<!-- 
RSS generated by JIRA (9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c) at Sat Feb 10 02:23:53 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>Whamcloud Community JIRA</title>
    <link>https://jira.whamcloud.com</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>9.4.14</version>
        <build-number>940014</build-number>
        <build-date>05-12-2023</build-date>
    </build-info>


<item>
            <title>[LU-9174] kernel update [RHEL7.3 3.10.0-514.10.2.el7]</title>
                <link>https://jira.whamcloud.com/browse/LU-9174</link>
                <project id="10000" key="LU">Lustre</project>
                    <description>&lt;p&gt;Security Fix(es):&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Linux kernel built with the Kernel-based Virtual Machine (CONFIG_KVM) support&lt;br/&gt;
is vulnerable to a null pointer dereference flaw. It could occur on x86&lt;br/&gt;
platform, when emulating an undefined instruction. An attacker could use this&lt;br/&gt;
flaw to crash the host kernel resulting in DoS. (CVE-2016-8630, Important)&lt;/li&gt;
&lt;/ul&gt;


&lt;ul&gt;
	&lt;li&gt;A race condition issue leading to a use-after-free flaw was found in the way&lt;br/&gt;
the raw packet sockets implementation in the Linux kernel networking subsystem&lt;br/&gt;
handled synchronization while creating the TPACKET_V3 ring buffer. A local user&lt;br/&gt;
able to open a raw packet socket (requires the CAP_NET_RAW capability) could use&lt;br/&gt;
this flaw to elevate their privileges on the system. (CVE-2016-8655, Important)&lt;/li&gt;
&lt;/ul&gt;


&lt;ul&gt;
	&lt;li&gt;A flaw was discovered in the Linux kernel&apos;s implementation of VFIO. An&lt;br/&gt;
attacker issuing an ioctl can create a situation where memory is corrupted and&lt;br/&gt;
modify memory outside of the expected area. This may overwrite kernel memory and&lt;br/&gt;
subvert kernel execution. (CVE-2016-9083, Important)&lt;/li&gt;
&lt;/ul&gt;


