[Ksplice][Virtuozzo 4.7 Updates] New Ksplice updates for Virtuozzo 4.7 or OpenVZ on RHEL 6 (042stab125.5)

Oracle Ksplice ksplice-support_ww at oracle.com
Wed Oct 25 16:04:31 PDT 2017


Synopsis: 042stab125.5 can now be patched using Ksplice
CVEs: CVE-2017-15274

Systems running Virtuozzo 4.7 or the OpenVZ RHEL 6 kernel can now use
Ksplice to patch against the latest Parallels Virtuozzo Containers 4.7
kernel security update, 042stab125.5.

INSTALLING THE UPDATES

We recommend that all users of Ksplice Uptrack running Virtuozzo 4.7
or OpenVZ on RHEL 6 install these updates.

On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.

Alternatively, you can install these updates by running:

# /usr/sbin/uptrack-upgrade -y


DESCRIPTION

* CVE-2017-15274: Denial-of-service in kernel keyring add_key() syscall.

A NULL pointer dereference could allow a local, unprivileged user to
cause a denial of service by updating a key with a NULL payload an
non-zero length.

SUPPORT

Ksplice support is available at ksplice-support_ww at oracle.com.





More information about the Ksplice-VZ4.7-Updates mailing list