Tag: els

CentOS 6 ELS kernel v.2.6.32-754.35.2 has been scheduled for gradual rollout

kernel

CentOS 6 ELS kernel v.2.6.32-754.35.2.el6 has been scheduled for gradual rollout from our production repository.

CentOS 6 ELS kernel v.2.6.32-754.29.3 has been rolled out to 100%

kernel

CentOS 6 ELS kernel v.2.6.32-754.29.3.el6 has been rolled out to 100% and is now available for download from our production repository.

CentOS 6 ELS kernel v.2.6.32-754.29.3 has been scheduled for gradual rollout

kernel

CentOS 6 ELS kernel v.2.6.32-754.29.3.el6 has been scheduled for gradual rollout from our production repository.

Rollout slot: 2

Rolled out to: 1%

ETA for 100%: February, 16

Changelog

  • CKSIX-268: futex: Handle faults correctly for PI futexes
  • CKSIX-268: futex: Provide and use pi_state_update_owner()
  • CKSIX-263: KEYS: allow reaching the keys quotas exactly
  • CKSIX-263: KEYS: reaching the keys quotas correctly
  • CKSIX-263: fix -ENOMEM result with invalid user space pointer in
    sendto() syscall
  • CKSIX-263: CVE-2017-18344: posix-timer: Properly check sigevent->sigev_notify
  • CKSIX-263: CVE-2018-6927: futex: Prevent overflow by strengthen
    input validation
  • CKSIX-258: CVE-2017-6951: KEYS: Change the name of the dead type to
    ".dead" to prevent user access
  • CKSIX-258: CVE-2017-15299: KEYS: don't let add_key() update an
    uninstantiated key
  • CKSIX-258: fix CVE-2016-9604
  • CKSIX-258: KEYS: add missing permission check for request_key() destination
  • CKSIX-258: KEYS: prevent KEYCTL_READ on negative key
  • CKSIX-258: CVE-2017-10661: timerfd: Protect the might cancel mechanism proper
  • CKSIX-258: fix CVE-2017-7472
  • CKSIX-258: fix CVE-2017-15274

Update

yum update kernel*

Immediate update (via bypass)

yum update kernel* --enablerepo=ELS6-rollout-2-bypass

A new sudo package with the CVE-2021-3156 fix within CloudLinux 6 Extended Lifecycle Support has been rolled out to 100%

Extended-CL

A new sudo package with the CVE-2021-3156 fix within CloudLinux 6 extended lifecycle support has been rolled out to 100% and is now available for download from our production repository.

Changelog

sudo-1.8.6p3-30.cloudlinux.els6

  • Fixed Heap-based buffer overflow in Sudo (CVE-2021-3156)

Update command

yum update sudo*

CVE-2021-3156 description

Sudo before 1.9.5p2 has a Heap-based Buffer Overflow, allowing privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

A new sudo package with the CVE-2021-3156 fix within CentOS 6 Extended Lifecycle Support has been rolled out to 100%

Extended-CentOS

A new sudo package with the CVE-2021-3156 fix within CentOS 6 extended lifecycle support has been rolled out to 100% and is now available for download from our production repository.

A new sudo package with the CVE-2021-3156 fix within CentOS 6 Extended Lifecycle Support has been scheduled for gradual rollout

Extended-CentOS

A new sudo package with the CVE-2021-3156 fix within CentOS 6 extended lifecycle support has been scheduled for gradual rollout from our production repository.

A new sudo package with the CVE-2021-3156 fix within CloudLinux 6 Extended Lifecycle Support has been scheduled for gradual rollout

Extended-CL

A new sudo package with the CVE-2021-3156 fix within CloudLinux 6 extended lifecycle support has been scheduled for gradual rollout from our production repository.

Rollout slot: 4

Rolled out to: 1%

ETA for 100% rollout: February, 10

Changelog

sudo-1.8.6p3-30.cloudlinux.els6

  • Fixed Heap-based buffer overflow in Sudo (CVE-2021-3156)

Update command

yum update sudo*

Immediate update (via bypass)

yum update sudo* --enablerepo=cloudlinux-rollout-4-bypass

CVE-2021-3156 description

Sudo before 1.9.5p2 has a Heap-based Buffer Overflow, allowing privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

A new PHP package within CloudLinux 6 Extended Lifecycle Support has been scheduled for gradual rollout

Extended-CL

A new PHP package within CloudLinux 6 extended lifecycle support has been scheduled for gradual rollout from our production repository.

A new PHP package within CentOS 6 Extended Lifecycle Support has been scheduled for gradual rollout

Extended-CentOS

A new PHP package within CentOS 6 extended lifecycle support has been scheduled for gradual rollout from our production repository.

OpenSSL and cURL packages within CloudLinux 6 Extended Lifecycle Support with a fix for the CVE-2020-1971 and the CVE-2020-8284 have been rolled out to 100%

Extended-CL

We are happy to announce that new openssl-1.0.1e-59.cloudlinux.els6 and curl-7.19.7-55.cloudlinux.els6 packages within CloudLinux 6 extended lifecycle support have been rolled out to 100% and is now available for download from our production repository.

imunify-logo

WEB SERVER SECURITY BLOG

Subscribe to CloudLinux Newsletter