[El-errata] ELSA-2016-1539 Important: Oracle Linux 7 kernel security and bug fix update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Tue Aug 2 14:05:14 PDT 2016


Oracle Linux Security Advisory ELSA-2016-1539

http://linux.oracle.com/errata/ELSA-2016-1539.html

The following updated rpms for Oracle Linux 7 have been uploaded to the 
Unbreakable Linux Network:

x86_64:
kernel-3.10.0-327.28.2.el7.x86_64.rpm
kernel-abi-whitelists-3.10.0-327.28.2.el7.noarch.rpm
kernel-debug-3.10.0-327.28.2.el7.x86_64.rpm
kernel-debug-devel-3.10.0-327.28.2.el7.x86_64.rpm
kernel-devel-3.10.0-327.28.2.el7.x86_64.rpm
kernel-doc-3.10.0-327.28.2.el7.noarch.rpm
kernel-headers-3.10.0-327.28.2.el7.x86_64.rpm
kernel-tools-3.10.0-327.28.2.el7.x86_64.rpm
kernel-tools-libs-3.10.0-327.28.2.el7.x86_64.rpm
kernel-tools-libs-devel-3.10.0-327.28.2.el7.x86_64.rpm
perf-3.10.0-327.28.2.el7.x86_64.rpm
python-perf-3.10.0-327.28.2.el7.x86_64.rpm


SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates/kernel-3.10.0-327.28.2.el7.src.rpm



Description of changes:

[3.10.0-327.28.2.el7.OL7]
- Oracle Linux certificates (Alexey Petrenko)

[3.10.0-327.28.2.el7]
- [net] bridge: include in6.h in if_bridge.h for struct in6_addr (Jiri 
Benc) [1331285 1268057]
- [net] inet: defines IPPROTO_* needed for module alias generation (Jiri 
Benc) [1331285 1268057]
- [net] sync some IP headers with glibc (Jiri Benc) [1331285 1268057]

[3.10.0-327.28.1.el7]
- [netdrv] e1000: Double Tx descriptors needed check for 82544 (Jarod 
Wilson) [1349448 1274170]
- [netdrv] e1000: Do not overestimate descriptor counts in Tx pre-check 
(Jarod Wilson) [1349448 1274170]
- [scsi] 3w-9xxx: version string touch (Tomas Henzl) [1348833 1322447]
- [scsi] 3w-9xxx: don't unmap bounce buffered commands (Tomas Henzl) 
[1348833 1322447]
- [scsi] 3w-9xxx: fix command completion race (Tomas Henzl) [1348833 
1322447]
- [fs] gfs2: don't set rgrp gl_object until it's inserted into rgrp tree 
(Robert S Peterson) [1348829 1344363]
- [fs] fanotify: fix notification of groups with inode & mount marks 
(Miklos Szeredi) [1348828 1308393]
- [fs] ovl: fix permission checking for setattr (Vivek Goyal) [1293980 
1293981]
- [security] keys: potential uninitialized variable (David Howells) 
[1345935 1341352] {CVE-2016-4470}
- [tty] Invert tty_lock/ldisc_sem lock order (Herton R. Krzesinski) 
[1336823 1327403]
- [tty] Don't hold tty_lock for ldisc release (Herton R. Krzesinski) 
[1336823 1327403]
- [tty] Reset hupped state on open (Herton R. Krzesinski) [1336823 1327403]
- [tty] Fix hangup race with TIOCSETD ioctl (Herton R. Krzesinski) 
[1336823 1327403]
- [tty] Clarify ldisc variable (Herton R. Krzesinski) [1336823 1327403]
- [infiniband] security: Restrict use of the write() interface (Don 
Dutile) [1332553 1316685] {CVE-2016-4565}

