In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade Oracle:6
mlnx_en-2.6.32-400.26.2.el6uekdebug
to version 0:1.5.7-0.1 or higher.
This issue was patched in ELSA-2013-2520
.
Note: Versions mentioned in the description apply only to the upstream mlnx_en-2.6.32-400.26.2.el6uekdebug
package and not the mlnx_en-2.6.32-400.26.2.el6uekdebug
package as distributed by Oracle
.
See How to fix?
for Oracle:6
relevant fixed versions and status.
The cipso_v4_validate function in net/ipv4/cipso_ipv4.c in the Linux kernel before 3.4.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an IPOPT_CIPSO IP_OPTIONS setsockopt system call.