[El-errata] ELSA-2012-1540-1 Important: Oracle Linux 5 kernel security, bug fix, and enhancement update
Errata Announcements for Oracle Linux
el-errata at oss.oracle.com
Wed Dec 5 17:23:34 PST 2012
Oracle Linux Security Advisory ELSA-2012-1540-1
https://rhn.redhat.com/errata/RHSA-2012-1540.html
The following updated rpms for Oracle Linux 5 have been uploaded to the
Unbreakable Linux Network:
i386:
kernel-2.6.18-308.24.1.0.1.el5.i686.rpm
kernel-PAE-2.6.18-308.24.1.0.1.el5.i686.rpm
kernel-PAE-devel-2.6.18-308.24.1.0.1.el5.i686.rpm
kernel-debug-2.6.18-308.24.1.0.1.el5.i686.rpm
kernel-debug-devel-2.6.18-308.24.1.0.1.el5.i686.rpm
kernel-devel-2.6.18-308.24.1.0.1.el5.i686.rpm
kernel-doc-2.6.18-308.24.1.0.1.el5.noarch.rpm
kernel-headers-2.6.18-308.24.1.0.1.el5.i386.rpm
kernel-xen-2.6.18-308.24.1.0.1.el5.i686.rpm
kernel-xen-devel-2.6.18-308.24.1.0.1.el5.i686.rpm
x86_64:
kernel-2.6.18-308.24.1.0.1.el5.x86_64.rpm
kernel-debug-2.6.18-308.24.1.0.1.el5.x86_64.rpm
kernel-debug-devel-2.6.18-308.24.1.0.1.el5.x86_64.rpm
kernel-devel-2.6.18-308.24.1.0.1.el5.x86_64.rpm
kernel-doc-2.6.18-308.24.1.0.1.el5.noarch.rpm
kernel-headers-2.6.18-308.24.1.0.1.el5.x86_64.rpm
kernel-xen-2.6.18-308.24.1.0.1.el5.x86_64.rpm
kernel-xen-devel-2.6.18-308.24.1.0.1.el5.x86_64.rpm
ia64:
kernel-2.6.18-308.24.1.0.1.el5.ia64.rpm
kernel-debug-2.6.18-308.24.1.0.1.el5.ia64.rpm
kernel-debug-devel-2.6.18-308.24.1.0.1.el5.ia64.rpm
kernel-devel-2.6.18-308.24.1.0.1.el5.ia64.rpm
kernel-doc-2.6.18-308.24.1.0.1.el5.noarch.rpm
kernel-headers-2.6.18-308.24.1.0.1.el5.ia64.rpm
kernel-xen-2.6.18-308.24.1.0.1.el5.ia64.rpm
kernel-xen-devel-2.6.18-308.24.1.0.1.el5.ia64.rpm
SRPMS:
http://oss.oracle.com/ol5/SRPMS-updates/kernel-2.6.18-308.24.1.0.1.el5.src.rpm
The following packages were rebuilt to be in sync with the updated
kernel version (no changes other than updating the version number):
i386:
oracleasm-2.6.18-308.24.1.0.1.el5-2.0.5-1.el5.i686.rpm
oracleasm-2.6.18-308.24.1.0.1.el5PAE-2.0.5-1.el5.i686.rpm
oracleasm-2.6.18-308.24.1.0.1.el5xen-2.0.5-1.el5.i686.rpm
oracleasm-2.6.18-308.24.1.0.1.el5debug-2.0.5-1.el5.i686.rpm
ocfs2-2.6.18-308.24.1.0.1.el5-1.4.10-1.el5.i686.rpm
ocfs2-2.6.18-308.24.1.0.1.el5PAE-1.4.10-1.el5.i686.rpm
ocfs2-2.6.18-308.24.1.0.1.el5xen-1.4.10-1.el5.i686.rpm
ocfs2-2.6.18-308.24.1.0.1.el5debug-1.4.10-1.el5.i686.rpm
x86_64:
oracleasm-2.6.18-308.24.1.0.1.el5-2.0.5-1.el5.x86_64.rpm
oracleasm-2.6.18-308.24.1.0.1.el5xen-2.0.5-1.el5.x86_64.rpm
oracleasm-2.6.18-308.24.1.0.1.el5debug-2.0.5-1.el5.x86_64.rpm
ocfs2-2.6.18-308.24.1.0.1.el5-1.4.10-1.el5.x86_64.rpm
ocfs2-2.6.18-308.24.1.0.1.el5xen-1.4.10-1.el5.x86_64.rpm
ocfs2-2.6.18-308.24.1.0.1.el5debug-1.4.10-1.el5.x86_64.rpm
ia64:
oracleasm-2.6.18-308.24.1.0.1.el5-2.0.5-1.el5.ia64.rpm
oracleasm-2.6.18-308.24.1.0.1.el5xen-2.0.5-1.el5.ia64.rpm
oracleasm-2.6.18-308.24.1.0.1.el5debug-2.0.5-1.el5.ia64.rpm
ocfs2-2.6.18-308.24.1.0.1.el5-1.4.10-1.el5.ia64.rpm
ocfs2-2.6.18-308.24.1.0.1.el5xen-1.4.10-1.el5.ia64.rpm
ocfs2-2.6.18-308.24.1.0.1.el5debug-1.4.10-1.el5.ia64.rpm
SRPMS:
http://oss.oracle.com/el5/SRPMS-updates/oracleasm-2.6.18-308.24.1.0.1.el5-2.0.5-1.el5.src.rpm
http://oss.oracle.com/el5/SRPMS-updates/ocfs2-2.6.18-308.24.1.0.1.el5-1.4.10-1.el5.src.rpm
Description of changes:
kernel
[2.6.18-308.24.1.0.1.el5]
- [kernel] Initialize the local uninitialized variable stats. [orabug
14051367]
- [fs] JBD:make jbd support 512B blocks correctly for ocfs2. [orabug
13477763]
- [x86 ] fix fpu context corrupt when preempt in signal context [orabug
14038272]
- [mm] fix hugetlb page leak (Dave McCracken) [orabug 12375075]
- fix ia64 build error due to add-support-above-32-vcpus.patch(Zhenzhong
Duan)
- [x86] use dynamic vcpu_info remap to support more than 32 vcpus