[3.10.0-327.27.1.el7]
- [md] raid5: check_reshape() shouldn't call mddev_suspend (Jes 
Sorensen) [1344313 1312828]
- [net] sctp: Potentially-Failed state should not be reached from 
unconfirmed state (Xin Long) [1347809 1333696]
- [net] sctp: fix the transports round robin issue when init is 
retransmitted (Xin Long) [1347809 1333696]
- [net] sctp: fix suboptimal edge-case on non-active active/retrans path 
selection (Xin Long) [1347809 1333696]
- [net] sctp: spare unnecessary comparison in sctp_trans_elect_best (Xin 
Long) [1347809 1333696]
- [net] sctp: improve sctp_select_active_and_retran_path selection (Xin 
Long) [1347809 1333696]
- [net] sctp: migrate most recently used transport to ktime (Xin Long) 
[1347809 1333696]
- [net] sctp: refactor active path selection (Xin Long) [1347809 1333696]
- [net] sctp: remove NULL check in sctp_assoc_update_retran_path (Xin 
Long) [1347809 1333696]
- [net] sctp: rework multihoming retransmission path selection to 
rfc4960 (Xin Long) [1347809 1333696]
- [net] sctp: retran_path not set properly after transports recovering 
(Xin Long) [1347809 1333696]
- [mm] memcg: fix endless loop caused by mem_cgroup_iter (Herton R. 
Krzesinski) [1344750 1297381]
- [scsi] qla2xxx: Set relogin flag when we fail to queue login requests 
(Chad Dupuis) [1347344 1273080]
- [x86] perf/x86/intel/uncore: Add Broadwell-EP uncore support (Jiri 
Olsa) [1347374 1259976]
- [x86] perf/x86/intel/uncore: Add Broadwell-DE uncore support (Jiri 
Olsa) [1348063 1306834]
- [lib] rhashtable: Do hashing inside of rhashtable_lookup_compare() 
(Phil Sutter) [1343639 1238749]
- [s390] mm: four page table levels vs. fork (Hendrik Brueckner) 
[1341547 1308879] {CVE-2016-2143}
- [firmware] dmi_scan: Fix UUID endianness for SMBIOS >= 2.6 (Prarit 
Bhargava) [1340118 1294461]
- [misc] cxl: Export AFU error buffer via sysfs (Gustavo Duarte) 
[1343537 1275968]
- [misc] cxl: Poll for outstanding IRQs when detaching a context 
(Alexander Gordeev) [1338886 1332487]
- [misc] cxl: Keep IRQ mappings on context teardown (Alexander Gordeev) 
[1338886 1332487]
- [netdrv] mlx4_en: Fix endianness bug in IPV6 csum calculation (kamal 
heib) [1337431 1325358]
- [acpi] srat: fix SRAT parsing order with both LAPIC and X2APIC present 
(Prarit Bhargava) [1336821 1331394]

[3.10.0-327.26.1.el7]
- [block] blk-mq: fix race between timeout and freeing request (David 
Milburn) [1347743 1288601]
- [x86] nmi: Fix use of unallocated cpumask_var_t (Jerry Snitselaar) 
[1346176 1069217]
- [x86] nmi: Perform a safe NMI stack trace on all CPUs (Jerry 
Snitselaar) [1346176 1069217]
- [kernel] printk: Add per_cpu printk func to allow printk to be 
diverted (Jerry Snitselaar) [1346176 1069217]
- [lib] seq: Add minimal support for seq_buf (Jerry Snitselaar) [1346176 
1069217]
- [fs] ovl: use a minimal buffer in ovl_copy_xattr (Vivek Goyal) 
[1347235 1306358]
- [fs] ovl: allow zero size xattr (Vivek Goyal) [1347235 1306358]

[3.10.0-327.25.1.el7]
- [fs] xfs: fix broken multi-fsb buffer logging (Brian Foster) [1344234 
1334671]

[3.10.0-327.24.1.el7]
- [net] udp: properly support MSG_PEEK with truncated buffers (Sabrina 
Dubroca) [1339115 1294384]

[3.10.0-327.23.1.el7]
- [net] af_unix: Guard against other == sk in unix_dgram_sendmsg (Jakub 
Sitnicki) [1337513 1285792]
- [net] unix: avoid use-after-free in ep_remove_wait_queue (Paolo Abeni) 
[1337513 1285792]






More information about the El-errata mailing list