OracleVM 2.1 : kernel (OVMSA-2008-2005)

High Nessus Plugin ID 79447


The remote OracleVM host is missing one or more security updates.


The remote OracleVM system is missing necessary patches to address critical security updates :

- fix utrace dead_engine ops race

- fix ptrace_attach leak

- CVE-2007-5093: kernel PWC driver DoS

- CVE-2007-6282: IPSec ESP kernel panics

- CVE-2007-6712: kernel: infinite loop in highres timers (kernel hang)

- CVE-2008-1615: kernel: ptrace: Unprivileged crash on x86_64 %cs corruption

- CVE-2008-1294: kernel: setrlimit(RLIMIT_CPUINFO) with zero value doesn't inherit properly across children

- CVE-2008-2136: kernel: sit memory leak

- CVE-2008-2812: kernel: NULL ptr dereference in multiple network drivers due to missing checks in tty code

- restore linux-2.6-x86-clear-df-flag-for-signal-handlers.patch

- restore linux-2.6-utrace.patch / linux-2.6-xen-utrace.patch

- Kernel security erratas for OVM 2.1.2 from bz#5932 :

- CVE-2007-6063: isdn: fix possible isdn_net buffer overflows

- CVE-2007-3104 Null pointer to an inode in a dentry can cause an oops in sysfs_readdir

- CVE-2008-0598: write system call vulnerability

- CVE-2008-1375: kernel: race condition in dnotify

- CVE-2008-0001: kernel: filesystem corruption by unprivileged user via directory truncation

- CVE-2008-2358: dccp: sanity check feature length

- CVE-2007-5938: NULL dereference in iwl driver

- RHSA-2008:0508: kernel: [x86_64] The string instruction version didn't zero the output on exception.

- kernel: clear df flag for signal handlers

- fs: missing dput in do_lookup error leaks dentries

- sysfs: fix condition check in sysfs_drop_dentry

- sysfs: fix race condition around sd->s_dentry

- ieee80211: off-by-two integer underflow


Update the affected packages.

See Also

Plugin Details

Severity: High

ID: 79447

File Name: oraclevm_OVMSA-2008-2005.nasl

Version: $Revision: 1.6 $

Type: local

Published: 2014/11/26

Modified: 2017/02/14

Dependencies: 12634

Risk Information

Risk Factor: High


Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:oracle:vm:kernel-BOOT, p-cpe:/a:oracle:vm:kernel-BOOT-devel, p-cpe:/a:oracle:vm:kernel-kdump, p-cpe:/a:oracle:vm:kernel-kdump-devel, p-cpe:/a:oracle:vm:kernel-ovs, p-cpe:/a:oracle:vm:kernel-ovs-devel, cpe:/o:oracle:vm_server:2.1

Required KB Items: Host/local_checks_enabled, Host/OracleVM/release, Host/OracleVM/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2008/09/24

Reference Information

CVE: CVE-2007-3104, CVE-2007-5093, CVE-2007-5938, CVE-2007-6063, CVE-2007-6282, CVE-2007-6712, CVE-2008-0001, CVE-2008-0598, CVE-2008-1294, CVE-2008-1375, CVE-2008-1615, CVE-2008-2136, CVE-2008-2358, CVE-2008-2812

BID: 24631, 26605, 27280, 29003, 29081, 29086, 29235, 29603, 29942, 30076

CWE: 16, 20, 119, 189, 200, 362, 399