Oracle Linux 7 : Unbreakable Enterprise kernel (ELSA-2020-5732) (deprecated)

high Nessus Plugin ID 137697

Synopsis

This plugin has been deprecated.

Description

Description of changes:

[4.14.35-1902.303.5.3.el7uek] - rds: Deregister all FRWR mr with free_mr (Hans Westgaard Ry) [Orabug: 31476202]
- Revert 'rds: Do not cancel RDMAs that have been posted to the HCA' (Gerd Rausch) [Orabug: 31475329]
- Revert 'rds: Introduce rds_conn_to_path helper' (Gerd Rausch) [Orabug: 31475329]
- Revert 'rds: Three cancel fixes' (Gerd Rausch) [Orabug: 31475318]

[4.14.35-1902.303.5.2.el7uek] - rds: Three cancel fixes (H&aring kon Bugge) [Orabug: 31463014]

[4.14.35-1902.303.5.1.el7uek] - x86/speculation: Add SRBDS vulnerability and mitigation documentation (Mark Gross) [Orabug: 31446720] {CVE-2020-0543} - x86/speculation: Add Special Register Buffer Data Sampling (SRBDS) mitigation (Mark Gross) [Orabug: 31446720] {CVE-2020-0543} - x86/cpu: Add 'table' argument to cpu_matches() (Mark Gross) [Orabug: 31446720] {CVE-2020-0543}
- x86/cpu: Add a steppings field to struct x86_cpu_id (Mark Gross) [Orabug: 31446720] {CVE-2020-0543}

[4.14.35-1902.303.5.el7uek] - net/mlx5: Decrease default mr cache size (Artemy Kovalyov) [Orabug: 31446379]

As of 2020/06/22 this advisory has been retracted because it apparently does not fix any security problems relevant to already running systems.

See Also

https://oss.oracle.com/pipermail/el-errata/2020-June/010063.html

https://oss.oracle.com/pipermail/el-errata/2020-June/010066.html

Plugin Details

Severity: High

ID: 137697

File Name: oraclelinux_ELSA-2020-5732.nasl

Version: 1.2

Type: local

Agent: unix

Published: 6/22/2020

Updated: 6/23/2020

Supported Sensors: Continuous Assessment, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

Vulnerability Information

CPE: p-cpe:/a:oracle:linux:kernel-uek-debug-devel, p-cpe:/a:oracle:linux:kernel-uek-devel, p-cpe:/a:oracle:linux:kernel-uek-debug, cpe:/o:oracle:linux:7, p-cpe:/a:oracle:linux:kernel-uek-doc, p-cpe:/a:oracle:linux:kernel-uek-tools, p-cpe:/a:oracle:linux:kernel-uek

Required KB Items: Host/local_checks_enabled, Host/OracleLinux, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 6/18/2020

Reference Information

CVE: CVE-2020-0543