[Ksplice][EL7-Updates] New updates available via Ksplice (RHSA-2016:1277-01)

Oracle Ksplice ksplice-support_ww at oracle.com
Mon Jun 27 15:03:14 PDT 2016


Synopsis: RHSA-2016:1277-01 can now be patched using Ksplice
CVEs: CVE-2015-8767 CVE-2016-4565

Systems running RHCK on Oracle Linux 7, Red Hat Enterprise Linux 7,
CentOS 7, and Scientific Linux 7 can now use Ksplice to patch against
the latest Red Hat Security Advisory, RHSA-2016:1277-01.

INSTALLING THE UPDATES

We recommend that all users of Ksplice Uptrack on OL 7, RHEL 7, CentOS
7, and Scientific Linux 7 install these updates.

On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.

Alternatively, you can install these updates by running:

# /usr/sbin/uptrack-upgrade -y


DESCRIPTION

* CVE-2015-8767: Denial-of-service in SCTP heartbeat timeout.

Incorrect locking when accepting an SCTP connection during the 4-way
handshake could result in deadlock.  A local user could use this flaw to
block SCTP connections.


* CVE-2016-4565: Privilege escalation in Infiniband ioctl.

The Infiniband ioctl interface does not correctly validate parameters
from userspace which can allow local users to corrupt kernel memory and
escalate privileges.

SUPPORT

Ksplice support is available at ksplice-support_ww at oracle.com.


  



More information about the Ksplice-EL7-updates mailing list