[Ksplice][Debian 8.0 Updates] New Ksplice updates for Debian 8.0 Jessie (3.16.76-1)

Oracle Ksplice ksplice-support_ww at oracle.com
Tue Jan 21 01:32:05 PST 2020


Synopsis: 3.16.76-1 can now be patched using Ksplice
CVEs: CVE-2018-12207 CVE-2019-0154 CVE-2019-11135

Systems running Debian 8.0 Jessie can now use Ksplice to patch against
the latest Debian kernel update, 3.16.76-1.

INSTALLING THE UPDATES

We recommend that all users of Ksplice Uptrack running Debian 8.0
Jessie install these updates.

On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.

Alternatively, you can install these updates by running:

# /usr/sbin/uptrack-upgrade -y


DESCRIPTION

* CVE-2019-11135: Side-channel information leak in Intel TSX.

A side-channel information leak on some generations of Intel processors
could allow the leaking of internal microarchitectural buffers during
asynchronous aborts in a TSX transaction.  For CPUs that are vulnerable
to Microarchitectural Data Sampling, existing mitigations cover
CVE-2019-11135, for newer CPUs with hardware fixes for MDS, TSX is
transparently disabled.  On these newer CPUs, TSX functionality can be
restored by writing 0 to /sys/kernel/debug/x86/tsx_force_abort.


* Note: Oracle will not be providing a zero downtime update for CVE-2018-12207.

The latest Jessie kernel (3.16.76-1) does not provide a mitigation for
CVE-2018-12207.


* CVE-2019-0154: Denial-of-service in Intel i915 graphics driver.

Due to a hardware error, the Intel i915 device state could get corrupted.
A malicious user could use this to cause denial-of-service.


* Improved fix for Spectre v1: Bounds-check bypass in sys_ptrace().

Missing sanitizaion of array index after bounds check in the
sys_ptrace() system call could lead to a Spectre variant 1 information
leak. A local attacker could exploit this flaw to gain information about
the running system.

SUPPORT

Ksplice support is available at ksplice-support_ww at oracle.com.





More information about the Ksplice-Debian-8.0-Updates mailing list