CVE-2017-5715 fix update for the listed kernels

40 views
Skip to first unread message

Irina Semenova

unread,
Jul 18, 2018, 9:00:51 AM7/18/18
to kernelcar...@googlegroups.com
We've released security updates for the following kernels:
- CloudLinux6 Hybrid
- CloudLinux 7
- Proxmox VE 3.10
- RHEL7
-CentOS7
CentoOS7 - plus

Systems with AUTO_UPDATE=True (DEFAULT) in /etc/sysconfig/kcare/kcare.conf will automatically update, and no action is needed for them.

You can manually update the serv
er by running:
# /usr/bin/kcarectl --update

Fixed CVE: CVE-2017-5715

CHANGELOG:
pve-3.10:
  CVE-2017-5715: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis
  cvelist: [CVE-2017-5715]
  latest-version: 3.10.0-22-pve_3.10.0-52
rhel7:
  CVE-2017-5715: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis
  cvelist: [CVE-2017-5715]
  latest-version: 3.10.0-862.9.1.el7
centos7:
  CVE-2017-5715: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
  cvelist: [CVE-2017-5715]
  latest-version: 3.10.0-862.9.1.el7
centos7-plus:
  CVE-2017-5715: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
  cvelist: [CVE-2017-5715]
  latest-version: 3.10.0-862.9.1.el7
cl6h:
  CVE-2017-5715: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
  cvelist: [CVE-2017-5715]
  latest-version: 3.10.0-714.10.2.lve1.5.17.1.el6h
cl7:
  CVE-2017-5715: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
  cvelist: [CVE-2017-5715]
  latest-version: 3.10.0-714.10.2.lve1.5.17.1.el7




--
-- 
Regards, 
Irina Semenova | Project Coordinator of KernelCare 
Skype: iras535

CloudLinux.com  |  KernelCare.com  |  Imunify360 

helpdesk.cloudlinux.com: 24/7 Free, exceptionally good support
Follow twitter.com/CloudLinuxOS for technical updates
Reply all
Reply to author
Forward
0 new messages