[Ksplice-Fedora-19-updates] New updates available via Ksplice (FEDORA-2013-18820)

Oracle Ksplice ksplice-support_ww at oracle.com
Mon Oct 14 13:56:16 PDT 2013


Synopsis: FEDORA-2013-18820 can now be patched using Ksplice
CVEs: CVE-2013-4387

Systems running Fedora 19 can now use Ksplice to patch against the
latest Fedora kernel update, FEDORA-2013-18820.

INSTALLING THE UPDATES

We recommend that all users of Ksplice Uptrack on Fedora 19 install
these updates.

On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.

Alternatively, you can install these updates by running:

# /usr/sbin/uptrack-upgrade -y


DESCRIPTION

* Memory corruption in filesystem buffer management.

The kernel does not correctly map memory when copying large filesystem buffers
leading to memory corruption and a kernel panic.


* Data loss in block device writeback flushing.

The block device driver uses incorrect options when flushing data on a block
device with writeback enabled, leading to data corruption on the backing device.


* Use-after-free in kernel device management.

The kernel does not correctly manage reference counts when removing devices from
the system leading to a use-after-free condition and kernel panic.


* CVE-2013-4387: Memory corruption in IPv6 UDP fragmentation offload.

The kernel IPv6 stack does not correctly handle queuing multiple UDP fragments
when using UDP Fragmentation Offloading allowing a local unprivileged user to
cause kernel memory corruption and potentially gain privileged code execution.


* Use-after-free in netfilter connection tracking extensions.

A race condition in netfilter connection tracking allows the kernel to free
in-use extensions leading to a use-after-free condition and kernel panic.


* Denial-of-service in virtual function I/O IOMMU_MAP_DMA ioctl.

An incorrect assertion in the VFIO_IOMMU_MAP_DMA ioctl allows local users with
access to the /dev/vfio/vfio device to trigger a kernel panic.

SUPPORT

Ksplice support is available at ksplice-support_ww at oracle.com.


  



More information about the Ksplice-Fedora-19-Updates mailing list