Category Archives: Fedora

Fedora – Security Updates

kernel-4.10.4-200.fc25

The 4.10.4 stable kernel update contains a number of important fixes across the tree. It also reverts CONFIG_CFG80211_CRDA_SUPPORT to match the previous 4.9 kernels.

—-

The 4.10.3 kernel rebase contains a number of new features, important fixes, and additional hardware support.

qemu-2.7.1-4.fc25

* CVE-2016-7907: net: imx: infinite loop (bz #1381182)
* CVE-2017-5525: audio: memory leakage in ac97 (bz #1414110)
* CVE-2017-5526: audio: memory leakage in es1370 (bz #1414210)
* CVE-2016-10155 watchdog: memory leakage in i6300esb (bz #1415200)
* CVE-2017-5552: virtio-gpu-3d: memory leakage (bz #1415283)
* CVE-2017-5578: virtio-gpu: memory leakage (bz #1415797)
* CVE-2017-5667: sd: sdhci OOB access during multi block transfer (bz #1417560)
* CVE-2017-5856: scsi: megasas: memory leakage (bz #1418344)
* CVE-2017-5857: virtio-gpu-3d: host memory leakage in virgl_cmd_resource_unref (bz #1418383)
* CVE-2017-5898: usb: integer overflow in emulated_apdu_from_guest (bz #1419700)
* CVE-2017-5987: sd: infinite loop issue in multi block transfers (bz #1422001)
* CVE-2017-6058: vmxnet3: OOB access when doing vlan stripping (bz #1423359)
* CVE-2017-6505: usb: an infinite loop issue in ohci_service_ed_list (bz #1429434)
* CVE-2017-2615: cirrus: oob access while doing bitblt copy backward (bz #1418206)
* CVE-2017-2620: cirrus: potential arbitrary code execution (bz #1425419)
* Fix spice GL with new mesa/libglvnd (bz #1431905)