news 28 Posted August 17, 2017 Oracle Linux Security Advisory ELSA-2017-3605 http://linux.oracle.com/errata/ELSA-2017-3605.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: kernel-uek-doc-4.1.12-94.5.9.el7uek.noarch.rpm kernel-uek-firmware-4.1.12-94.5.9.el7uek.noarch.rpm kernel-uek-4.1.12-94.5.9.el7uek.x86_64.rpm kernel-uek-devel-4.1.12-94.5.9.el7uek.x86_64.rpm kernel-uek-debug-4.1.12-94.5.9.el7uek.x86_64.rpm kernel-uek-debug-devel-4.1.12-94.5.9.el7uek.x86_64.rpm dtrace-modules-4.1.12-94.5.9.el7uek-0.6.0-4.el7.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates/kernel-uek-4.1.12-94.5.9.el7uek.src.rpm http://oss.oracle.com/ol7/SRPMS-updates/dtrace-modules-4.1.12-94.5.9.el7uek-0.6.0-4.el7.src.rpm Description of changes: kernel-uek [4.1.12-94.5.9.el7uek] - dentry name snapshots (Al Viro) [Orabug: 26630936] {CVE-2017-7533} [4.1.12-94.5.8.el7uek] - scsi: libiscsi: use kvzalloc for iscsi_pool_init (Kyle Fortin) [Orabug: 26621191] - mm: introduce kv[mz]alloc helpers (Kyle Fortin) [Orabug: 26621191] - KEYS: Disallow keyrings beginning with '.' to be joined as session keyrings (David Howells) [Orabug: 26621179] {CVE-2016-9604} {CVE-2016-9604} - l2tp: fix racy SOCK_ZAPPED flag check in l2tp_ip{,6}_bind() (Guillaume Nault) [Orabug: 26621176] {CVE-2016-10200} - mnt: Add a per mount namespace limit on the number of mounts (Eric W. Biederman) [Orabug: 26621171] {CVE-2016-6213} {CVE-2016-6213} - ipv6: fix out of bound writes in __ip6_append_data() (Eric Dumazet) [Orabug: 26621163] {CVE-2017-9242} _______________________________________________ Share this post Link to post