[ELSA-2015-3055] Unbreakable Enterprise kernel security update

Severity Moderate
Affected Packages 20
CVEs 4

kernel-uek
[2.6.32-400.37.9uek]
- x86, tls: Interpret an all-zero struct user_desc as 'no segment' (Andy Lutomirski) [Orabug: 21518750]
- x86, tls, ldt: Stop checking lm in LDT_empty (Andy Lutomirski) [Orabug: 21518750]

[2.6.32-400.37.8uek]
- KVM: x86: SYSENTER emulation is broken (Nadav Amit) [Orabug: 21502741] {CVE-2015-0239} {CVE-2015-0239}
- x86/tls: Validate TLS entries to protect espfix (Andy Lutomirski) [Orabug: 20223778] {CVE-2014-8133}
- fs: take i_mutex during prepare_binprm for set[ug]id executables (Jann Horn) [Orabug: 21502256] {CVE-2015-3339}
- eCryptfs: Remove buggy and unnecessary write in file name decode routine (Michael Halcrow) [Orabug: 21502067] {CVE-2014-9683}

Package Affected Version
pkg:rpm/oraclelinux/ofa-2.6.32-400.37.9.el6uekdebug < 1.5.1-4.0.58
pkg:rpm/oraclelinux/ofa-2.6.32-400.37.9.el6uek < 1.5.1-4.0.58
pkg:rpm/oraclelinux/ofa-2.6.32-400.37.9.el5uekdebug < 1.5.1-4.0.58
pkg:rpm/oraclelinux/ofa-2.6.32-400.37.9.el5uek < 1.5.1-4.0.58
pkg:rpm/oraclelinux/mlnx_en-2.6.32-400.37.9.el6uekdebug < 1.5.7-0.1
pkg:rpm/oraclelinux/mlnx_en-2.6.32-400.37.9.el6uek < 1.5.7-0.1
pkg:rpm/oraclelinux/mlnx_en-2.6.32-400.37.9.el5uekdebug < 1.5.7-2
pkg:rpm/oraclelinux/mlnx_en-2.6.32-400.37.9.el5uek < 1.5.7-2
pkg:rpm/oraclelinux/kernel-uek?distro=oraclelinux-6 < 2.6.32-400.37.9.el6uek
pkg:rpm/oraclelinux/kernel-uek?distro=oraclelinux-5 < 2.6.32-400.37.9.el5uek
pkg:rpm/oraclelinux/kernel-uek-firmware?distro=oraclelinux-6 < 2.6.32-400.37.9.el6uek
pkg:rpm/oraclelinux/kernel-uek-firmware?distro=oraclelinux-5 < 2.6.32-400.37.9.el5uek
pkg:rpm/oraclelinux/kernel-uek-doc?distro=oraclelinux-6 < 2.6.32-400.37.9.el6uek
pkg:rpm/oraclelinux/kernel-uek-doc?distro=oraclelinux-5 < 2.6.32-400.37.9.el5uek
pkg:rpm/oraclelinux/kernel-uek-devel?distro=oraclelinux-6 < 2.6.32-400.37.9.el6uek
pkg:rpm/oraclelinux/kernel-uek-devel?distro=oraclelinux-5 < 2.6.32-400.37.9.el5uek
pkg:rpm/oraclelinux/kernel-uek-debug?distro=oraclelinux-6 < 2.6.32-400.37.9.el6uek
pkg:rpm/oraclelinux/kernel-uek-debug?distro=oraclelinux-5 < 2.6.32-400.37.9.el5uek
pkg:rpm/oraclelinux/kernel-uek-debug-devel?distro=oraclelinux-6 < 2.6.32-400.37.9.el6uek
pkg:rpm/oraclelinux/kernel-uek-debug-devel?distro=oraclelinux-5 < 2.6.32-400.37.9.el5uek
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/oraclelinux/ofa-2.6.32-400.37.9.el6uekdebug oraclelinux ofa-2.6.32-400.37.9.el6uekdebug < 1.5.1-4.0.58
