OracleVM 3.4 : Unbreakable / etc (OVMSA-2019-0047)
Low Nessus Plugin ID 129986
Synopsis
The remote OracleVM host is missing one or more security updates.
Description
The remote OracleVM system is missing necessary patches to address critical security updates :
- scsi: sg: fixup infoleak when using SG_GET_REQUEST_TABLE (Hannes Reinecke) [Orabug: 26941755] (CVE-2017-14991)
- failover: allow name change on IFF_UP slave interfaces (Si-Wei Liu)
- Revert 'net_failover: delay taking over primary device to accommodate udevd renaming' (Si-Wei Liu) [Orabug:
29707258]
- build: Revert 'repairing out-of-tree build functionality' (Todd Vierling) [Orabug: 30257829]
- rds: add ibmr to busy_list in flush code path (Manjunath Patil)
- rds: fix uninteneded increase of rds_rdma:pool->max_items_soft (Manjunath Patil)
- ext4: fix data exposure after a crash (Jan Kara) [Orabug: 30361860] (CVE-2017-7495)
Solution
Update the affected kernel-uek / kernel-uek-firmware packages.