Description: | Summary: The remote host is missing an update for the 'kernel' package(s) announced via the ELSA-2015-1137 advisory.
Vulnerability Insight: [3.10.0-229.7.2] - Oracle Linux certificates (Alexey Petrenko)
[3.10.0-229.7.2] - [fs] pipe: fix pipe corruption and iovec overrun on partial copy (Seth Jennings) [1202861 1198843] {CVE-2015-1805}
[3.10.0-229.7.1] - [scsi] storvsc: get rid of overly verbose warning messages (Vitaly Kuznetsov) [1215770 1206437] - [scsi] storvsc: force discovery of LUNs that may have been removed (Vitaly Kuznetsov) [1215770 1206437] - [scsi] storvsc: in response to a scan event, scan the host (Vitaly Kuznetsov) [1215770 1206437] - [scsi] storvsc: NULL pointer dereference fix (Vitaly Kuznetsov) [1215770 1206437] - [virtio] defer config changed notifications (David Gibson) [1220278 1196009] - [virtio] unify config_changed handling (David Gibson) [1220278 1196009] - [x86] kernel: Remove a bogus 'ret_from_fork' optimization (Mateusz Guzik) [1209234 1209235] {CVE-2015-2830} - [kernel] futex: Mention key referencing differences between shared and private futexes (Larry Woodman) [1219169 1205862] - [kernel] futex: Ensure get_futex_key_refs() always implies a barrier (Larry Woodman) [1219169 1205862] - [scsi] megaraid_sas: revert: Add release date and update driver version (Tomas Henzl) [1216213 1207175] - [kernel] module: set nx before marking module MODULE_STATE_COMING (Hendrik Brueckner) [1214788 1196977] - [kernel] module: Clean up ro/nx after early module load failures (Pratyush Anand) [1214403 1202866] - [drm] radeon: fix kernel segfault in hwmonitor (Jerome Glisse) [1213467 1187817] - [fs] btrfs: make xattr replace operations atomic (Eric Sandeen) [1205086 1205873] - [x86] mm: Linux stack ASLR implementation (Jacob Tanenbaum) [1195684 1195685] {CVE-2015-1593} - [net] netfilter: nf_tables: fix flush ruleset chain dependencies (Jiri Pirko) [1192880 1192881] {CVE-2015-1573} - [fs] isofs: Fix unchecked printing of ER records (Mateusz Guzik) [1180482 1180483] {CVE-2014-9584} - [security] keys: memory corruption or panic during key garbage collection (Jacob Tanenbaum) [1179851 1179852] {CVE-2014-9529} - [fs] isofs: infinite loop in CE record entries (Jacob Tanenbaum) [1175246 1175248] {CVE-2014-9420}
[3.10.0-229.6.1] - [net] tcp: abort orphan sockets stalling on zero window probes (Florian Westphal) [1215924 1151756] - [x86] crypto: aesni - fix memory usage in GCM decryption (Kurt Stutsman) [1213331 1212178] {CVE-2015-3331}
[3.10.0-229.5.1] - [powerpc] mm: thp: Add tracepoints to track hugepage invalidate (Gustavo Duarte) [1212977 1199016] - [powerpc] mm: Use read barrier when creating real_pte (Gustavo Duarte) [1212977 1199016] - [powerpc] mm: thp: Use ACCESS_ONCE when loading pmdp (Gustavo Duarte) [1212977 1199016] - [powerpc] mm: thp: Invalidate with vpn in loop (Gustavo Duarte) [1212977 1199016] - [powerpc] mm: thp: Handle combo pages in invalidate (Gustavo Duarte) [1212977 1199016] - [powerpc] mm: thp: Invalidate old 64K based hash page mapping before insert of 4k pte (Gustavo Duarte) ... [Please see the references for more information on the vulnerabilities]
Affected Software/OS: 'kernel' package(s) on Oracle Linux 7.
Solution: Please install the updated package(s).
CVSS Score: 7.2
CVSS Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
|