[Ksplice][EL7-Updates] New Ksplice updates for OL 7, RHEL 7, CentOS 7, and Scientific Linux 7 (ELSA-2021-0336)

Oracle Ksplice ksplice-support_ww at oracle.com
Fri Feb 5 12:19:57 PST 2021


Synopsis: ELSA-2021-0336 can now be patched using Ksplice
CVEs: CVE-2020-15436 CVE-2020-35513

Systems running RHCK on Oracle Linux 7, Red Hat Enterprise Linux 7,
CentOS 7, and Scientific Linux 7 can now use Ksplice to patch against
the latest Red Hat kernel update, ELSA-2021-0336.
More information about this errata can be found at
https://linux.oracle.com/errata/ELSA-2021-0336.html

INSTALLING THE UPDATES

We recommend that all users of Ksplice Uptrack running OL 7, RHEL 7,
CentOS 7, and Scientific Linux 7 install these updates.

On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.

Alternatively, you can install these updates by running:

# /usr/sbin/uptrack-upgrade -y


DESCRIPTION

* CVE-2020-15436: Use-after-free in blk device locks allows privilege escalation.

Incorrect reference counting in the __blkdev_get() call responsible for
synchronizing access to generic block devices could result in a
use-after-free of the device memory. A malicious user might exploit this
to cause a denial-of-service or escalate their privileges.


* CVE-2020-35513: Incorrect umask persistence when creating NFSv4 files.

When creating or opening files over NFSv4, the umask value is
incorrectly persisted across operations in an invalid way. A malicious
user with access to the NFS share might exploit this to change
permissions on an exported file.

SUPPORT

Ksplice support is available at ksplice-support_ww at oracle.com.





More information about the Ksplice-EL7-updates mailing list