[El-errata] New updates available via Ksplice (ELBA-2016-3549)

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Mon May 2 11:18:53 PDT 2016


Synopsis: ELBA-2016-3549 can now be patched using Ksplice

Users with Oracle Linux Premier Support can now use Ksplice to patch
against the latest Oracle kernel update, ELBA-2016-3549.

INSTALLING THE UPDATES

We recommend that all users of Ksplice Uptrack on EL 5 install these
updates.

On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.

Alternatively, you can install these updates by running:

# /usr/sbin/uptrack-upgrade -y


DESCRIPTION

* Data corruption when transmitting packets via Virtual Ethernet device.

A logic error can cause checksums to be ignored by the Virtual Ethernet
device driver which can cause corrupted data to be delivered to containers.


* NULL pointer dereference in SunRPC driver on concurrent connect/close.

A race condition in the SunRPC driver could lead to a NULL pointer
dereference on concurrent connect()/close() on the same socket. A local,
unprivileged user could use this flaw to cause a denial-of-service.


* Kernel panic when processing fragmented packets via MLX4 Virtual NIC.

A logic error in the Mellanox Virtual NIC driver can cause an
out-of-bounds read and kernel panic when processing fragmented packets.
A remote user could use this flaw to cause a denial of service.

SUPPORT

Ksplice support is available at ksplice-support_ww at oracle.com.





More information about the El-errata mailing list