[Oraclevm-errata] OVMSA-2017-0104 Important: Oracle VM 3.4 Unbreakable Enterprise kernel security update

Errata Announcements for Oracle VM oraclevm-errata at oss.oracle.com
Tue May 16 10:09:59 PDT 2017


Oracle VM Security Advisory OVMSA-2017-0104

The following updated rpms for Oracle VM 3.4 have been uploaded to the 
Unbreakable Linux Network:

x86_64:
kernel-uek-4.1.12-94.3.4.el6uek.x86_64.rpm
kernel-uek-firmware-4.1.12-94.3.4.el6uek.noarch.rpm


SRPMS:
http://oss.oracle.com/oraclevm/server/3.4/SRPMS-updates/kernel-uek-4.1.12-94.3.4.el6uek.src.rpm



Description of changes:

[4.1.12-94.3.4.el6uek]
- ipv6: catch a null skb before using it in a DTRACE (Shannon Nelson) 
[Orabug: 26075879]
- sparc64: Do not retain old VM_SPARC_ADI flag when protection changes 
on page (Khalid Aziz)  [Orabug: 26038830]

[4.1.12-94.3.3.el6uek]
- nfsd: stricter decoding of write-like NFSv2/v3 ops (J. Bruce Fields) 
[Orabug: 25986971]  {CVE-2017-7895}

[4.1.12-94.3.2.el6uek]
- sparc64: Detect DAX ra+pgsz when hvapi minor doesn't indicate it (Rob 
Gardner)  [Orabug: 25997533]
- sparc64: DAX memory will use RA+PGSZ feature in HV (Rob Gardner) 
[Orabug: 25997533] [Orabug: 25931417]
- sparc64: Disable DAX flow control (Rob Gardner)  [Orabug: 25997226]
- sparc64: DAX memory needs persistent mappings (Rob Gardner)  [Orabug: 
25997137]
- sparc64: Fix incorrect error print in DAX driver when validating ccb 
(Sanath Kumar)  [Orabug: 25996975]
- sparc64: DAX request for non 4MB memory should return with unique 
errno (Sanath Kumar)  [Orabug: 25996823]
- sparc64: DAX request to mmap non 4MB memory should fail with a debug 
print (Sanath Kumar)  [Orabug: 25996823]
- sparc64: DAX request for non 4MB memory should return with unique 
errno (Sanath Kumar)  [Orabug: 25996823]
- sparc64: Incorrect print by DAX driver when old driver API is used 
(Sanath Kumar)  [Orabug: 25996790]
- sparc64: DAX request to dequeue half of a long CCB should not succeed 
(Sanath Kumar)  [Orabug: 25996747]
- sparc64: dax_overflow_check reports incorrect data (Sanath Kumar) 
[Orabug: 25996655]
- sparc64: Ignored DAX ref count causes lockup (Rob Gardner)  [Orabug: 
25996628]
- sparc64: disable dax page range checking on RA (Rob Gardner)  [Orabug: 
25996546]
- sparc64: Oracle Data Analytics Accelerator (DAX) driver (Sanath Kumar) 
  [Orabug: 25996522]
- sparc64: Add DAX hypervisor services (Allen Pais)  [Orabug: 25996475]
- sparc64: create/destroy cpu sysfs dynamically (Atish Patra)  [Orabug: 
21775890] [Orabug: 25216469]
- megaraid: Fix unaligned warning (Allen Pais)  [Orabug: 24817799]

[4.1.12-94.3.1.el6uek]
- Re-enable SDP for uek-nano kernel (Ashok Vairavan)  [Orabug: 25968572]
- xsigo: Compute node crash on FC failover (Pradeep Gopanapalli) 
[Orabug: 25946533]
- NVMe: Set affinity after allocating request queues (Keith Busch) 
[Orabug: 25945973]
- nvme: use an integer value to Linux errno values (Christoph Hellwig) 
[Orabug: 25945973]
- blk-mq: fix racy updates of rq->errors (Christoph Hellwig)  [Orabug: 
25945973]
- x86/apic: Handle zero vector gracefully in clear_vector_irq() (Keith 
Busch)  [Orabug: 24515998]
- PCI: Prevent VPD access for QLogic ISP2722 (Ethan Zhao)  [Orabug: 
24819170]
- PCI: Prevent VPD access for buggy devices (Babu Moger)  [Orabug: 
24819170]
- ipv6: Skip XFRM lookup if dst_entry in socket cache is valid (Jakub 
Sitnicki)  [Orabug: 25525433]
- Btrfs: don't BUG_ON() in btrfs_orphan_add (Josef Bacik)  [Orabug: 
25534945]
- Btrfs: clarify do_chunk_alloc()'s return value (Liu Bo)  [Orabug: 
25534945]
- btrfs: flush_space: treat return value of do_chunk_alloc properly 
(Alex Lyakas)  [Orabug: 25534945]
- Revert "[SCSI] libiscsi: Reduce locking contention in fast path" 
(Ashish Samant)  [Orabug: 25721518]
- qla2xxx: Allow vref count to timeout on vport delete. (Joe Carnuccio) 
  [Orabug: 25862953]
- Drivers: hv: kvp: fix IP Failover (Vitaly Kuznetsov)  [Orabug: 25866691]
- Drivers: hv: util: Pass the channel information during the init call 
(K. Y. Srinivasan)  [Orabug: 25866691]
- Drivers: hv: utils: run polling callback always in interrupt context 
(Olaf Hering)  [Orabug: 25866691]
- Drivers: hv: util: Increase the timeout for util services (K. Y. 
Srinivasan)  [Orabug: 25866691]
- Drivers: hv: kvp: check kzalloc return value (Vitaly Kuznetsov) 
[Orabug: 25866691]
- Drivers: hv: fcopy: dynamically allocate smsg_out in fcopy_send_data() 
(Vitaly Kuznetsov)
- Drivers: hv: vss: full handshake support (Vitaly Kuznetsov)  [Orabug: 
25866691]
- xen: Make VPMU init message look less scary (Juergen Gross)  [Orabug: 
25873416]
- udp: properly support MSG_PEEK with truncated buffers (Eric Dumazet) 
[Orabug: 25876652]  {CVE-2016-10229}




More information about the Oraclevm-errata mailing list