Kernel security update: CVE-2017-18017; Virtuozzo ReadyKernel patch 42.0 for Virtuozzo 7.0.4, 7.0.4 HF3, 7.0.5, 7.0.6, and 7.0.6 HF3¶
Issue date: 2018-01-12
Applies to: Virtuozzo 7.0
Virtuozzo Advisory ID: VZA-2018-005
1. Overview¶
The cumulative Virtuozzo ReadyKernel patch was updated with a security fix. The patch applies to Virtuozzo kernels 3.10.0-514.16.1.vz7.30.10 (Virtuozzo 7.0.4), 3.10.0-514.16.1.vz7.30.15 (Virtuozzo 7.0.4 HF3), 3.10.0-514.26.1.vz7.33.22 (Virtuozzo 7.0.5), 3.10.0-693.1.1.vz7.37.30 (Virtuozzo 7.0.6), and 3.10.0-693.11.6.vz7.40.4 (Virtuozzo 7.0.6 HF3).
2. Security Fixes¶
[Moderate] If the system uses iptables and there are iptables rules with TCPMSS action there, a remote attacker could cause a denial of service (use-after-free in tcpmss_mangle_packet function leading to memory corruption) or possibly have unspecified other impact by sending specially crafted network packets. (CVE-2017-18017)
3. Installing the Update¶
Download, install, and instantly apply the patch to the current kernel by running ‘readykernel update’.
4. References¶
https://readykernel.com/patch/Virtuozzo-7/readykernel-patch-30.10-42.0-1.vl7/
https://readykernel.com/patch/Virtuozzo-7/readykernel-patch-30.15-42.0-1.vl7/
https://readykernel.com/patch/Virtuozzo-7/readykernel-patch-33.22-42.0-1.vl7/
https://readykernel.com/patch/Virtuozzo-7/readykernel-patch-37.30-42.0-1.vl7/
https://readykernel.com/patch/Virtuozzo-7/readykernel-patch-40.4-42.0-1.vl7/
The JSON file with the list of new and updated packages is available at http://docs.virtuozzo.com/vza/VZA-2018-005.json.