[Ksplice][EL6-Updates] New updates available via Ksplice (RHSA-2012:1156-1)

Samson Yeung samson.yeung at oracle.com
Tue Aug 14 17:40:37 PDT 2012


Synopsis: RHSA-2012:1156-1 can now be patched using Ksplice
CVEs: CVE-2011-1078 CVE-2012-2384

Systems running Red Hat Enterprise Linux 6, CentOS 6, and Scientific
Linux 6 can now use Ksplice to patch against the latest Red Hat
Security Advisory, RHSA-2012:1156-1.

INSTALLING THE UPDATES

We recommend that all users of Ksplice Uptrack on RHEL 6, CentOS 6,
and Scientific Linux 6 install these updates.

On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.

Alternatively, you can install these updates by running:

# /usr/sbin/uptrack-upgrade -y


DESCRIPTION

* CVE-2011-1078: Information leak in Bluetooth SCO link driver.

One byte of the 'struct sco_conninfo' data structure was not
initialized before being copied to userspace, leading to a leak of
potentially sensitive kernel memory.


* CVE-2012-2384: Integer overflow in i915 execution buffer.

An integer overflow in the i915 execution buffer code could result in a
user triggering a denial-of-service attack or elevating privileges.

SUPPORT

Ksplice support is available at ksplice-support_ww at oracle.com.




More information about the Ksplice-EL6-Updates mailing list