[El-errata] ELSA-2012-0571 Moderate: Oracle Linux 6 kernel security and bug fix update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Mon May 21 16:03:24 PDT 2012


Oracle Linux Security Advisory ELSA-2012-0571

https://rhn.redhat.com/errata/RHSA-2012-0571.html

The following updated rpms for Oracle Linux 6 have been uploaded to the 
Unbreakable Linux Network:

i386:
kernel-2.6.32-220.17.1.el6.i686.rpm
kernel-debug-2.6.32-220.17.1.el6.i686.rpm
kernel-debug-devel-2.6.32-220.17.1.el6.i686.rpm
kernel-devel-2.6.32-220.17.1.el6.i686.rpm
kernel-doc-2.6.32-220.17.1.el6.noarch.rpm
kernel-firmware-2.6.32-220.17.1.el6.noarch.rpm
kernel-headers-2.6.32-220.17.1.el6.i686.rpm

x86_64:
kernel-2.6.32-220.17.1.el6.x86_64.rpm
kernel-debug-2.6.32-220.17.1.el6.x86_64.rpm
kernel-debug-devel-2.6.32-220.17.1.el6.x86_64.rpm
kernel-devel-2.6.32-220.17.1.el6.x86_64.rpm
kernel-doc-2.6.32-220.17.1.el6.noarch.rpm
kernel-firmware-2.6.32-220.17.1.el6.noarch.rpm
kernel-headers-2.6.32-220.17.1.el6.x86_64.rpm


SRPMS:
http://oss.oracle.com/ol6/SRPMS-updates/kernel-2.6.32-220.17.1.el6.src.rpm

The following packages were rebuilt to be in sync with the updated 
kernel version (no changes other than updating the version number):

Users with Oracle Linux Premier Support can now use Ksplice to patch
against this Security Advisory.

We recommend that all users of  Oracle Linux 5 install these updates.

Users of Ksplice Uptrack can install these updates by running :

# /usr/sbin/uptrack-upgrade -y
On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any additional action.


Description of changes:

* Denial of service due to race condition in the scheduler subsystem.

A race condition between exiting a task on one CPU and waking it up by a
different CPU can cause a kernel panic when the second task will try
waking up a dead task.


* CVE-2011-4086: Denial of service in journaling block device.

The journal block device assumed that a buffer marked as unwritten
or delay could be live without checking if the buffer was mapped.

An unprivileged local user could use this flaw to crash the system.


* CVE-2012-1601: Denial of service in KVM VCPU creation.

Inconsistent state in the creation of KVM virtual CPU's could
lead to NULL pointer dereferences.  A unprivileged local user
could use this flaw to crash the system.

[2.6.32-220.17.1.el6]
- [scsi] fcoe: Do not switch context in vport_delete callback (Neil 
Horman) [809388 806119]

[2.6.32-220.16.1.el6]
- Revert: [x86] Ivy Bridge kernel rdrand support (Jay Fenlason) [800268 
696442]

[2.6.32-220.15.1.el6]
- [net] SUNRPC: We must not use list_for_each_entry_safe() in 
rpc_wake_up() (Steve Dickson) [811299 809928]
- [char] ipmi: Increase KCS timeouts (Matthew Garrett) [806906 803378]
- [kernel] sched: Fix ancient race in do_exit() (Frantisek Hrbata) 
[805457 784758]
- [scsi] sd: Unmap discard alignment needs to be converted to bytes 
(Mike Snitzer) [810322 805519]
- [scsi] sd: Fix VPD buffer allocations (Mike Snitzer) [810322 805519]
- [x86] Ivy Bridge kernel rdrand support (Jay Fenlason) [800268 696442]
- [scsi] fix system lock up from scsi error flood (Frantisek Hrbata) 
[809378 800555]
- [sound] ALSA: pcm midlevel code - add time check for (Jaroslav Kysela) 
[801329 798984]
- [pci] Add pcie_hp=nomsi to disable MSI/MSI-X for pciehp driver (hiro 
muneda) [807426 728852]
- [sound] ALSA: enable OSS emulation layer for PCM and mixer (Jaroslav 
Kysela) [812960 657291]
- [scsi] qla4xxx: Fixed BFS with sendtargets as boot index (Chad Dupuis) 
[803881 722297]
- [fs] nfs: Additional readdir cookie loop information (Steve Dickson) 
[811135 770250]
- [fs] NFS: Fix spurious readdir cookie loop messages (Steve Dickson) 
[811135 770250]
- [x86] powernow-k8: Fix indexing issue (Frank Arnold) [809391 781566]
- [x86] powernow-k8: Avoid Pstate MSR accesses on systems supporting CPB 
(Frank Arnold) [809391 781566]
- [redhat] spec: Add python-perf-debuginfo subpackage (Josh Boyer) 
[806859 806859]

[2.6.32-220.14.1.el6]
- [net] fix vlan gro path (Jiri Pirko) [810454 720611]
- [virt] VMX: vmx_set_cr0 expects kvm->srcu locked (Marcelo Tosatti) 
[808206 807507] {CVE-2012-1601}
- [virt] KVM: Ensure all vcpus are consistent with in-kernel irqchip 
settings (Marcelo Tosatti) [808206 807507] {CVE-2012-1601}
- [scsi] fcoe: Move destroy_work to a private work queue (Neil Horman) 
[809388 806119]
- [fs] jbd2: clear BH_Delay & BH_Unwritten in journal_unmap_buffer (Eric 
Sandeen) [749727 748713] {CVE-2011-4086}
- [net] af_iucv: offer new getsockopt SO_MSGSIZE (Hendrik Brueckner) 
[804547 786997]
- [net] af_iucv: performance improvements for new HS transport (Hendrik 
Brueckner) [804548 786996]
- [s390x] af_iucv: remove IUCV-pathes completely (Hendrik Brueckner) 
[807158 786960]
- [x86] iommu/amd: Fix wrong shift direction (Don Dutile) [809376 781531]
- [x86] iommu/amd: Don't use MSI address range for DMA addresses (Don 
Dutile) [809374 781524]
- [fs] NFSv4: Further reduce the footprint of the idmapper (Steve 
Dickson) [802852 730045]
- [fs] NFSv4: Reduce the footprint of the idmapper (Steve Dickson) 
[802852 730045]
- [scsi] fcoe: Make fcoe_transport_destroy a synchronous operation (Neil 
Horman) [809372 771251]
- [net] ipv4: Constrain UFO fragment sizes to multiples of 8 bytes (Jiri 
Benc) [809104 797731]
- [net] ipv4: Don't use ufo handling on later transformed packets (Jiri 
Benc) [809104 797731]
- [net] udp: Add UFO to NETIF_F_GSO_SOFTWARE (Jiri Benc) [809104 797731]
- [fs] nfs: Try using machine credentials for RENEW calls (Sachin 
Prabhu) [806205 795441]





More information about the El-errata mailing list