[ELSA-2019-4316] Unbreakable Enterprise kernel security update

Severity Important
Affected Packages 14
CVEs 22

kernel-uek
[3.8.13-118.29.1]
- Copy secure_boot flag in boot params across kexec reboot (Dave Young) [Orabug: 22066352] {CVE-2015-7837}
- ipv6: tcp: add rcu locking in tcp_v6_send_synack() (Eric Dumazet) [Orabug: 25059183] {CVE-2016-3841}
- ipv6: add complete rcu protection around np->opt (Eric Dumazet) [Orabug: 25059183] {CVE-2016-3841}
- scsi: qla2xxx: Fix an integer overflow in sysfs code (Dan Carpenter) [Orabug: 28220420] {CVE-2017-14051}
- ext4: fail ext4_iget for root directory if unallocated (Theodore Ts'o) [Orabug: 28220433] {CVE-2018-1092} {CVE-2018-1092}
- certs: Add Oracle's new X509 cert into the kernel keyring (Eric Snowberg) [Orabug: 28926205]
- ALSA: seq: Fix regression by incorrect ioctl_mutex usages (Takashi Iwai) [Orabug: 29005190] {CVE-2018-1000004}
- netfilter: xt_osf: Add missing permission checks (Kevin Cernekee) [Orabug: 29037832] {CVE-2017-17450}
- wil6210: missing length check in wmi_set_ie (Lior David) [Orabug: 29060697] {CVE-2018-5848}
- HID: debug: check length before copy_to_user() (Daniel Rosenberg) [Orabug: 29128167] {CVE-2018-9516}
- x86/MCE: Serialize sysfs changes (Seunghun Han) [Orabug: 29152249] {CVE-2018-7995}
- Input: i8042 - fix crash at boot time (Chen Hong) [Orabug: 29152329] {CVE-2017-18079}

ID
ELSA-2019-4316
Severity
important
URL
https://linux.oracle.com/errata/ELSA-2019-4316.html
Published
2019-01-04T00:00:00
(5 years ago)
Modified
2019-01-04T00:00:00
(5 years ago)
Rights
Copyright 2019 Oracle, Inc.
Other Advisories
Source # ID Name URL
elsa ELSA-2019-4316 http://linux.oracle.com/errata/ELSA-2019-4316.html
CVE CVE-2015-7837 http://linux.oracle.com/cve/CVE-2015-7837.html
CVE CVE-2016-3841 http://linux.oracle.com/cve/CVE-2016-3841.html
CVE CVE-2017-18017 http://linux.oracle.com/cve/CVE-2017-18017.html
CVE CVE-2018-1000004 http://linux.oracle.com/cve/CVE-2018-1000004.html
CVE CVE-2017-17805 http://linux.oracle.com/cve/CVE-2017-17805.html
CVE CVE-2018-1092 http://linux.oracle.com/cve/CVE-2018-1092.html
CVE CVE-2018-5848 http://linux.oracle.com/cve/CVE-2018-5848.html
CVE CVE-2018-7757 http://linux.oracle.com/cve/CVE-2018-7757.html
CVE CVE-2018-10902 http://linux.oracle.com/cve/CVE-2018-10902.html
CVE CVE-2017-13168 http://linux.oracle.com/cve/CVE-2017-13168.html
CVE CVE-2018-1000204 http://linux.oracle.com/cve/CVE-2018-1000204.html
CVE CVE-2018-18710 http://linux.oracle.com/cve/CVE-2018-18710.html
CVE CVE-2014-9728 http://linux.oracle.com/cve/CVE-2014-9728.html
CVE CVE-2016-3713 http://linux.oracle.com/cve/CVE-2016-3713.html
CVE CVE-2017-17806 http://linux.oracle.com/cve/CVE-2017-17806.html
CVE CVE-2018-7755 http://linux.oracle.com/cve/CVE-2018-7755.html
CVE CVE-2018-10021 http://linux.oracle.com/cve/CVE-2018-10021.html
CVE CVE-2017-18079 http://linux.oracle.com/cve/CVE-2017-18079.html
CVE CVE-2017-14051 http://linux.oracle.com/cve/CVE-2017-14051.html
CVE CVE-2017-17450 http://linux.oracle.com/cve/CVE-2017-17450.html
CVE CVE-2018-7995 http://linux.oracle.com/cve/CVE-2018-7995.html
CVE CVE-2018-9516 http://linux.oracle.com/cve/CVE-2018-9516.html
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/oraclelinux/kernel-uek?distro=oraclelinux-7 oraclelinux kernel-uek < 3.8.13-118.29.1.el7uek oraclelinux-7
Affected pkg:rpm/oraclelinux/kernel-uek?distro=oraclelinux-6 oraclelinux kernel-uek < 3.8.13-118.29.1.el6uek oraclelinux-6
Affected pkg:rpm/oraclelinux/kernel-uek-firmware?distro=oraclelinux-7 oraclelinux kernel-uek-firmware < 3.8.13-118.29.1.el7uek oraclelinux-7
Affected pkg:rpm/oraclelinux/kernel-uek-firmware?distro=oraclelinux-6 oraclelinux kernel-uek-firmware < 3.8.13-118.29.1.el6uek oraclelinux-6
Affected pkg:rpm/oraclelinux/kernel-uek-doc?distro=oraclelinux-7 oraclelinux kernel-uek-doc < 3.8.13-118.29.1.el7uek oraclelinux-7
Affected pkg:rpm/oraclelinux/kernel-uek-doc?distro=oraclelinux-6 oraclelinux kernel-uek-doc < 3.8.13-118.29.1.el6uek oraclelinux-6
Affected pkg:rpm/oraclelinux/kernel-uek-devel?distro=oraclelinux-7 oraclelinux kernel-uek-devel < 3.8.13-118.29.1.el7uek oraclelinux-7
Affected pkg:rpm/oraclelinux/kernel-uek-devel?distro=oraclelinux-6 oraclelinux kernel-uek-devel < 3.8.13-118.29.1.el6uek oraclelinux-6
Affected pkg:rpm/oraclelinux/kernel-uek-debug?distro=oraclelinux-7 oraclelinux kernel-uek-debug < 3.8.13-118.29.1.el7uek oraclelinux-7
Affected pkg:rpm/oraclelinux/kernel-uek-debug?distro=oraclelinux-6 oraclelinux kernel-uek-debug < 3.8.13-118.29.1.el6uek oraclelinux-6
Affected pkg:rpm/oraclelinux/kernel-uek-debug-devel?distro=oraclelinux-7 oraclelinux kernel-uek-debug-devel < 3.8.13-118.29.1.el7uek oraclelinux-7
Affected pkg:rpm/oraclelinux/kernel-uek-debug-devel?distro=oraclelinux-6 oraclelinux kernel-uek-debug-devel < 3.8.13-118.29.1.el6uek oraclelinux-6
Affected pkg:rpm/oraclelinux/dtrace-modules-3.8.13-118.29.1.el7uek?distro=oraclelinux-7 oraclelinux dtrace-modules-3.8.13-118.29.1.el7uek < 0.4.5-3.el7 oraclelinux-7
Affected pkg:rpm/oraclelinux/dtrace-modules-3.8.13-118.29.1.el6uek?distro=oraclelinux-6 oraclelinux dtrace-modules-3.8.13-118.29.1.el6uek < 0.4.5-3.el6 oraclelinux-6
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...