Description: | Summary: The remote host is missing an update for the 'kernel, ocfs2-2.6.18-128.7.1.0.1.el5, oracleasm-2.6.18-128.7.1.0.1.el5' package(s) announced via the ELSA-2009-1222 advisory.
Vulnerability Insight: [2.6.18-128.7.1.0.1.el5] - [NET] Add entropy support to e1000 and bnx2 (John Sobecki,Guru Anbalagane) [orabug 6045759] - [MM] shrink zone patch (John Sobecki,Chris Mason) [orabug 6086839] - [NET] Add xen pv/bonding netconsole support (Tina yang) [orabug 6993043] [bz 7258] - [nfs] convert ENETUNREACH to ENOTCONN (Guru Anbalagane) [orabug 7689332] - [xen] check to see if hypervisor supports memory reservation change (Chuck Anderson) [orabug 7556514] - [MM] balloon code needs to adjust totalhigh_pages (Chuck Anderson) [orabug 8300888] - [NET] Add entropy support to igb ( John Sobecki) [orabug 7607479] - [XEN] use hypercall to fixmap pte updates (Mukesh Rathor) [orabug 8433329] - [XEN] Extend physical mask to 40bit for machine above 64G [orabug 8312526]
[2.6.18-128.7.1.el5] - [net] prevent null pointer dereference in udp_sendmsg (Vitaly Mayatskikh) [518047 518043] {CVE-2009-2698}
[2.6.18-128.6.1.el5] - [net] make sock_sendpage use kernel_sendpage (Jiri Pirko ) [517445 516955] {CVE-2009-2692}
[2.6.18-128.5.1.el5] - [dlm] free socket in error exit path (David Teigland ) [515432 508829]
Affected Software/OS: 'kernel, ocfs2-2.6.18-128.7.1.0.1.el5, oracleasm-2.6.18-128.7.1.0.1.el5' package(s) on Oracle Linux 5.
Solution: Please install the updated package(s).
CVSS Score: 7.2
CVSS Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
|