Description: | Summary: The remote host is missing an update for the 'kernel, ocfs2-2.6.18-128.1.1.0.1.el5, oracleasm-2.6.18-128.1.1.0.1.el5' package(s) announced via the ELSA-2009-0264 advisory.
Vulnerability Insight: [2.6.18-128.1.1.0.1.el5] - [NET] Add entropy support to e1000 and bnx2 (John Sobecki,Guru Anbalagane) [orabug 6045759] - [MM] shrink zone patch (John Sobecki,Chris Mason) [orabug 6086839] - [NET] Add xen pv/bonding netconsole support (Tina yang) [orabug 6993043] [bz 7258] - [nfs] convert ENETUNREACH to ENOTCONN (Guru Anbalagane) [orabug 7689332]
[2.6.18-128.1.1.el5] - [security] introduce missing kfree (Jiri Pirko ) [480597 480598] {CVE-2009-0031} - [sched] fix clock_gettime monotonicity (Peter Zijlstra ) [481122 477763] - [nfs] create rpc clients with proper auth flavor (Jeff Layton ) [481119 465456] - [net] sctp: overflow with bad stream ID in FWD-TSN chunk (Eugene Teo ) [478804 478805] {CVE-2009-0065} - [md] fix oops with device-mapper mirror target (Heinz Mauelshagen ) [481120 472558] - [openib] restore traffic in connected mode on HCA (AMEET M. PARANJAPE ) [479812 477000] - [net] add preemption point in qdisc_run (Jiri Pirko ) [477746 471398] {CVE-2008-5713} - [x86_64] copy_user_c assembler can leave garbage in rsi (Larry Woodman ) [481117 456682] - [misc] setpgid returns ESRCH in some situations (Oleg Nesterov ) [480576 472433] - [s390] zfcp: fix hexdump data in s390dbf traces (Hans-Joachim Picht ) [480996 470618] - [fs] hfsplus: fix buffer overflow with a corrupted image (Anton Arapov ) [469637 469638] {CVE-2008-4933} - [fs] hfsplus: check read_mapping_page return value (Anton Arapov ) [469644 469645] {CVE-2008-4934} - [fs] hfs: fix namelength memory corruption (Anton Arapov ) [470772 470773] {CVE-2008-5025}
Affected Software/OS: 'kernel, ocfs2-2.6.18-128.1.1.0.1.el5, oracleasm-2.6.18-128.1.1.0.1.el5' package(s) on Oracle Linux 5.
Solution: Please install the updated package(s).
CVSS Score: 10.0
CVSS Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
|