{"id":"MGASA-2015-0450","summary":"Updated kernel packages fix security vulnerabilities","details":"This kernel update is based on upstream 4.1.13 longterm kernel and fixes\nthe following security issues:\n\nThe virtnet_probe function in drivers/net/virtio_net.c in the Linux kernel\nbefore 4.2 attempts to support a FRAGLIST feature without proper memory\nallocation, which allows guest OS users to cause a denial of service (buffer\noverflow and memory corruption) via a crafted sequence of fragmented packets.\n(CVE-2015-5156)\n\nA guest to host DoS issue was found affecting various hypervisors. In that,\na guest can DoS the host by triggering an infinite stream of \"alignment\ncheck\" (#AC) exceptions. This causes the microcode to enter an infinite loop\nwhere the core never receives another interrupt. The host kernel panics due\nto this effect (CVE-2015-5307).\n\nA guest to host DoS issue was found affecting various hypervisors. In that,\na guest can DoS the host by triggering an infinite stream of \"debug check\"\n(#DB) exceptions. This causes the microcode to enter an infinite loop where\nthe core never receives another interrupt. The host kernel panics due to\nthis effect (CVE-2015-8104).\n\nFor other fixes in this update, see the referenced changelog.\n","modified":"2026-02-01T01:03:30.685242Z","published":"2015-11-19T22:08:19Z","related":["CVE-2015-5156","CVE-2015-5307","CVE-2015-8104"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2015-0450.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=17129"},{"type":"REPORT","url":"https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.1.13"}],"affected":[{"package":{"name":"kernel","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/kernel?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.13-2.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0450.json"}},{"package":{"name":"kernel-userspace-headers","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/kernel-userspace-headers?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.13-2.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0450.json"}},{"package":{"name":"kmod-xtables-addons","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/kmod-xtables-addons?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.7-6.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0450.json"}},{"package":{"name":"kmod-broadcom-wl","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/kmod-broadcom-wl?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.30.223.271-3.mga5.nonfree"}]}],"ecosystem_specific":{"section":"nonfree"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0450.json"}},{"package":{"name":"kmod-fglrx","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/kmod-fglrx?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"15.200.1046-7.mga5.nonfree"}]}],"ecosystem_specific":{"section":"nonfree"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0450.json"}},{"package":{"name":"kmod-nvidia304","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/kmod-nvidia304?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"304.128-3.mga5.nonfree"}]}],"ecosystem_specific":{"section":"nonfree"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0450.json"}},{"package":{"name":"kmod-nvidia340","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/kmod-nvidia340?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"340.93-3.mga5.nonfree"}]}],"ecosystem_specific":{"section":"nonfree"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0450.json"}},{"package":{"name":"kmod-nvidia-current","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/kmod-nvidia-current?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"346.96-3.mga5.nonfree"}]}],"ecosystem_specific":{"section":"nonfree"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0450.json"}}],"schema_version":"1.7.3","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}