[Ksplice-Fedora-27-updates] New Ksplice updates for Fedora 27 (FEDORA-2017-f280f7985e)

Oracle Ksplice ksplice-support_ww at oracle.com
Thu Dec 14 12:54:17 PST 2017


Synopsis: FEDORA-2017-f280f7985e can now be patched using Ksplice

Systems running Fedora 27 can now use Ksplice to patch against the
latest Fedora kernel update, FEDORA-2017-f280f7985e.

INSTALLING THE UPDATES

We recommend that all users of Ksplice Uptrack running Fedora 27
install these updates.

On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.

Alternatively, you can install these updates by running:

# /usr/sbin/uptrack-upgrade -y


DESCRIPTION

* NULL pointer dereference in large page allocation.

A incorrect function call in the hugetlb code could lead to a NULL
pointer dereference during allocation when in 5-level paging mode.
A malicious user could exploit this to cause a denial-of-service.


* Kernel panic in NFS4 server during unlock.

A typo in the NFS4 code could lead to a panic on the server side
with a "unable to handle kernel page request" while doing an unlock.


* NULL pointer dereference in crypto AEAD receive.

A missing check in the crypto AEAD receive code could lead to
a NULL pointer dereference when receiving messages.  A malicious
user could use this to cause a denial-of-service.


* NULL pointer dereference in IIO multiplexer when configuring channels.

A missing check in the IIO multiplexer code could lead to a NULL
pointer dereference when setting up channels.  A malicious user
could use this to cause a denial-of-service.


* Kernel panic in USB xhci removal.

A missing check in the USB xhci code could cause a kernel panic
if remove is called shortly after a probe.  A malicious user could
exploit this to cause a denial-of-service.


* Denial-of-service in USB filesystem.

A missing check in the USB fs code could allow a malicious
user to send in invalid flags causing a denial-of-service.

SUPPORT

Ksplice support is available at ksplice-support_ww at oracle.com.





More information about the Ksplice-Fedora-27-Updates mailing list