OracleVM 3.4 : Unbreakable / etc (OVMSA-2018-0037)

high Nessus Plugin ID 109426


The remote OracleVM host is missing one or more security updates.


The remote OracleVM system is missing necessary patches to address critical security updates :

- scsi: iscsi_tcp: set BDI_CAP_STABLE_WRITES when data digest enabled (Jianchao Wang) [Orabug: 27726302]

- block: fix bio_will_gap for first bvec with offset (Ming Lei)

- block: relax check on sg gap (Ming Lei) [Orabug:

- block: don't optimize for non-cloned bio in bio_get_last_bvec (Ming Lei) [Orabug: 27775588]

- block: merge: get the 1st and last bvec via helpers (Ming Lei)

- block: get the 1st and last bvec via helpers (Ming Lei) [Orabug: 27775588]

- block: check virt boundary in bio_will_gap (Ming Lei) [Orabug: 27775588]

- block: bio: introduce helpers to get the 1st and last bvec (Ming Lei)

- Failing to send a CLOSE if file is opened WRONLY and server reboots on a 4.x mount (Olga Kornievskaia) [Orabug: 27848303]

- ext4: add validity checks for bitmap block numbers (Theodore Ts'o) [Orabug: 27854373] (CVE-2018-1093) (CVE-2018-1093)

- ocfs2: Take inode cluster lock before moving reflinked inode from orphan dir (Ashish Samant) [Orabug: 27869411]

- Input: gtco - fix potential out-of-bound access (Dmitry Torokhov) [Orabug: 27869844] (CVE-2017-16643)

- Input: ims-psu - check if CDC union descriptor is sane (Dmitry Torokhov) [Orabug: 27870333] (CVE-2017-16645)

- vfio/pci: Virtualize Maximum Payload Size (Alex Williamson)

- vfio-pci: Virtualize PCIe & AF FLR (Alex Williamson)

- uek-rpm: Disable DMA CMA (Jianchao Wang) [Orabug:

- nvme-pci: fix multiple ctrl removal scheduling (Rakesh Pandit)

- nvme-pci: Fix nvme queue cleanup if IRQ setup fails (Jianchao Wang)

- nvme/pci: Fix stuck nvme reset (Keith Busch) [Orabug:

- nvme: don't schedule multiple resets (Keith Busch) [Orabug: 27892359]

- blk-mq: fix use-after-free in blk_mq_free_tag_set (Junichi Nomura)

- USB: core: prevent malicious bNumInterfaces overflow (Alan Stern)

- driver core: platform: fix race condition with driver_override (Adrian Salido) [Orabug: 27897874] (CVE-2017-12146)

- usb/core: usb_alloc_dev: fix setting of ->portnum (Nicolai Stange)


Update the affected kernel-uek / kernel-uek-firmware packages.

See Also

Plugin Details

Severity: High

ID: 109426

File Name: oraclevm_OVMSA-2018-0037.nasl

Version: 1.3

Type: local

Published: 4/30/2018

Updated: 9/27/2019

Supported Sensors: Nessus

Risk Information


Risk Factor: Medium

Score: 5.9


Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C


Risk Factor: High

Base Score: 7

Temporal Score: 6.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:oracle:vm:kernel-uek, p-cpe:/a:oracle:vm:kernel-uek-firmware, cpe:/o:oracle:vm_server:3.4

Required KB Items: Host/local_checks_enabled, Host/OracleVM/release, Host/OracleVM/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 4/27/2018

Vulnerability Publication Date: 9/8/2017

Reference Information

CVE: CVE-2017-12146, CVE-2017-16643, CVE-2017-16645, CVE-2018-1093