[El-errata] New updates available via Ksplice (ELSA-2016-3618)

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Mon Sep 26 23:47:50 PDT 2016


Synopsis: ELSA-2016-3618 can now be patched using Ksplice
CVEs: CVE-2015-8374 CVE-2016-4997 CVE-2016-4998

Users with Oracle Linux Premier Support can now use Ksplice to patch
against the latest Oracle Linux Security Advisory, ELSA-2016-3618.

INSTALLING THE UPDATES

We recommend that all users of Ksplice Uptrack on EL 5 install these
updates.

On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.

Alternatively, you can install these updates by running:

# /usr/sbin/uptrack-upgrade -y


DESCRIPTION

* CVE-2016-4997, CVE-2016-4998: Privilege escalation in the Netfilter driver.

Incomplete input validation when processing Netfilter xtables entries could
lead to out of bounds memory read and write.  An unprivileged user inside a
container could use this flaw to cause a denial-of-service or elevate
privileges.


* CVE-2015-8374: Information leak when truncating a compressed and inlined extent on Btrfs.

An information leak vulnerability was found when truncating a file to a
smaller size which consists of an inline extent that is compressed. The
data between the new file size and the old file size was not discarded,
allowing another user to read it through the clone ioctl.

SUPPORT

Ksplice support is available at ksplice-support_ww at oracle.com.




More information about the El-errata mailing list