[El-errata] New Ksplice updates for UEKR4 4.1.12 on OL6 and OL7 (ELSA-2017-3539)
Errata Announcements for Oracle Linux
el-errata at oss.oracle.com
Tue Apr 18 03:51:20 PDT 2017
Synopsis: ELSA-2017-3539 can now be patched using Ksplice
CVEs: CVE-2016-10208 CVE-2016-10229 CVE-2016-7910 CVE-2017-2583 CVE-2017-5986 CVE-2017-6214 CVE-2017-6347 CVE-2017-7184
Users with Oracle Linux Premier Support can now use Ksplice to patch
against the latest Oracle Linux Security Advisory, ELSA-2017-3539.
INSTALLING THE UPDATES
We recommend that all users of Ksplice Uptrack running UEKR4 4.1.12 on
OL6 and OL7 install these updates.
On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.
Alternatively, you can install these updates by running:
# /usr/sbin/uptrack-upgrade -y
DESCRIPTION
* CVE-2016-10229: Remote code execution when receiving UDP packet with short buffers.
Incorrect handling of checksums for short receive buffers could result
in applications failing to receive data from a UDP socket. A remote
attacker could use this flaw to execute arbitrary code.
* CVE-2016-7910: Privilege escalation in /proc/partitions.
Incorrect cleanup when finishing reading /proc/partitions could result
in a use-after-free condition. A local, unprivileged user could use
this flaw to crash the system, or potentially, escalate privileges.
* CVE-2017-7184: Privilege escalation when using xfrm IP framework.
A missing check when using xfrm IP framework could lead to an out of
bound access. A local attacker could use this flaw to cause a denial of
service or to escalate privilege.
* CVE-2017-6214: Denial-of-service when splicing from TCP socket.
A specially crafted packet can be queued to trigger an infinite loop in
IPv4 subsystem. This can be exploited by an remote attacker to cause
denial-of-service.
* CVE-2017-5986: Denial-of-service when using SCTP socket with concurrent thread.
A BUG_ON() could be triggered when queueing data in a full SCTP socket
while another thread disassociates the first thread from the socket. A
local attacker could use this flaw to cause a denial-of-service.
* CVE-2016-10208: Denial-of-service when mounting ext4 image with large metablock group.
A missing check when mounting an ext4 image with a high first metablock
group value could lead to a buffer overflow. A local attacker with mount
capability could use this flaw to cause a denial-of-service.
* CVE-2017-2583: Denial-of-service due to incorrect segments configuration within VMs.
A logic error leads to an incorrect configuration of segment selector
within a Virtual Machine. An attacker could use this incorrect
configuration to cause a denial-of-service of the VM.
* CVE-2017-6347: Denial of service in IPv4 IP_CHECKSUM control message.
A logic error when calculating the checksum of an IPv4 packet can trigger an
out-of-bounds read and kernel panic. A local user could use this flaw to cause
a denial of service.
SUPPORT
Ksplice support is available at ksplice-support_ww at oracle.com.
More information about the El-errata
mailing list