[El-errata] ELSA-2014-0328 Important: Oracle Linux 6 kernel security and bug fix update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Tue Mar 25 14:21:56 PDT 2014


Oracle Linux Security Advisory ELSA-2014-0328

https://rhn.redhat.com/errata/RHSA-2014-0328.html

The following updated rpms for Oracle Linux 6 have been uploaded to the 
Unbreakable Linux Network:

i386:
kernel-2.6.32-431.11.2.el6.i686.rpm
kernel-abi-whitelists-2.6.32-431.11.2.el6.noarch.rpm
kernel-debug-2.6.32-431.11.2.el6.i686.rpm
kernel-debug-devel-2.6.32-431.11.2.el6.i686.rpm
kernel-devel-2.6.32-431.11.2.el6.i686.rpm
kernel-doc-2.6.32-431.11.2.el6.noarch.rpm
kernel-firmware-2.6.32-431.11.2.el6.noarch.rpm
kernel-headers-2.6.32-431.11.2.el6.i686.rpm
perf-2.6.32-431.11.2.el6.i686.rpm
python-perf-2.6.32-431.11.2.el6.i686.rpm

x86_64:
kernel-2.6.32-431.11.2.el6.x86_64.rpm
kernel-abi-whitelists-2.6.32-431.11.2.el6.noarch.rpm
kernel-debug-2.6.32-431.11.2.el6.x86_64.rpm
kernel-debug-devel-2.6.32-431.11.2.el6.x86_64.rpm
kernel-devel-2.6.32-431.11.2.el6.x86_64.rpm
kernel-doc-2.6.32-431.11.2.el6.noarch.rpm
kernel-firmware-2.6.32-431.11.2.el6.noarch.rpm
kernel-headers-2.6.32-431.11.2.el6.x86_64.rpm
perf-2.6.32-431.11.2.el6.x86_64.rpm
python-perf-2.6.32-431.11.2.el6.x86_64.rpm


SRPMS:
http://oss.oracle.com/ol6/SRPMS-updates/kernel-2.6.32-431.11.2.el6.src.rpm


Description of changes:

[2.6.32-431.11.2.el6]
- [net] sctp: fix sctp_sf_do_5_1D_ce to verify if peer is AUTH capable 
(Daniel Borkmann) [1070715 1067451] {CVE-2014-0101}
- [vhost] validate vhost_get_vq_desc return value (Michael S. Tsirkin) 
[1062579 1058677] {CVE-2014-0055}

[2.6.32-431.11.1.el6]
- [net] netpoll: take rcu_read_lock_bh() in netpoll_send_skb_on_dev() 
(Florian Westphal) [1063271 1049052]
[2.6.32-431.11.1.el6]
- [net] netpoll: take rcu_read_lock_bh() in netpoll_send_skb_on_dev() 
(Florian Westphal) [1063271 1049052]
- [fs] cifs: sanity check length of data to send before sending (Sachin 
Prabhu) [1065668 1062590] {CVE-2014-0069}
- [fs] cifs: ensure that uncached writes handle unmapped areas correctly 
(Sachin Prabhu) [1065668 1062590] {CVE-2014-0069}
- [infiniband] ipoib: Report operstate consistently when brought up 
without a link (Michal Schmidt) [1064464 995300]
- [security] selinux: fix broken peer recv check (Paul Moore) [1059991 
1043051]
- [fs] GFS2: Fix slab memory leak in gfs2_bufdata (Robert S Peterson) 
[1064913 1024024]
- [fs] GFS2: Fix use-after-free race when calling gfs2_remove_from_ail 
(Robert S Peterson) [1064913 1024024]
- [fs] nfs: always make sure page is up-to-date before extending a write 
to cover the entire page (Scott Mayhew) [1066942 1054493]
- [fs] xfs: ensure we capture IO errors correctly (Lachlan McIlroy) 
[1058418 1021325]
- [mm] get rid of unnecessary pageblock scanning in 
setup_zone_migrate_reserve (Motohiro Kosaki) [1062113 1043353]
- [security] selinux: process labeled IPsec TCP SYN-ACK packets properly 
in selinux_ip_postroute() (Paul Moore) [1055364 1024631]
- [security] selinux: look for IPsec labels on both inbound and outbound 
packets (Paul Moore) [1055364 1024631]
- [security] selinux: handle TCP SYN-ACK packets correctly in 
selinux_ip_postroute() (Paul Moore) [1055364 1024631]
- [security] selinux: handle TCP SYN-ACK packets correctly in 
selinux_ip_output() (Paul Moore) [1055364 1024631]
- [edac] e752x_edac: Fix pci_dev usage count (Aristeu Rozanski) [1058420 
1029530]
- [s390] mm: handle asce-type exceptions as normal page fault (Hendrik 
Brueckner) [1057164 1034268]
- [s390] mm: correct tlb flush on page table upgrade (Hendrik Brueckner) 
[1057165 1034269]
- [net] fix memory information leaks in recv protocol handlers (Florian 
Westphal) [1039868 1039869]
- [usb] cdc-wdm: fix buffer overflow (Alexander Gordeev) [922000 922001] 
{CVE-2013-1860}
- [usb] cdc-wdm: Fix race between autosuspend and reading from the 
device (Alexander Gordeev) [922000 922001] {CVE-2013-1860}

[2.6.32-431.10.1.el6]
- [fs] xfs: xfs_remove deadlocks due to inverted AGF vs AGI lock 
ordering (Brian Foster) [1067775 1059334]
- [x86] apic: Map the local apic when parsing the MP table (Prarit 
Bhargava) [1063507 1061873]

[2.6.32-431.9.1.el6]
- [netdrv] bonding: add NETIF_F_NO_CSUM vlan_features (Ivan Vecera) 
[1063199 1059777]

[2.6.32-431.8.1.el6]
- [netdrv] enic: remove enic->vlan_group check (Stefan Assmann) [1064115 
1057704]

[2.6.32-431.7.1.el6]
- [char] n_tty: Fix unsafe update of available buffer space (Jiri Benc) 
[1060491 980188]
- [char] n_tty: Fix stuck throttled driver (Jiri Benc) [1060491 980188]
- [char] tty: Add safe tty throttle/unthrottle functions (Jiri Benc) 
[1060491 980188]
- [char] tty: note race we need to fix (Jiri Benc) [1060491 980188]

[2.6.32-431.6.1.el6]
- [mm] memcg: fix oom schedule_timeout() (Ulrich Obergfell) [1054072 
1034237]
- [mm] memcg: change memcg_oom_mutex to spinlock (Ulrich Obergfell) 
[1054072 1034237]
- [mm] memcg: fix hierarchical oom locking (Ulrich Obergfell) [1054072 
1034237]
- [mm] memcg: make oom_lock 0 and 1 based rather than counter (Ulrich 
Obergfell) [1054072 1034237]





More information about the El-errata mailing list