Welcome, Guest Login

Support Center

Kernel security update: CVE-2017-15274; new kernel 2.6.32-042stab125.5, Virtuozzo 6.0 Update 12 Hotfix 17 (6.0.12-3687)

Last Updated: Oct 23, 2017 10:22AM UTC

Issue date: 2017-10-23

Affected products: Virtuozzo 6.0

Virtuozzo Advisory ID: VZA-2017-096

1. Overview

This update provides a new Virtuozzo 6.0 kernel 2.6.32-042stab125.5 based on the Red Hat Enterprise Linux 6.9 kernel 2.6.32-696.10.2.el6. The new kernel introduces security and stability fixes.

2. Security Fixes

  • [Moderate] A flaw was found in the implementation of associative arrays where the add_key systemcall and KEYCTL_UPDATE operations allowed for a NULL payload with a nonzero length. When accessing the payload within this length parameters value, an unprivileged user could trivially cause a NULL pointer dereference (kernel oops). (CVE-2017-15274)

3. Bug Fixes

  • Improved the hash function for IPv6 neighbours to increase system responsiveness under IPv6 flooding attacks. (PSBM-73496)
  • Stopping NFS server inside a container could cause the host to crash. (PSBM-74832)

4. Installing the Update

Install the update by running 'yum update'.

5. References

The JSON file with the list of new and updated packages is available at http://docs.virtuozzo.com/vza/VZA-2017-096.json.

Open a new case

  • You can call our Support Team:

     +1 855-466-6670  Toll-free
     +1 425-689-7142  US
     +44 203-389-8331  UK
     +49 8914-379-4365  DE
     +7 499-609-2754  RU
seconds ago
a minute ago
minutes ago
an hour ago
hours ago
a day ago
days ago
Invalid characters found