Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Fedora 23: Security Advisory for Kernel Update on DoS Threats

fedora
Calendar Grey November 19, 2015
Scroller Fedora
Fedora 23 has released a kernel update that remedies severe DoS vulnerabilities, significantly bolstering the overall security with vital patches.
The 4.2.6 stable update contains a number of important fixes across the tree

Summary

The kernel meta package

Update Information:

The 4.2.6 stable update contains a number of important fixes across the tree. kernel-4.2.6-300.fc23 - Fix incorrect size calculations in megaraid with 64K pages (rhbz 1269300) - CVE-2015-8104 kvm: DoS infinite loop in microcode DB exception (rhbz 1278496 1279691) - CVE-2015-5307 kvm: DoS infinite loop in microcode AC exception (rhbz 1277172 1279688)

Change Log

References


[ 1 ] Bug #1278496 - CVE-2015-8104 virt: guest to host DoS by triggering an infinite loop in microcode via #DB exception https://bugzilla.redhat.com/show_bug.cgi?id=1278496 [ 2 ] Bug #1277172 - CVE-2015-5307 virt: guest to host DoS by triggering an infinite loop in microcode via #AC exception https://bugzilla.redhat.com/show_bug.cgi?id=1277172 [ 3 ] Bug #1271134 - CVE-2015-7799 kernel: net: slip: crash when using PPP character device driver https://bugzilla.redhat.com/show_bug.cgi?id=1271134 [ 4 ] Bug #1276437 - CVE-2015-7990 kernel: Race condition when sending message on unbound socket causing NULL pointer dereference https://bugzilla.redhat.com/show_bug.cgi?id=1276437

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update kernel' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: kernel
Product: Fedora 23
Version: 4.2.6
Release: 300.fc23
Summary: The Linux kernel

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.