Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Red Hat: RHSA-2010:0842-01 Important: Kernel Security Fix

red hat
Calendar Grey November 10, 2010
Dist Redhat Esm H88
New kernel upgrade released for Red Hat Enterprise Linux 6 addressing multiple security vulnerabilities and defects classified as critical.
Updated kernel packages that fix multiple security issues and several bugs are now available for Red Hat Enterprise Linux 6

Solution

Before applying this update, make sure all previously-released errata relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at

To install kernel packages manually, use "rpm -ivh [package]". Do not use "rpm -Uvh" as that will remove the running kernel binaries from your system. You may use "rpm -e" to remove old kernels after determining that the new kernel functions properly on your system.

Summary

The kernel packages contain the Linux kernel, the core of any Linux operating system.
This update fixes the following security issues:
* Missing sanity checks in the Intel i915 driver in the Linux kernel could allow a local, unprivileged user to escalate their privileges. (CVE-2010-2962, Important)
* compat_alloc_user_space() in the Linux kernel 32/64-bit compatibility layer implementation was missing sanity checks. This function could be abused in other areas of the Linux kernel if its length argument can be controlled from user-space. On 64-bit systems, a local, unprivileged user could use this flaw to escalate their privileges. (CVE-2010-3081, Important)
* A buffer overflow flaw in niu_get_ethtool_tcam_all() in the niu Ethernet driver in the Linux kernel, could allow a local user to cause a denial of service or escalate their privileges. (CVE-2010-3084, Important)
* A flaw in the IA32 system call emulation provided in 64-bit Linux kernels could allow a local user to escalate their privileges. (CVE-2010-3301, Important)
* A flaw in sctp_packet_config() in the Linux kernel's Stream Control Transmission Protocol (SCTP) implementation could allow a remote attacker to cause a denial of service. (CVE-2010-3432, Important)
* A missing integer overflow check in snd_ctl_new() in the Linux kernel's sound subsystem could allow a local, unprivileged user on a 32-bit system to cause a denial of service or escalate their privileges. (CVE-2010-3442, Important)
* A flaw was found in sctp_auth_asoc_get_hmac() in the Linux kernel's SCTP implementation. When iterating through the hmac_ids array, it did not reset the last id element if it was out of range. This could allow a remote attacker to cause a denial of service. (CVE-2010-3705, Important)
* A function in the Linux kernel's Reliable Datagram Sockets (RDS) protocol implementation was missing sanity checks, which could allow a local, unprivileged user to escalate their privileges. (CVE-2010-3904, Important)
* A flaw in drm_ioctl() in the Linux kernel's Direct Rendering Manager (DRM) implementation could allow a local, unprivileged user to cause an information leak. (CVE-2010-2803, Moderate)
* It was found that wireless drivers might not always clear allocated buffers when handling a driver-specific IOCTL information request. A local user could trigger this flaw to cause an information leak. (CVE-2010-2955, Moderate)
* A NULL pointer dereference flaw in ftrace_regex_lseek() in the Linux kernel's ftrace implementation could allow a local, unprivileged user to cause a denial of service. Note: The debugfs file system must be mounted locally to exploit this issue. It is not mounted by default. (CVE-2010-3079, Moderate)
* A flaw in the Linux kernel's packet writing driver could be triggered via the PKT_CTRL_CMD_STATUS IOCTL request, possibly allowing a local, unprivileged user with access to "/dev/pktcdvd/control" to cause an information leak. Note: By default, only users in the cdrom group have access to "/dev/pktcdvd/control". (CVE-2010-3437, Moderate)
* A flaw was found in the way KVM (Kernel-based Virtual Machine) handled the reloading of fs and gs segment registers when they had invalid selectors. A privileged host user with access to "/dev/kvm" could use this flaw to crash the host. (CVE-2010-3698, Moderate)
Red Hat would like to thank Kees Cook for reporting CVE-2010-2962 and CVE-2010-2803; Ben Hawkes for reporting CVE-2010-3081 and CVE-2010-3301; Dan Rosenberg for reporting CVE-2010-3442, CVE-2010-3705, CVE-2010-3904, and CVE-2010-3437; and Robert Swiecki for reporting CVE-2010-3079.
This update also fixes several bugs. Documentation for these bug fixes will be available shortly from the Technical Notes document linked to in the References section.
Users should upgrade to these updated packages, which contain backported patches to correct these issues. The system must be rebooted for this update to take effect.

