Description: | Summary: The remote host is missing an update for the 'kernel' package(s) announced via the ELSA-2011-0007 advisory.
Vulnerability Insight: [2.6.32-71.14.1.0.1.el6] - replace Red Hat with Oracle in files genkey and kernel.spec
[2.6.32-71.14.1.el6] - [kvm] x86: zero kvm_vcpu_events->interrupt.pad (Marcelo Tosatti) [665471 665409] {CVE-2010-4525}
[2.6.32-71.13.1.el6] email_6.RHSA-2011-0007 178L, 11970C written - [scsi] lpfc: Fixed crashes for NULL pnode dereference (Rob Evers) [660589 635733]
[2.6.32-71.12.1.el6] - [netdrv] igb: only use vlan_gro_receive if vlans are registered (Stefan Assmann) [652804 660192] {CVE-2010-4263} - [net] core: neighbour update Oops (Jiri Pirko) [660591 658518] - [scsi] lpfc: Set heartbeat timer off by default (Rob Evers) [660244 655935] - [scsi] lpfc: Fixed crashes for BUG_ONs hit in the lpfc_abort_handler (Rob Evers) [659611 645882]
[2.6.32-71.11.1.el6] - [kernel] posix-cpu-timers: workaround to suppress the problems with mt exec (Oleg Nesterov) [656267 656268] {CVE-2010-4248} - [fs] bio: take care not overflow page count when mapping/copying user data (Danny Feng) [652530 652531] {CVE-2010-4162} - [net] can-bcm: fix minor heap overflow (Danny Feng) [651846 651847] {CVE-2010-3874} - [net] filter: make sure filters don't read uninitialized memory (Jiri Pirko) [651704 651705] {CVE-2010-4158} - [net] inet_diag: Make sure we actually run the same bytecode we audited (Jiri Pirko) [651268 651269] {CVE-2010-3880} - [v4l] ivtvfb: prevent reading uninitialized stack memory (Mauro Carvalho Chehab) [648832 648833] {CVE-2010-4079} - [drm] via/ioctl.c: prevent reading uninitialized stack memory (Dave Airlie) [648718 648719] {CVE-2010-4082} - [char] nozomi: clear data before returning to userspace on TIOCGICOUNT (Mauro Carvalho Chehab) [648705 648706] {CVE-2010-4077} - [serial] clean data before filling it on TIOCGICOUNT (Mauro Carvalho Chehab) [648702 648703] {CVE-2010-4075} - [net] af_unix: limit unix_tot_inflight (Neil Horman) [656761 656762] {CVE-2010-4249} - [block] check for proper length of iov entries in blk_rq_map_user_iov() (Danny Feng) [652958 652959] {CVE-2010-4163} - [net] Limit sendto()/recvfrom()/iovec total length to INT_MAX (Jiri Pirko) [651894 651895] {CVE-2010-4160} - [netdrv] mlx4: Add OFED-1.5.2 patch to increase log_mtts_per_seg (Jay Fenlason) [643815 637284] - [kernel] kbuild: fix external module compiling (Aristeu Rozanski) [658879 655231] - [net] bluetooth: Fix missing NULL check (Jarod Wilson) [655667 655668] {CVE-2010-4242} - [kernel] ipc: initialize structure memory to zero for compat functions (Danny Feng) [648694 648695] {CVE-2010-4073} - [kernel] shm: fix information leak to userland (Danny Feng) [648688 648689] {CVE-2010-4072} - [md] dm: remove extra locking when changing device size (Mike Snitzer) [653900 644380] - [block] read i_size with i_size_read() (Mike Snitzer) [653900 644380] - [kbuild] don't sign out-of-tree modules (Aristeu Rozanski) [655122 653507]
[2.6.32-71.10.1.el6] - [fs] xfs: prevent reading uninitialized stack memory (Dave Chinner) [630808 ... [Please see the references for more information on the vulnerabilities]
Affected Software/OS: 'kernel' package(s) on Oracle Linux 6.
Solution: Please install the updated package(s).
CVSS Score: 8.3
CVSS Vector: AV:A/AC:L/Au:N/C:C/I:C/A:C
|