[Ksplice][Debian 8.0 Updates] New Ksplice updates for Debian 8.0 Jessie (3.16.76-1)
Oracle Ksplice
ksplice-support_ww at oracle.com
Tue Jan 21 01:32:05 PST 2020
Synopsis: 3.16.76-1 can now be patched using Ksplice
CVEs: CVE-2018-12207 CVE-2019-0154 CVE-2019-11135
Systems running Debian 8.0 Jessie can now use Ksplice to patch against
the latest Debian kernel update, 3.16.76-1.
INSTALLING THE UPDATES
We recommend that all users of Ksplice Uptrack running Debian 8.0
Jessie install these updates.
On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.
Alternatively, you can install these updates by running:
# /usr/sbin/uptrack-upgrade -y
DESCRIPTION
* CVE-2019-11135: Side-channel information leak in Intel TSX.
A side-channel information leak on some generations of Intel processors
could allow the leaking of internal microarchitectural buffers during
asynchronous aborts in a TSX transaction. For CPUs that are vulnerable
to Microarchitectural Data Sampling, existing mitigations cover
CVE-2019-11135, for newer CPUs with hardware fixes for MDS, TSX is
transparently disabled. On these newer CPUs, TSX functionality can be
restored by writing 0 to /sys/kernel/debug/x86/tsx_force_abort.
* Note: Oracle will not be providing a zero downtime update for CVE-2018-12207.
The latest Jessie kernel (3.16.76-1) does not provide a mitigation for
CVE-2018-12207.
* CVE-2019-0154: Denial-of-service in Intel i915 graphics driver.
Due to a hardware error, the Intel i915 device state could get corrupted.
A malicious user could use this to cause denial-of-service.
* Improved fix for Spectre v1: Bounds-check bypass in sys_ptrace().
Missing sanitizaion of array index after bounds check in the
sys_ptrace() system call could lead to a Spectre variant 1 information
leak. A local attacker could exploit this flaw to gain information about
the running system.
SUPPORT
Ksplice support is available at ksplice-support_ww at oracle.com.
More information about the Ksplice-Debian-8.0-Updates
mailing list