Description: | Summary: The remote host is missing an update for the 'kernel-uek, mlnx_en-2.6.32-400.36.9.el5uek, mlnx_en-2.6.32-400.36.9.el6uek, ofa-2.6.32-400.36.9.el5uek, ofa-2.6.32-400.36.9.el6uek' package(s) announced via the ELSA-2014-3083 advisory.
Vulnerability Insight: kernel-uek [2.6.32-400.36.9uek] - ALSA: control: Don't access controls outside of protected regions (Lars-Peter Clausen) [Orabug: 19817787] {CVE-2014-4653} {CVE-2014-4654} {CVE-2014-4655} - ALSA: control: Fix replacing user controls (Lars-Peter Clausen) [Orabug: 19817749] {CVE-2014-4653} {CVE-2014-4654} {CVE-2014-4655} - mm: try_to_unmap_cluster() should lock_page() before mlocking (Vlastimil Babka) [Orabug: 19817324] {CVE-2014-3122} - vm: convert fb_mmap to vm_iomap_memory() helper (Linus Torvalds) [Orabug: 19816564] {CVE-2013-2596} - vm: add vm_iomap_memory() helper function (Linus Torvalds) [Orabug: 19816564] {CVE-2013-2596} - net: sctp: inherit auth_capable on INIT collisions (Daniel Borkmann) [Orabug: 19816069] {CVE-2014-5077}
Affected Software/OS: 'kernel-uek, mlnx_en-2.6.32-400.36.9.el5uek, mlnx_en-2.6.32-400.36.9.el6uek, ofa-2.6.32-400.36.9.el5uek, ofa-2.6.32-400.36.9.el6uek' package(s) on Oracle Linux 5, Oracle Linux 6.
Solution: Please install the updated package(s).
CVSS Score: 7.1
CVSS Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C
|