 | |
| Message-ID: | <573F444B.8070603@oracle.com> |
Oracle Linux Security Advisory ELSA-2016-3565 http://linux.oracle.com/errata/ELSA-2016-3565.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: kernel-uek-firmware-3.8.13-118.6.2.el7uek.noarch.rpm kernel-uek-doc-3.8.13-118.6.2.el7uek.noarch.rpm kernel-uek-3.8.13-118.6.2.el7uek.x86_64.rpm kernel-uek-devel-3.8.13-118.6.2.el7uek.x86_64.rpm kernel-uek-debug-devel-3.8.13-118.6.2.el7uek.x86_64.rpm kernel-uek-debug-3.8.13-118.6.2.el7uek.x86_64.rpm dtrace-modules-3.8.13-118.6.2.el7uek-0.4.5-3.el7.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates/kernel-uek-3.8.13... http://oss.oracle.com/ol7/SRPMS-updates/dtrace-modules-3.... Description of changes: kernel-uek [3.8.13-118.6.2.el7uek] - KEYS: Fix ASN.1 indefinite length object parsing This fixes CVE-2016-0758. (David Howells) [Orabug: 23279020] {CVE-2016-0758} - net: add validation for the socket syscall protocol argument (Hannes Frederic Sowa) [Orabug: 23267997] {CVE-2015-8543} {CVE-2015-8543} - ipv6: addrconf: validate new MTU before applying it (Marcelo Leitner) [Orabug: 23263252] {CVE-2015-8215} - unix: properly account for FDs passed over unix sockets (willy tarreau) [Orabug: 23262276] {CVE-2013-4312} {CVE-2013-4312} _______________________________________________ El-errata mailing list El-errata@oss.oracle.com https://oss.oracle.com/mailman/listinfo/el-errata