(Zhenzhong Duan)
- [x86] Fix lvt0 reset when hvm boot up with noapic param
- [scsi] remove printk's when doing I/O to a dead device (John Sobecki,
Chris Mason)
[orabug 12342275]
- [char] ipmi: Fix IPMI errors due to timing problems (Joe Jin) [orabug
12561346]
- [scsi] Fix race when removing SCSI devices (Joe Jin) [orabug 12404566]
- [net] net: Redo the broken redhat netconsole over bonding (Tina Yang)
[orabug 12740042]
- [fs] nfs: Fix __put_nfs_open_context() NULL pointer panic (Joe Jin)
[orabug 12687646]
- [scsi] fix scsi hotplug and rescan race [orabug 10260172]
- fix filp_close() race (Joe Jin) [orabug 10335998]
- make xenkbd.abs_pointer=1 by default [orabug 67188919]
- [xen] check to see if hypervisor supports memory reservation change
(Chuck Anderson) [orabug 7556514]
- [net] Enable entropy for bnx2,bnx2x,e1000e,igb,ixgb,ixgbe,ixgbevf
(John Sobecki)
[orabug 10315433]
- [NET] Add xen pv netconsole support (Tina Yang) [orabug 6993043] [bz 7258]
- [mm] Patch shrink_zone to yield during severe mempressure events, avoiding
hangs and evictions (John Sobecki,Chris Mason) [orabug 6086839]
- [mm] Enhance shrink_zone patch allow full swap utilization, and also be
NUMA-aware (John Sobecki,Chris Mason,Herbert van den Bergh) [orabug
9245919]
- fix aacraid not to reset during kexec (Joe Jin) [orabug 8516042]
- [rds] Patch rds to 1.4.2-20 (Andy Grover) [orabug 9471572, 9344105]
RDS: Fix BUG_ONs to not fire when in a tasklet
ipoib: Fix lockup of the tx queue
RDS: Do not call set_page_dirty() with irqs off (Sherman Pun)
RDS: Properly unmap when getting a remote access error (Tina Yang)
RDS: Fix locking in rds_send_drop_to()
- [xen] PVHVM guest with PoD crashes under memory pressure (Chuck Anderson)
[orabug 9107465]
- [xen] PV guest with FC HBA hangs during shutdown (Chuck Anderson)
[orabug 9764220]
- Support 256GB+ memory for pv guest (Mukesh Rathor) [orabug 9450615]
- fix overcommit memory to use percpu_counter for el5 (KOSAKI Motohiro,
Guru Anbalagane) [orabug 6124033]
- [ipmi] make configurable timeouts for kcs of ipmi [orabug 9752208]
- [ib] fix memory corruption (Andy Grover) [orabug 9972346]
[2.6.18-308.24.1.el5]
- Revert: [scsi] sg: fix races during device removal (Ewan Milne)
[868950 861004]
[2.6.18-308.23.1.el5]
- [net] bnx2x: Add remote-fault link detection (Alexander Gordeev)
[870120 796905]
- [net] bnx2x: Cosmetic changes (Alexander Gordeev) [870120 796905]
- [net] rds-ping cause kernel panic (Alexander Gordeev) [822755 822756]
{CVE-2012-2372}
- [xen] add guest address range checks to XENMEM_exchange handlers (Igor
Mammedov) [878033 878034] {CVE-2012-5513}
- [xen] x86/physmap: Prevent incorrect updates of m2p mappings (Igor
Mammedov) [870148 870149] {CVE-2012-4537}
- [xen] VCPU/timer: Dos vulnerability prev overflow in calculations
(Igor Mammedov) [870150 870151] {CVE-2012-4535}
- [scsi] sg: fix races during device removal (Ewan Milne) [868950 861004]
[2.6.18-308.22.1.el5]
- [net] bonding: fix link down handling in 802.3ad mode (Andy
Gospodarek) [877943 782866]
[2.6.18-308.21.1.el5]
- [fs] ext4: race-cond protect for convert_unwritten_extents_endio
(Lukas Czerner) [869910 869911] {CVE-2012-4508}
- [fs] ext4: serialize fallocate w/ ext4_convert_unwritten_extents
(Lukas Czerner) [869910 869911] {CVE-2012-4508}
- [fs] ext4: flush the i_completed_io_list during ext4_truncate (Lukas
Czerner) [869910 869911] {CVE-2012-4508}
- [net] WARN if struct ip_options was allocated directly by kmalloc
(Jiri Pirko) [874973 872612]
- [net] ipv4: add RCU protection to inet->opt (Jiri Pirko) [872113
855302] {CVE-2012-3552}
- [scsi] qla2xx: Don't toggle inter bits after IRQ lines attached (Chad
Dupuis) [870118 800708]
More information about the El-errata
mailing list