[El-errata] ELSA-2016-0176 Critical: Oracle Linux 7 glibc security and bug fix update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Tue Feb 16 15:22:23 PST 2016


Oracle Linux Security Advisory ELSA-2016-0176

http://linux.oracle.com/errata/ELSA-2016-0176.html

The following updated rpms for Oracle Linux 7 have been uploaded to the 
Unbreakable Linux Network:

x86_64:
glibc-2.17-106.0.1.el7_2.4.i686.rpm
glibc-2.17-106.0.1.el7_2.4.x86_64.rpm
glibc-common-2.17-106.0.1.el7_2.4.x86_64.rpm
glibc-devel-2.17-106.0.1.el7_2.4.i686.rpm
glibc-devel-2.17-106.0.1.el7_2.4.x86_64.rpm
glibc-headers-2.17-106.0.1.el7_2.4.x86_64.rpm
glibc-static-2.17-106.0.1.el7_2.4.i686.rpm
glibc-static-2.17-106.0.1.el7_2.4.x86_64.rpm
glibc-utils-2.17-106.0.1.el7_2.4.x86_64.rpm
nscd-2.17-106.0.1.el7_2.4.x86_64.rpm


SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates/glibc-2.17-106.0.1.el7_2.4.src.rpm



Description of changes:

[2.17-106.0.1.4]
- Remove strstr and strcasestr implementations using sse4.2 instructions.
- Upstream commits 584b18eb4df61ccd447db2dfe8c8a7901f8c8598 and
   1818483b15d22016b0eae41d37ee91cc87b37510 backported.

[2.17-106.4]
- Revert problematic libresolv change, not needed for the
   CVE-2015-7547 fix (#1296030).

[2.17-106.3]
- Fix CVE-2015-7547: getaddrinfo() stack-based buffer overflow (#1296030).
- Fix madvise performance issues (#1298930).
- Avoid "monstartup: out of memory" error on powerpc64le (#1298956).

[2.17-106.2]
- Fix CVE-2015-5229: calloc() may return non-zero memory (#1296453).





More information about the El-errata mailing list