[El-errata] New updates available via Ksplice (ELSA-2016-3618)

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Mon Sep 26 23:47:50 PDT 2016

Synopsis: ELSA-2016-3618 can now be patched using Ksplice
CVEs: CVE-2015-8374 CVE-2016-4997 CVE-2016-4998

Users with Oracle Linux Premier Support can now use Ksplice to patch
against the latest Oracle Linux Security Advisory, ELSA-2016-3618.


We recommend that all users of Ksplice Uptrack on EL 5 install these

On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.

Alternatively, you can install these updates by running:

# /usr/sbin/uptrack-upgrade -y


* CVE-2016-4997, CVE-2016-4998: Privilege escalation in the Netfilter driver.

Incomplete input validation when processing Netfilter xtables entries could
lead to out of bounds memory read and write.  An unprivileged user inside a
container could use this flaw to cause a denial-of-service or elevate

* CVE-2015-8374: Information leak when truncating a compressed and inlined extent on Btrfs.

An information leak vulnerability was found when truncating a file to a
smaller size which consists of an inline extent that is compressed. The
data between the new file size and the old file size was not discarded,
allowing another user to read it through the clone ioctl.


Ksplice support is available at ksplice-support_ww at oracle.com.

More information about the El-errata mailing list