Oracle Linux 5 : kernel (ELSA-2010-0723)

high Nessus Plugin ID 68106

Synopsis

The remote Oracle Linux host is missing one or more security updates.

Description

The remote Oracle Linux 5 host has packages installed that are affected by multiple vulnerabilities as referenced in the ELSA-2010-0723 advisory.

- [misc] make compat_alloc_user_space() incorporate the access_ok() (Don Howard) [634463 634464] {CVE-2010-3081}
- [fs] xfs: fix missing untrusted inode lookup tag (Dave Chinner) [624366 607032] {CVE-2010-2943}
- [net] sched: fix some kernel memory leaks (Jiri Pirko) [624904 624638] {CVE-2010-2942}
- [usb] fix usbfs information leak (Eugene Teo) [566628 566629] {CVE-2010-1083}
- [fs] xfs: rename XFS_IGET_BULKSTAT to XFS_IGET_UNTRUSTED (Dave Chinner) [624366 607032] {CVE-2010-2943}
- [fs] xfs: validate untrusted inode numbers during lookup (Dave Chinner) [624366 607032] {CVE-2010-2943}
- [fs] xfs: always use iget in bulkstat (Dave Chinner) [624366 607032] {CVE-2010-2943}
- [xen] fix guest crash on non-EPT machine may crash host (Paolo Bonzini) [621429 621430] {CVE-2010-2938}
- [fs] ext4: consolidate in_range definitions (Eric Sandeen) [624331 624332] {CVE-2010-3015}
- [mm] accept an abutting stack segment (Jiri Pirko) [607857 607858] {CVE-2010-2240}
- [mm] pass correct mm when growing stack (Jiri Pirko) [607857 607858] {CVE-2010-2240}
- [mm] fix up some user-visible effects of stack guard page (Jiri Pirko) [607857 607858] {CVE-2010-2240}
- [mm] fix page table unmap for stack guard page properly (Jiri Pirko) [607857 607858] {CVE-2010-2240}
- [mm] fix missing unmap for stack guard page failure case (Jiri Pirko) [607857 607858] {CVE-2010-2240}

Tenable has extracted the preceding description block directly from the Oracle Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://linux.oracle.com/errata/ELSA-2010-0723.html

Plugin Details

Severity: High

ID: 68106

File Name: oraclelinux_ELSA-2010-0723.nasl

Version: 1.18

Type: local

Agent: unix

Published: 7/12/2013

Updated: 11/1/2024

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.0

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2010-2798

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.3

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2010-2943

Vulnerability Information

CPE: p-cpe:/a:oracle:linux:oracleasm-2.6.18-194.17.1.0.1.el5debug, p-cpe:/a:oracle:linux:ocfs2-2.6.18-194.17.1.0.1.el5xen, p-cpe:/a:oracle:linux:kernel-xen, cpe:/o:oracle:linux:5, p-cpe:/a:oracle:linux:kernel-devel, p-cpe:/a:oracle:linux:ocfs2-2.6.18-194.17.1.0.1.el5debug, p-cpe:/a:oracle:linux:oracleasm-2.6.18-194.17.1.0.1.el5, p-cpe:/a:oracle:linux:kernel-pae-devel, p-cpe:/a:oracle:linux:oracleasm-2.6.18-194.17.1.0.1.el5pae, p-cpe:/a:oracle:linux:kernel-xen-devel, p-cpe:/a:oracle:linux:kernel-pae, p-cpe:/a:oracle:linux:ocfs2-2.6.18-194.17.1.0.1.el5pae, p-cpe:/a:oracle:linux:oracleasm-2.6.18-194.17.1.0.1.el5xen, p-cpe:/a:oracle:linux:kernel-debug-devel, p-cpe:/a:oracle:linux:kernel-debug, p-cpe:/a:oracle:linux:kernel-headers, p-cpe:/a:oracle:linux:kernel, p-cpe:/a:oracle:linux:ocfs2-2.6.18-194.17.1.0.1.el5

Required KB Items: Host/local_checks_enabled, Host/OracleLinux, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/30/2010

Vulnerability Publication Date: 4/6/2010

Reference Information

CVE: CVE-2010-1083, CVE-2010-2492, CVE-2010-2798, CVE-2010-2938, CVE-2010-2942, CVE-2010-2943, CVE-2010-3015

BID: 39042, 42124, 42237, 42477, 42527, 42529

RHSA: 2010:0723