Affected pkg:rpm/oraclelinux/ofa-2.6.32-400.37.9.el6uek oraclelinux ofa-2.6.32-400.37.9.el6uek < 1.5.1-4.0.58
Affected pkg:rpm/oraclelinux/ofa-2.6.32-400.37.9.el5uekdebug oraclelinux ofa-2.6.32-400.37.9.el5uekdebug < 1.5.1-4.0.58
Affected pkg:rpm/oraclelinux/ofa-2.6.32-400.37.9.el5uek oraclelinux ofa-2.6.32-400.37.9.el5uek < 1.5.1-4.0.58
Affected pkg:rpm/oraclelinux/mlnx_en-2.6.32-400.37.9.el6uekdebug oraclelinux mlnx_en-2.6.32-400.37.9.el6uekdebug < 1.5.7-0.1
Affected pkg:rpm/oraclelinux/mlnx_en-2.6.32-400.37.9.el6uek oraclelinux mlnx_en-2.6.32-400.37.9.el6uek < 1.5.7-0.1
Affected pkg:rpm/oraclelinux/mlnx_en-2.6.32-400.37.9.el5uekdebug oraclelinux mlnx_en-2.6.32-400.37.9.el5uekdebug < 1.5.7-2
Affected pkg:rpm/oraclelinux/mlnx_en-2.6.32-400.37.9.el5uek oraclelinux mlnx_en-2.6.32-400.37.9.el5uek < 1.5.7-2
Affected pkg:rpm/oraclelinux/kernel-uek?distro=oraclelinux-6 oraclelinux kernel-uek < 2.6.32-400.37.9.el6uek oraclelinux-6
Affected pkg:rpm/oraclelinux/kernel-uek?distro=oraclelinux-5 oraclelinux kernel-uek < 2.6.32-400.37.9.el5uek oraclelinux-5
Affected pkg:rpm/oraclelinux/kernel-uek-firmware?distro=oraclelinux-6 oraclelinux kernel-uek-firmware < 2.6.32-400.37.9.el6uek oraclelinux-6
Affected pkg:rpm/oraclelinux/kernel-uek-firmware?distro=oraclelinux-5 oraclelinux kernel-uek-firmware < 2.6.32-400.37.9.el5uek oraclelinux-5
Affected pkg:rpm/oraclelinux/kernel-uek-doc?distro=oraclelinux-6 oraclelinux kernel-uek-doc < 2.6.32-400.37.9.el6uek oraclelinux-6
Affected pkg:rpm/oraclelinux/kernel-uek-doc?distro=oraclelinux-5 oraclelinux kernel-uek-doc < 2.6.32-400.37.9.el5uek oraclelinux-5
Affected pkg:rpm/oraclelinux/kernel-uek-devel?distro=oraclelinux-6 oraclelinux kernel-uek-devel < 2.6.32-400.37.9.el6uek oraclelinux-6
Affected pkg:rpm/oraclelinux/kernel-uek-devel?distro=oraclelinux-5 oraclelinux kernel-uek-devel < 2.6.32-400.37.9.el5uek oraclelinux-5
Affected pkg:rpm/oraclelinux/kernel-uek-debug?distro=oraclelinux-6 oraclelinux kernel-uek-debug < 2.6.32-400.37.9.el6uek oraclelinux-6
Affected pkg:rpm/oraclelinux/kernel-uek-debug?distro=oraclelinux-5 oraclelinux kernel-uek-debug < 2.6.32-400.37.9.el5uek oraclelinux-5
Affected pkg:rpm/oraclelinux/kernel-uek-debug-devel?distro=oraclelinux-6 oraclelinux kernel-uek-debug-devel < 2.6.32-400.37.9.el6uek oraclelinux-6
Affected pkg:rpm/oraclelinux/kernel-uek-debug-devel?distro=oraclelinux-5 oraclelinux kernel-uek-debug-devel < 2.6.32-400.37.9.el5uek oraclelinux-5
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...