FEDORA-2017-090a9c11db created by thaller 4 years ago for Fedora 25
stable

Update with patches from upstream

  • check valid input arguments for nla_reserve() (rh #1414305, CVE-2017-0386)
  • fix crash during SRIOV parsing
  • lazyly read psched settings
  • use O_CLOEXEC when creating file descriptors with fopen()

How to install

sudo dnf upgrade --advisory=FEDORA-2017-090a9c11db

This update has been submitted for testing by thaller.

4 years ago
User Icon laine commented & provided feedback 4 years ago
karma

This solves the crash when parsing SRIOV VF info. Also tested basic runtime functionality, and built both libvirt and netcf packages (which use libnl3-devel during the build)

This update has been pushed to testing.

4 years ago
User Icon cserpentis commented & provided feedback 4 years ago
karma

works for me

This update has been submitted for stable by bodhi.

4 years ago
User Icon besser82 commented & provided feedback 4 years ago
karma

Works great! LGTM! =)

This update has been pushed to stable.

4 years ago

Please login to add feedback.

Metadata
Type
security
Karma
3
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
disabled
Dates
submitted
4 years ago
in testing
4 years ago
in stable
4 years ago
BZ#1414304 CVE-2017-0386 libnl: Privilege escalation due to insufficient data checks in nla_reserve and nla_put
0
0
BZ#1414305 CVE-2017-0386 libnl3: libnl: Privilege escalation due to insufficient data checks in nla_reserve and nla_put [fedora-all]
0
0

Automated Test Results