[El-errata] ELSA-2012-0571 Moderate: Oracle Linux 6 kernel security and bug fix update
Errata Announcements for Oracle Linux
el-errata at oss.oracle.com
Mon May 21 16:03:24 PDT 2012
Oracle Linux Security Advisory ELSA-2012-0571
https://rhn.redhat.com/errata/RHSA-2012-0571.html
The following updated rpms for Oracle Linux 6 have been uploaded to the
Unbreakable Linux Network:
i386:
kernel-2.6.32-220.17.1.el6.i686.rpm
kernel-debug-2.6.32-220.17.1.el6.i686.rpm
kernel-debug-devel-2.6.32-220.17.1.el6.i686.rpm
kernel-devel-2.6.32-220.17.1.el6.i686.rpm
kernel-doc-2.6.32-220.17.1.el6.noarch.rpm
kernel-firmware-2.6.32-220.17.1.el6.noarch.rpm
kernel-headers-2.6.32-220.17.1.el6.i686.rpm
x86_64:
kernel-2.6.32-220.17.1.el6.x86_64.rpm
kernel-debug-2.6.32-220.17.1.el6.x86_64.rpm
kernel-debug-devel-2.6.32-220.17.1.el6.x86_64.rpm
kernel-devel-2.6.32-220.17.1.el6.x86_64.rpm
kernel-doc-2.6.32-220.17.1.el6.noarch.rpm
kernel-firmware-2.6.32-220.17.1.el6.noarch.rpm
kernel-headers-2.6.32-220.17.1.el6.x86_64.rpm
SRPMS:
http://oss.oracle.com/ol6/SRPMS-updates/kernel-2.6.32-220.17.1.el6.src.rpm
The following packages were rebuilt to be in sync with the updated
kernel version (no changes other than updating the version number):
Users with Oracle Linux Premier Support can now use Ksplice to patch
against this Security Advisory.
We recommend that all users of Oracle Linux 5 install these updates.
Users of Ksplice Uptrack can install these updates by running :
# /usr/sbin/uptrack-upgrade -y
On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any additional action.
Description of changes:
* Denial of service due to race condition in the scheduler subsystem.
A race condition between exiting a task on one CPU and waking it up by a
different CPU can cause a kernel panic when the second task will try
waking up a dead task.
* CVE-2011-4086: Denial of service in journaling block device.
The journal block device assumed that a buffer marked as unwritten
or delay could be live without checking if the buffer was mapped.
An unprivileged local user could use this flaw to crash the system.
* CVE-2012-1601: Denial of service in KVM VCPU creation.
Inconsistent state in the creation of KVM virtual CPU's could
lead to NULL pointer dereferences. A unprivileged local user
could use this flaw to crash the system.
[2.6.32-220.17.1.el6]
- [scsi] fcoe: Do not switch context in vport_delete callback (Neil
Horman) [809388 806119]
[2.6.32-220.16.1.el6]
- Revert: [x86] Ivy Bridge kernel rdrand support (Jay Fenlason) [800268
696442]
[2.6.32-220.15.1.el6]
- [net] SUNRPC: We must not use list_for_each_entry_safe() in
rpc_wake_up() (Steve Dickson) [811299 809928]
- [char] ipmi: Increase KCS timeouts (Matthew Garrett) [806906 803378]
- [kernel] sched: Fix ancient race in do_exit() (Frantisek Hrbata)
[805457 784758]
- [scsi] sd: Unmap discard alignment needs to be converted to bytes
(Mike Snitzer) [810322 805519]
- [scsi] sd: Fix VPD buffer allocations (Mike Snitzer) [810322 805519]
- [x86] Ivy Bridge kernel rdrand support (Jay Fenlason) [800268 696442]
- [scsi] fix system lock up from scsi error flood (Frantisek Hrbata)
[809378 800555]
- [sound] ALSA: pcm midlevel code - add time check for (Jaroslav Kysela)
[801329 798984]
- [pci] Add pcie_hp=nomsi to disable MSI/MSI-X for pciehp driver (hiro
muneda) [807426 728852]
- [sound] ALSA: enable OSS emulation layer for PCM and mixer (Jaroslav
Kysela) [812960 657291]
- [scsi] qla4xxx: Fixed BFS with sendtargets as boot index (Chad Dupuis)
[803881 722297]
- [fs] nfs: Additional readdir cookie loop information (Steve Dickson)
[811135 770250]
- [fs] NFS: Fix spurious readdir cookie loop messages (Steve Dickson)
[811135 770250]
- [x86] powernow-k8: Fix indexing issue (Frank Arnold) [809391 781566]
- [x86] powernow-k8: Avoid Pstate MSR accesses on systems supporting CPB
(Frank Arnold) [809391 781566]
- [redhat] spec: Add python-perf-debuginfo subpackage (Josh Boyer)
[806859 806859]
[2.6.32-220.14.1.el6]
- [net] fix vlan gro path (Jiri Pirko) [810454 720611]
- [virt] VMX: vmx_set_cr0 expects kvm->srcu locked (Marcelo Tosatti)
[808206 807507] {CVE-2012-1601}
- [virt] KVM: Ensure all vcpus are consistent with in-kernel irqchip
settings (Marcelo Tosatti) [808206 807507] {CVE-2012-1601}
- [scsi] fcoe: Move destroy_work to a private work queue (Neil Horman)
[809388 806119]
- [fs] jbd2: clear BH_Delay & BH_Unwritten in journal_unmap_buffer (Eric
Sandeen) [749727 748713] {CVE-2011-4086}
- [net] af_iucv: offer new getsockopt SO_MSGSIZE (Hendrik Brueckner)
[804547 786997]
- [net] af_iucv: performance improvements for new HS transport (Hendrik
Brueckner) [804548 786996]
- [s390x] af_iucv: remove IUCV-pathes completely (Hendrik Brueckner)
[807158 786960]
- [x86] iommu/amd: Fix wrong shift direction (Don Dutile) [809376 781531]
- [x86] iommu/amd: Don't use MSI address range for DMA addresses (Don
Dutile) [809374 781524]
- [fs] NFSv4: Further reduce the footprint of the idmapper (Steve
Dickson) [802852 730045]
- [fs] NFSv4: Reduce the footprint of the idmapper (Steve Dickson)
[802852 730045]
- [scsi] fcoe: Make fcoe_transport_destroy a synchronous operation (Neil
Horman) [809372 771251]
- [net] ipv4: Constrain UFO fragment sizes to multiples of 8 bytes (Jiri
Benc) [809104 797731]
- [net] ipv4: Don't use ufo handling on later transformed packets (Jiri
Benc) [809104 797731]
- [net] udp: Add UFO to NETIF_F_GSO_SOFTWARE (Jiri Benc) [809104 797731]
- [fs] nfs: Try using machine credentials for RENEW calls (Sachin
Prabhu) [806205 795441]
More information about the El-errata
mailing list