Description: | Summary: The remote host is missing an update for the 'kernel, ocfs2-2.6.18-238.el5, oracleasm-2.6.18-238.el5' package(s) announced via the ELSA-2011-0017 advisory.
Vulnerability Insight: [2.6.18-238.el5] - [net] bnx2: remove extra call to pci_map_page (John Feeney) [663509] - [fs] nfs: set lock_context field in nfs_readpage_sync (Jeff Layton) [663853]
[2.6.18-237.el5] - [block] fully zeroize request struct in rq_init (Rob Evers) [662154] - [scsi] qla4xxx: update to 5.02.04.02.05.06-d0 (Chad Dupuis) [656999] - [scsi] qla4xxx: make get_sys_info function return void (Chad Dupuis) [656999] - [scsi] qla4xxx: don't default device to FAILED state (Chad Dupuis) [656999] - [scsi] qla4xxx: mask bits in F/W Options during init (Chad Dupuis) [656999] - [scsi] qla4xxx: update to 5.02.04.01.05.06-d0 (Chad Dupuis) [661768] - [scsi] qla4xxx: disable irq instead of req pci_slot_reset (Chad Dupuis) [661768] - [scsi] qla4xxx: no device add until scsi_add_host success (Chad Dupuis) [661768] - [fs] nfs: set lock_context field in nfs_writepage_sync (Jeff Layton) [660580] - [scsi] bfa: fix crash reading driver sysfs statistics (Rob Evers) [659880] {CVE-2010-4343} - [misc] cpufeature: avoid corrupting cpuid vendor id (Matthew Garrett) [568751] - [char] drm: don't set signal blocker on master process (Dave Airlie) [570604] - [fs] nfs: remove problematic calls to nfs_clear_request (Jeff Layton) [656492] - [fs] nfs: handle alloc failures in nfs_create_request (Jeff Layton) [656492] - [fs] nfs: clean up nfs_create_request (Jeff Layton) [656492] - [net] forcedeth: fix race condition in latest backport (Ivan Vecera) [658434] - [net] cxgb3: fix read of uninitialized stack memory (Jay Fenlason) [633155] {CVE-2010-3296} - [net] tg3: increase jumbo flag threshold (John Feeney) [660506] - [net] s2io: fix netdev initialization failure (Bob Picco) [654948] - [net] igb: only use vlan_gro_receive if vlans registered (Stefan Assmann) [660190] {CVE-2010-4263} - [net] ipv6: try all routers with unknown reachable state (Thomas Graf) [661393] - [misc] kernel: fix address limit override in OOPS path (Dave Anderson) [659571] {CVE-2010-4258}
[2.6.18-236.el5] - [powerpc] support DLPAR remove operations (Steve Best) [655089] - [net] igb: fix tx packet count (Stefan Assmann) [658801] - [usb] serial: new driver MosChip MCS7840 (Stefan Assmann) [574507] - [fs] exec: copy fixes into compat_do_execve paths (Oleg Nesterov) [625694] {CVE-2010-4243} - [fs] exec: make argv/envp memory visible to oom-killer (Oleg Nesterov) [625694] {CVE-2010-4243} - [misc] binfmts: kill bprm->argv_len (Oleg Nesterov) [625694] {CVE-2010-4243} - [mm] backport upstream stack guard page /proc reporting (Larry Woodman) [643426] - [mm] add guard page for stacks that grow upwards (Johannes Weiner) [630563] - [net] tipc: fix information leak to userland (Jiri Pirko) [649892] {CVE-2010-3877} - [sound] ALSA: fix sysfs unload and OSS mixer mutex issues (Jaroslav Kysela) [652165] - [net] tg3: fix 5719 bugs (John Feeney) [657097] - [net] bnx2: update firmware to 6.0.x (John Feeney) [644438] - [redhat] configs: add ... [Please see the references for more information on the vulnerabilities]
Affected Software/OS: 'kernel, ocfs2-2.6.18-238.el5, oracleasm-2.6.18-238.el5' package(s) on Oracle Linux 5.
Solution: Please install the updated package(s).
CVSS Score: 7.9
CVSS Vector: AV:A/AC:M/Au:N/C:C/I:C/A:C
|