[Ksplice-Fedora-22-updates] New updates available via Ksplice (FEDORA-2016-ed5110c4bb)
Oracle Ksplice
ksplice-support_ww at oracle.com
Mon Apr 11 03:06:36 PDT 2016
Synopsis: FEDORA-2016-ed5110c4bb can now be patched using Ksplice
CVEs: CVE-2016-2184 CVE-2016-2185 CVE-2016-2186 CVE-2016-2187 CVE-2016-2188 CVE-2016-3136 CVE-2016-3137 CVE-2016-3138 CVE-2016-3140 CVE-2016-3157
Systems running Fedora 22 can now use Ksplice to patch against the
latest Fedora kernel update, FEDORA-2016-ed5110c4bb.
INSTALLING THE UPDATES
We recommend that all users of Ksplice Uptrack on Fedora 22 install
these updates.
On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.
Alternatively, you can install these updates by running:
# /usr/sbin/uptrack-upgrade -y
DESCRIPTION
* CVE-2016-2184: Denial of service in ALSA USB audio descriptor parsing.
A logic error in the ALSA USB audio driver can allow a malformed USB
descriptor with zero end-points to trigger a NULL pointer dereference
and kernel panic.
* CVE-2016-3137: Denial of service in USB Cypress M8 descriptor parsing.
A logic error in the Cypress M8 device driver can allow a malformed USB
descriptor with missing endpoints to trigger a NULL pointer dereference
and kernel panic.
* CVE-2016-2186: Denial of service in Griffin PowerMate USB descriptor parsing.
A logic error in the Griffin PowerMate USB driver can allow a malformed
USB descriptor with zero endpoints to trigger a NULL pointer dereference
and kernel panic.
* CVE-2016-2188: Denial of service in IO Warrior USB descriptor parsing.
A logic error in the IO Warrior USB driver can allow a malformed USB
descriptor with zero endpoints to trigger a NULL pointer dereference and
kernel panic.
* Denial of service in generic USB interface management.
A malformed USB descriptor can trigger a NULL pointer dereference and
kernel panic when the generic USB driver claims interfaces.
* CVE-2016-2185: Denial of service in ATI/Philips USB RF remote descriptor parsing.
A logic error in the ATI/Philips USB RF remote driver can allow a
malformed USB descriptor to trigger a NULL pointer dereference and
kernel panic.
* CVE-2016-3138: Denial of service in CDC ADM USB descriptor parsing.
A logic error in the CDC ADM USB driver can allow a malformed USB
descriptor with an incorrect number of interfaces to trigger a NULL
pointer dereference and kernel panic.
* CVE-2016-3140: Denial of service in Digi AccelePort USB descriptor parsing.
A logic error in the Digi AccelePort USB driver can allow a malformed
USB descriptor with missing endpoints to trigger a NULL pointer
dereference and kernel panic.
* Denial of service in IMS PCU USB descriptor parsing.
A logic error in the IMS PCU USB driver can allow a malformed USB
descriptor with missing interfaces to trigger a NULL pointer dereference
and kernel panic.
* CVE-2016-2187: Denial of service in GTCO CallComp/InterWrite USB descriptor parsing.
A logic error in the GTCO CallComp/InterWrite USB driver can allow a
malformed USB descriptor with zero endpoints to trigger a NULL pointer
dereference and kernel panic.
* CVE-2016-3136: Denial of service in MCT Serial USB descriptor parsing.
A logic error in the MCT Single Port Serial driver can allow a malformed
USB descriptor with missing ports to trigger a NULL pointer dereference
and kernel panic.
* CVE-2016-3157: Xen I/O port access privilege escalation in x86-64.
User mode processes not supposed to be able to access I/O ports may
be granted such permission, potentially resulting in one or more of
in-guest privilege escalation, guest crashes (Denial of Service), or
in-guest information leaks.
SUPPORT
Ksplice support is available at ksplice-support_ww at oracle.com.
More information about the Ksplice-Fedora-22-Updates
mailing list