[El-errata] ELSA-2015-3014 Important: Oracle Linux 5 Unbreakable Enterprise kernel security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Fri Mar 13 14:20:04 PDT 2015


Oracle Linux Security Advisory ELSA-2015-3014

http://linux.oracle.com/errata/ELSA-2015-3014.html

The following updated rpms for Oracle Linux 5 have been uploaded to the 
Unbreakable Linux Network:

i386:
kernel-uek-2.6.39-400.248.3.el5uek.i686.rpm
kernel-uek-debug-2.6.39-400.248.3.el5uek.i686.rpm
kernel-uek-debug-devel-2.6.39-400.248.3.el5uek.i686.rpm
kernel-uek-devel-2.6.39-400.248.3.el5uek.i686.rpm
kernel-uek-doc-2.6.39-400.248.3.el5uek.noarch.rpm
kernel-uek-firmware-2.6.39-400.248.3.el5uek.noarch.rpm

x86_64:
kernel-uek-firmware-2.6.39-400.248.3.el5uek.noarch.rpm
kernel-uek-doc-2.6.39-400.248.3.el5uek.noarch.rpm
kernel-uek-2.6.39-400.248.3.el5uek.x86_64.rpm
kernel-uek-devel-2.6.39-400.248.3.el5uek.x86_64.rpm
kernel-uek-debug-devel-2.6.39-400.248.3.el5uek.x86_64.rpm
kernel-uek-debug-2.6.39-400.248.3.el5uek.x86_64.rpm


SRPMS:
http://oss.oracle.com/ol5/SRPMS-updates/kernel-uek-2.6.39-400.248.3.el5uek.src.rpm



Description of changes:

[2.6.39-400.248.3.el5uek]
- kvm: fix excessive pages un-pinning in kvm_iommu_map error path. 
(Quentin Casasnovas)  [Orabug: 20687314]  {CVE-2014-3601} 
{CVE-2014-8369} {CVE-2014-3601}
- Revert "mm: Fix NULL pointer dereference in madvise(MADV_WILLNEED) 
support" (Guangyu Sun)  [Orabug: 20673281]  {CVE-2014-8173}

[2.6.39-400.248.2.el5uek]
- netfilter: conntrack: disable generic tracking for known protocols 
(Florian Westphal)  [Orabug: 20679630]  {CVE-2014-8160}
- mac80211: fix fragmentation code, particularly for encryption 
(Johannes Berg)  [Orabug: 20673313]  {CVE-2014-8709}
- mm: Fix NULL pointer dereference in madvise(MADV_WILLNEED) support 
(Kirill A. Shutemov)  [Orabug: 20673282]  {CVE-2014-8173}
- tracing/syscalls: Ignore numbers outside NR_syscalls' range (Rabin 
Vincent)  [Orabug: 20673164]  {CVE-2014-7825} {CVE-2014-7826}
- tracing/syscalls: Fix perf syscall tracing when syscall_nr == -1 (Will 
Deacon)  [Orabug: 20673164]  {CVE-2014-7825} {CVE-2014-7826}

[2.6.39-400.248.1.el5uek]
- NVMe: Disable pci before clearing queue (Keith Busch)  [Orabug: 
20533100] - x86, fpu: disable eagerfpu by default (Santosh Shilimkar) 
[Orabug: 20521543]





More information about the El-errata mailing list