Issue date: 2016-03-28
1. What's Included in This Update
The new packages for Virtuozzo (formerly Parallels Cloud Server) 6.0 provide usability, stability, and security fixes.
2. Bug Fixes
- IPv6 link-local address was being assigned to slave interfaces in bonding which resulted in DAD and network routing issues. (PSBM-42433)
- The way pcompact defragmented small files could result in all free space on host being consumed. (PSBM-42954)
- kswap activity needed to be restricted in case of high-order requests (PSBM-44291)
- It was impossible to subscribe to events from Python SDK due to missing functions. (PSBM-44826)
- In certain circumstances, Virtuozzo Storage host could hang under high I/O load. (PSBM-44857)
- Missing bounds check in ipt_entry structure in netfilter. (PSBM-45193, CVE-2016-3134)
- IPv6 connect could cause DoS via NULL pointer dereference (PSBM-45219, CVE-2015-8543)
- Pipe buffer state corruption after unsuccessful atomic read from pipe (PSBM-45328, CVE-2016-0774)
- pstorage-mount could crash after updating to version 6.0.11-14, if MDS packages were not updated first. (PSBM-45407)
- hostapd was broken in early RHEL6.7 kernels. (OVZ-6649)
3. Obtaining the Update
You can download and install the update using the yum utility included in the Virtuozzo (formerly Parallels Cloud Server) 6.0 distribution.
https://access.redhat.com/security/cve/CVE-2015-8543 https://access.redhat.com/security/cve/CVE-2016-0774 https://access.redhat.com/security/cve/CVE-2016-3134
Copyright (c) 1999-2016 Parallels IP Holdings GmbH and its affiliates. All rights reserved.