&lt;ul&gt;
	&lt;li&gt;The use of a kzalloc with an integer multiplication allowed an integer&lt;br/&gt;
overflow condition to be reached in vfio_pci_intrs.c. This combined with&lt;br/&gt;
CVE-2016-9083 may allow an attacker to craft an attack and use unallocated&lt;br/&gt;
memory, potentially crashing the machine. (CVE-2016-9084, Moderate)&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;To see the complete list of bug fixes and enhancements, refer to&lt;br/&gt;
the following KnowledgeBase article: &lt;a href=&quot;https://access.redhat.com/articles/2940041&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://access.redhat.com/articles/2940041&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Bugs fixed (&lt;a href=&quot;https://bugzilla.redhat.com/):&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://bugzilla.redhat.com/):&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;1389258 - CVE-2016-9083 kernel: State machine confusion bug in vfio driver leading to memory corruption&lt;br/&gt;
1389259 - CVE-2016-9084 kernel: Integer overflow when using kzalloc in vfio driver&lt;br/&gt;
1393350 - CVE-2016-8630 kernel: kvm: x86: NULL pointer dereference during instruction decode&lt;br/&gt;
1400019 - CVE-2016-8655 kernel: Race condition in packet_set_ring leads to use after free&lt;/p&gt;</description>
                <environment></environment>
        <key id="44255">LU-9174</key>
            <summary>kernel update [RHEL7.3 3.10.0-514.10.2.el7]</summary>
                <type id="1" iconUrl="https://jira.whamcloud.com/secure/viewavatar?size=xsmall&amp;avatarId=11303&amp;avatarType=issuetype">Bug</type>
                                            <priority id="4" iconUrl="https://jira.whamcloud.com/images/icons/priorities/minor.svg">Minor</priority>
                        <status id="5" iconUrl="https://jira.whamcloud.com/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="success"/>
                                    <resolution id="1">Fixed</resolution>
                                        <assignee username="bogl">Bob Glossman</assignee>
                                    <reporter username="bogl">Bob Glossman</reporter>
                        <labels>
                    </labels>
                <created>Thu, 2 Mar 2017 17:51:00 +0000</created>
                <updated>Wed, 12 Apr 2017 14:56:32 +0000</updated>
                            <resolved>Tue, 14 Mar 2017 06:17:06 +0000</resolved>
                                                    <fixVersion>Lustre 2.10.0</fixVersion>
                                        <due></due>
                            <votes>0</votes>
                                    <watches>2</watches>
                                                                            <comments>
                            <comment id="186912" author="gerrit" created="Fri, 3 Mar 2017 16:20:07 +0000"  >&lt;p&gt;Bob Glossman (bob.glossman@intel.com) uploaded a new patch: &lt;a href=&quot;https://review.whamcloud.com/25747&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://review.whamcloud.com/25747&lt;/a&gt;&lt;br/&gt;
Subject: &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-9174&quot; title=&quot;kernel update [RHEL7.3 3.10.0-514.10.2.el7]&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-9174&quot;&gt;&lt;del&gt;LU-9174&lt;/del&gt;&lt;/a&gt; kernel: kernel update RHEL7.3 &lt;span class=&quot;error&quot;&gt;&amp;#91;3.10.0-514.10.2.el7&amp;#93;&lt;/span&gt;&lt;br/&gt;
Project: fs/lustre-release&lt;br/&gt;
Branch: master&lt;br/&gt;
Current Patch Set: 1&lt;br/&gt;
Commit: 7520fc56aba86e183ff8e107b7f9155773d2503e&lt;/p&gt;</comment>
                            <comment id="188199" author="gerrit" created="Tue, 14 Mar 2017 02:59:59 +0000"  >&lt;p&gt;Oleg Drokin (oleg.drokin@intel.com) merged in patch &lt;a href=&quot;https://review.whamcloud.com/25747/&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://review.whamcloud.com/25747/&lt;/a&gt;&lt;br/&gt;
Subject: &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-9174&quot; title=&quot;kernel update [RHEL7.3 3.10.0-514.10.2.el7]&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-9174&quot;&gt;&lt;del&gt;LU-9174&lt;/del&gt;&lt;/a&gt; kernel: kernel update RHEL7.3 &lt;span class=&quot;error&quot;&gt;&amp;#91;3.10.0-514.10.2.el7&amp;#93;&lt;/span&gt;&lt;br/&gt;
Project: fs/lustre-release&lt;br/&gt;
Branch: master&lt;br/&gt;
Current Patch Set: &lt;br/&gt;
Commit: f8ac16100986b32cbae7b13baf69a30ac598ae7e&lt;/p&gt;</comment>
                            <comment id="188215" author="pjones" created="Tue, 14 Mar 2017 06:17:06 +0000"  >&lt;p&gt;Landed for 2.10&lt;/p&gt;</comment>
                    </comments>
                <issuelinks>
                            <issuelinktype id="10011">
                    <name>Related</name>
                                            <outwardlinks description="is related to ">
                                        <issuelink>
            <issuekey id="44032">LU-9143</issuekey>
        </issuelink>
                            </outwardlinks>
                                                                <inwardlinks description="is related to">
                                        <issuelink>
            <issuekey id="45437">LU-9323</issuekey>
        </issuelink>
                            </inwardlinks>
                                    </issuelinktype>
                    </issuelinks>
                <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                                                                                                                                            <customfield id="customfield_10890" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10390" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|hzz5nr:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10090" key="com.pyxis.greenhopper.jira:gh-global-rank">
                        <customfieldname>Rank (Obsolete)</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>9223372036854775807</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                            <customfield id="customfield_10060" key="com.atlassian.jira.plugin.system.customfieldtypes:select">
                        <customfieldname>Severity</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10022"><![CDATA[3]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        </customfields>
    </item>
</channel>
</rss>