You are here
Home > Preporuke > Ranjivosti jezgre operacijskog sustava

Ranjivosti jezgre operacijskog sustava

  • Detalji os-a: FED
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2015-115c302856
2015-11-19 08:18:45.207983
——————————————————————————–

Name : kernel
Product : Fedora 23
Version : 4.2.6
Release : 300.fc23
URL : http://www.kernel.org/
Summary : The Linux kernel
Description :
The kernel meta package

——————————————————————————–
Update Information:

The 4.2.6 stable update contains a number of important fixes across the tree.
kernel-4.2.6-300.fc23 – Fix incorrect size calculations in megaraid with 64K
pages (rhbz 1269300) – CVE-2015-8104 kvm: DoS infinite loop in microcode DB
exception (rhbz 1278496 1279691) – CVE-2015-5307 kvm: DoS infinite loop in
microcode AC exception (rhbz 1277172 1279688)
——————————————————————————–
References:

[ 1 ] Bug #1278496 – CVE-2015-8104 virt: guest to host DoS by triggering an infinite loop in microcode via #DB exception
https://bugzilla.redhat.com/show_bug.cgi?id=1278496
[ 2 ] Bug #1277172 – CVE-2015-5307 virt: guest to host DoS by triggering an infinite loop in microcode via #AC exception
https://bugzilla.redhat.com/show_bug.cgi?id=1277172
[ 3 ] Bug #1271134 – CVE-2015-7799 kernel: net: slip: crash when using PPP character device driver
https://bugzilla.redhat.com/show_bug.cgi?id=1271134
[ 4 ] Bug #1276437 – CVE-2015-7990 kernel: Race condition when sending message on unbound socket causing NULL pointer dereference
https://bugzilla.redhat.com/show_bug.cgi?id=1276437
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update kernel’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2015-cd94ad8d7c
2015-11-19 07:46:18.494499
——————————————————————————–

Name : kernel
Product : Fedora 22
Version : 4.2.6
Release : 200.fc22
URL : http://www.kernel.org/
Summary : The Linux kernel
Description :
The kernel meta package

——————————————————————————–
Update Information:

The 4.2.6 stable update contains a number of important fixes across the tree.
kernel-4.2.6-200.fc22 – Fix incorrect size calculations in megaraid with 64K
pages (rhbz 1269300) – CVE-2015-8104 kvm: DoS infinite loop in microcode DB
exception (rhbz 1278496 1279691) – CVE-2015-5307 kvm: DoS infinite loop in
microcode AC exception (rhbz 1277172 1279688)
——————————————————————————–
References:

[ 1 ] Bug #1278496 – CVE-2015-8104 virt: guest to host DoS by triggering an infinite loop in microcode via #DB exception
https://bugzilla.redhat.com/show_bug.cgi?id=1278496
[ 2 ] Bug #1277172 – CVE-2015-5307 virt: guest to host DoS by triggering an infinite loop in microcode via #AC exception
https://bugzilla.redhat.com/show_bug.cgi?id=1277172
[ 3 ] Bug #1271134 – CVE-2015-7799 kernel: net: slip: crash when using PPP character device driver
https://bugzilla.redhat.com/show_bug.cgi?id=1271134
[ 4 ] Bug #1276437 – CVE-2015-7990 kernel: Race condition when sending message on unbound socket causing NULL pointer dereference
https://bugzilla.redhat.com/show_bug.cgi?id=1276437
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update kernel’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

 

 

 

——————————————————————————–
Fedora Update Notification
FEDORA-2015-f2c534bc12
2015-11-20 19:00:55.798190
——————————————————————————–

Name        : kernel
Product     : Fedora 21
Version     : 4.1.13
Release     : 100.fc21
URL         : http://www.kernel.org/
Summary     : The Linux kernel
Description :
The kernel meta package

——————————————————————————–
Update Information:

  kernel-4.1.13-100.fc21  – Linux v4.1.13 – CVE-2015-8104 kvm: DoS infinite loop
in microcode DB exception (rhbz 1278496 1279691) – CVE-2015-5307 kvm: DoS
infinite loop in microcode AC exception (rhbz 1277172 1279688)
——————————————————————————–
References:

  [ 1 ] Bug #1276437 – CVE-2015-7990 kernel: Race condition when sending message on unbound socket causing NULL pointer dereference
        https://bugzilla.redhat.com/show_bug.cgi?id=1276437
  [ 2 ] Bug #1271134 – CVE-2015-7799 kernel: net: slip: crash when using PPP character device driver
        https://bugzilla.redhat.com/show_bug.cgi?id=1271134
  [ 3 ] Bug #1277172 – CVE-2015-5307 virt: guest to host DoS by triggering an infinite loop in microcode via #AC exception
        https://bugzilla.redhat.com/show_bug.cgi?id=1277172
  [ 4 ] Bug #1278496 – CVE-2015-8104 virt: guest to host DoS by triggering an infinite loop in microcode via #DB exception
        https://bugzilla.redhat.com/show_bug.cgi?id=1278496
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update kernel’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

 

AutorTomislav Protega
Cert idNCERT-REF-2015-11-0019-ADV
CveCVE-2015-8104 CVE-2015-5307 CVE-2015-7799 CVE-2015-7990
ID izvornikaFEDORA-2015-115
Proizvodkernel
Izvorhttp://www.redhat.com
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa ntp

Otkriveni su sigurnosni nedostaci u programskom paketu ntp Red Hat Enterprise Linux 7. Otkriveni nedostaci potencijalnim napadačima omogućuju rušenje servisa,...

Close