kernel-3.10.0-327.22.2.el7

エラータID: AXSA:2016-613:04

Release date: 
Tuesday, August 9, 2016 - 00:28
Subject: 
kernel-3.10.0-327.22.2.el7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

Security issues fixed with this release:

CVE-2015-8767
net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not
properly manage the relationship between a lock and a socket, which
allows local users to cause a denial of service (deadlock) via a
crafted sctp_accept call.
CVE-2016-4565
The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3
incorrectly relies on the write system call, which allows local users
to cause a denial of service (kernel memory write operation) or
possibly have unspecified other impact via a uAPI interface.

Security Fixes:
Fixed bugs:

* When Small Computer System Interface (SCSI) devices were removed or deleted, a system crash could occur due to a race condition between listing all SCSI devices and SCSI device removal. The provided patch ensures that the starting node for the klist_iter_init_node() function is actually a member of the list before using it. As a result, a system crash no longer occurs in the described scenario.
* This update offers a reworked series of patches for the resizable hash table (rhashtable) including a number of backported bug fixes and enhancements from upstream.
* Previously, the same value of the mperf Model-Specific Register (MSR) read twice in a row could lead to a kernel panic due to the divide-by-zero error. The provided patch fixes this bug, and the kernel now handles two identical values of mperf gracefully.
* When a transparent proxy application was running and the number of established connections on the computer exceeded one million, unrelated processes, such as curl or ssh, were unable to bind to a local IP on the box to initiate a connection. The provided patch fixes the cooperation of the REUSEADDR/NOREUSEADDR socket option, and thus prevents the local port from being exhausted. As a result, the aforementioned bug no longer occurs in the described scenario.
* Previously, the kernel support for non-local bind for the IPv6 protocol was incomplete. As a consequence, an attempt to bind a socket to an IPv6 address that is not assigned to the host could fail. The provided patch includes changes in the ip_nonlocal_bind variable, which is now set to allow binding to an IPv6 address that is not assigned to the host. As a result, Linux servers are now able to bind to non-local IPv6 addresses as expected.
* On some servers with a faster CPU, USB initialization could previously lead to a kernel hang during boot. If this inconvenience occurred when booting the second kernel during the kdump operation, the kdump service failed and the vmcore was lost. The provided upstream patch fixes this bug, and the kernel no longer hangs after USB initialization.
* Previously, when running iperf servers using the mlx4_en module, a kernel panic occurred. The underlying source code has been fixed, and the kernel panic no longer occurs in the described scenario.
These updated kernel packages include several security issues and numerous bug fixes, some of which you can see below.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. kernel-3.10.0-327.22.2.el7.src.rpm
    MD5: 0d95da689ab938924fbc7c3b8dd6d044
    SHA-256: 391fe3e2ab5373a14cf8e71cd4106b1b3508617db98d79683a98b1cadddc5f19
    Size: 79.20 MB

Asianux Server 7 for x86_64
  1. kernel-3.10.0-327.22.2.el7.x86_64.rpm
    MD5: 41f1e6ad3075dbbd0471646f2b0fd799
    SHA-256: 6fc21437a696a992267192b194c2a4a10a954689132756e905e99b180158cddf
    Size: 33.05 MB
  2. kernel-abi-whitelists-3.10.0-327.22.2.el7.noarch.rpm
    MD5: 6efc6944e16b05b8d8fe579348d8d908
    SHA-256: af6a96bb418a84f91761eebe4b5644b1667181ac0ece3ebf7c900ff4a28a3a8c
    Size: 2.33 MB
  3. kernel-debug-3.10.0-327.22.2.el7.x86_64.rpm
    MD5: bf289da08ae60f2890197b0fa8590eb2
    SHA-256: 5b40f1a399ce9c37c0a5905731376e3f226e39eeab2f1a305f2a3431aa17339b
    Size: 34.67 MB
  4. kernel-debug-devel-3.10.0-327.22.2.el7.x86_64.rpm
    MD5: 86fc3cb61ec745df00163308b366acd8
    SHA-256: b66a27edc18d51b9175458ae18e60e47e258c8997cee7113e739920e42ba6436
    Size: 11.04 MB
  5. kernel-devel-3.10.0-327.22.2.el7.x86_64.rpm
    MD5: a3cdedc1dd0c30f37f46548fb8e9ec8a
    SHA-256: 9436f91cfb57fa14e13c0d1e7836ee518473b5e6781d689491e69afdeb6c772d
    Size: 10.98 MB
  6. kernel-doc-3.10.0-327.22.2.el7.noarch.rpm
    MD5: 6548c00d09aa9ca1f3db3c85b119e3f2
    SHA-256: 83206ad23194a6a884388dd237acff3f1bea3698de5434d56408a3e1c7d12323
    Size: 13.44 MB
  7. kernel-headers-3.10.0-327.22.2.el7.x86_64.rpm
    MD5: 9e5526a28d3605c100d65df1a5fbd125
    SHA-256: 871f2377ce1a5d89fdb89fb126beca7b2172efb98f52ff5d74470929a8aaccb2
    Size: 3.19 MB
  8. kernel-tools-3.10.0-327.22.2.el7.x86_64.rpm
    MD5: 8047cf4cb41fecc1d03c1f119cd030b2
    SHA-256: 0f9de30f0a3d75c4bca01e5966317495bd3ffd898b011cf6a2d3a3fce651df7d
    Size: 2.40 MB
  9. kernel-tools-libs-3.10.0-327.22.2.el7.x86_64.rpm
    MD5: 31940d6e458649af763af87602e25dac
    SHA-256: 569defdc24235063f029f03b91d9322dbc773e9e927c23141942ff7189c81925
    Size: 2.33 MB
  10. perf-3.10.0-327.22.2.el7.x86_64.rpm
    MD5: 90ca3085d254cd08b0d55cfcd7d73c50
    SHA-256: 08cc6ba0fb8b1cdbfa223e2e71e9df98f8dd8ae1c477e73b35afbe64e69034b8
    Size: 3.32 MB
  11. python-perf-3.10.0-327.22.2.el7.x86_64.rpm
    MD5: 2c20978cf1b4f3e7b57b8fcf66e18273
    SHA-256: 289a69108211e995ce9f23df8c2b33a9bd32019e5eff512f7ef2431156b0a495
    Size: 2.40 MB