Description: | Summary: The remote host is missing an update for the 'kernel-uek, mlnx_en-2.6.32-300.29.2.el5uek, mlnx_en-2.6.32-300.29.2.el6uek, ofa-2.6.32-300.29.2.el5uek, ofa-2.6.32-300.29.2.el6uek' package(s) announced via the ELSA-2012-2026 advisory.
Vulnerability Insight: [2.6.32-300.29.2] - epoll: epoll_wait() should not use timespec_add_ns() (Eric Dumazet) - epoll: clear the tfile_check_list on -ELOOP (Joe Jin) {CVE-2012-3375} - Don't limit non-nested epoll paths (Jason Baron) - epoll: kabi fixups for epoll limit wakeup paths (Joe Jin) {CVE-2011-1083} - epoll: limit paths (Jason Baron) {CVE-2011-1083} - eventpoll: fix comment typo 'evenpoll' (Paul Bolle) - epoll: fix compiler warning and optimize the non-blocking path (Shawn Bohrer) - epoll: move ready event check into proper inline (Davide Libenzi) - epoll: make epoll_wait() use the hrtimer range feature (Shawn Bohrer) - select: rename estimate_accuracy() to select_estimate_accuracy() (Andrew Morton) - cred: copy_process() should clear child->replacement_session_keyring (Oleg Nesterov) {CVE-2012-2745}
Affected Software/OS: 'kernel-uek, mlnx_en-2.6.32-300.29.2.el5uek, mlnx_en-2.6.32-300.29.2.el6uek, ofa-2.6.32-300.29.2.el5uek, ofa-2.6.32-300.29.2.el6uek' package(s) on Oracle Linux 5, Oracle Linux 6.
Solution: Please install the updated package(s).
CVSS Score: 4.9
CVSS Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C
|