[Ksplice-Fedora-29-updates] New Ksplice updates for Fedora 29 (FEDORA-2019-aabdaa013d)

Oracle Ksplice ksplice-support_ww at oracle.com
Tue Feb 12 03:31:11 PST 2019


Synopsis: FEDORA-2019-aabdaa013d can now be patched using Ksplice
CVEs: CVE-2018-16880

Systems running Fedora 29 can now use Ksplice to patch against the
latest Fedora kernel update, FEDORA-2019-aabdaa013d.

INSTALLING THE UPDATES

We recommend that all users of Ksplice Uptrack running Fedora 29
install these updates.

On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.

Alternatively, you can install these updates by running:

# /usr/sbin/uptrack-upgrade -y


DESCRIPTION

* Denial-of-service in OCFS2 when mounting image with unrecovered alloc.

When mounting an OCFS2 filesystem image with an unrecovered local alloc
in its journal, an invalid kernel assertion causes a panic when the
image should actually be recoverable with an ocfs2.fsck run.


* Denial-of-service when querying InfiniBand port attribute.

When querying InfiniBand port attribute in the Cisco Virtual Interface Card
driver, a lock ordering bug leads to a deadlock. This could allow and
attacker to cause a denial-of-service.


* Denial-of-service when collecting peer statistics in ath10k driver.

When mesh networking is configured, ath10k driver could run into a race
condition where collecting peer statistics causes a NULL pointer
dereference. This could lead to a denial-of-service.


* Data loss when performing fsync affecting multiple filesystem.

Incorrect error handling in writeback error when performing fsync on
memory-mapped file results in metadata corruption. This could lead to
inadvertent data loss.


* Improved fix for Spectre v1: Bounds-check bypass in IPMI subsystem.

A missing sanitization of array index after bounds check during multiple
user-controlled configuration operations in the IPMI subsystem could lead
to an information leak. A local attacker could use this flaw to escalate
privilege.


* Denial-of-service when receiving IPMI response.

A use-after-free bug when receiving IPMI message response through the
serial interface could lead to kernel crash and a denial-of-service.


* CVE-2018-16880: Denial-of-service in virtual networking subsystem.

A malicious virtual guest under specific conditions can trigger an
out-of-bounds write on a virtual host which may lead to kernel memory
corruption and system panic. An attacker could exploit this flaw to
cause a denial-of-service.

SUPPORT

Ksplice support is available at ksplice-support_ww at oracle.com.





More information about the Ksplice-Fedora-29-Updates mailing list