References

https://access.redhat.com/security/cve/CVE-2010-2803 https://access.redhat.com/security/cve/CVE-2010-2955 https://access.redhat.com/security/cve/CVE-2010-2962 https://access.redhat.com/security/cve/CVE-2010-3079 https://access.redhat.com/security/cve/CVE-2010-3081 https://access.redhat.com/security/cve/CVE-2010-3084 https://access.redhat.com/security/cve/CVE-2010-3301 https://access.redhat.com/security/cve/CVE-2010-3432 https://access.redhat.com/security/cve/CVE-2010-3437 https://access.redhat.com/security/cve/CVE-2010-3442 https://access.redhat.com/security/cve/CVE-2010-3698 https://access.redhat.com/security/cve/CVE-2010-3705 https://access.redhat.com/security/cve/CVE-2010-3904 https://access.redhat.com/security/updates/classification#important https://access.redhat.com/search/

Package List

Red Hat Enterprise Linux Desktop (v. 6):
Source:
i386: kernel-2.6.32-71.7.1.el6.i686.rpm kernel-debug-2.6.32-71.7.1.el6.i686.rpm kernel-debug-debuginfo-2.6.32-71.7.1.el6.i686.rpm kernel-debug-devel-2.6.32-71.7.1.el6.i686.rpm kernel-debuginfo-2.6.32-71.7.1.el6.i686.rpm kernel-devel-2.6.32-71.7.1.el6.i686.rpm kernel-headers-2.6.32-71.7.1.el6.i686.rpm
noarch: kernel-doc-2.6.32-71.7.1.el6.noarch.rpm kernel-firmware-2.6.32-71.7.1.el6.noarch.rpm perf-2.6.32-71.7.1.el6.noarch.rpm
x86_64: kernel-2.6.32-71.7.1.el6.x86_64.rpm kernel-debug-2.6.32-71.7.1.el6.x86_64.rpm kernel-debug-debuginfo-2.6.32-71.7.1.el6.x86_64.rpm kernel-debug-devel-2.6.32-71.7.1.el6.x86_64.rpm kernel-debuginfo-2.6.32-71.7.1.el6.x86_64.rpm kernel-devel-2.6.32-71.7.1.el6.x86_64.rpm kernel-headers-2.6.32-71.7.1.el6.x86_64.rpm
Red Hat Enterprise Linux HPC Node (v. 6):
Source:
noarch: kernel-doc-2.6.32-71.7.1.el6.noarch.rpm kernel-firmware-2.6.32-71.7.1.el6.noarch.rpm perf-2.6.32-71.7.1.el6.noarch.rpm
x86_64: kernel-2.6.32-71.7.1.el6.x86_64.rpm kernel-debug-2.6.32-71.7.1.el6.x86_64.rpm kernel-debug-debuginfo-2.6.32-71.7.1.el6.x86_64.rpm kernel-debug-devel-2.6.32-71.7.1.el6.x86_64.rpm kernel-debuginfo-2.6.32-71.7.1.el6.x86_64.rpm kernel-devel-2.6.32-71.7.1.el6.x86_64.rpm

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2010:0842-01
Product: Red Hat Enterprise Linux
Issue date: 2010-11-10

Topic

Updated kernel packages that fix multiple security issues and several bugsare now available for Red Hat Enterprise Linux 6.The Red Hat Security Response Team has rated this update as havingimportant security impact. Common Vulnerability Scoring System (CVSS) basescores, which give detailed severity ratings, are available for eachvulnerability from the CVE links in the References section.

Relevant Releases Architectures

Red Hat Enterprise Linux Desktop (v. 6) - i386, noarch, x86_64

Red Hat Enterprise Linux HPC Node (v. 6) - noarch, x86_64

Red Hat Enterprise Linux Server (v. 6) - i386, noarch, ppc64, s390x, x86_64

Red Hat Enterprise Linux Workstation (v. 6) - i386, noarch, x86_64

Bugs Fixed

621435 - CVE-2010-2803 kernel: drm ioctls infoleak

628434 - CVE-2010-2955 kernel: wireless: fix 64K kernel heap content leak via ioctl

631623 - CVE-2010-3079 kernel: ftrace NULL ptr deref

632069 - CVE-2010-3084 kernel: niu: buffer overflow for ETHTOOL_GRXCLSRLALL

632292 - RHEL55.x32 crashes when installing under RHEL6 KVM on an AMD host [rhel-6.0.z]

633864 - block: fix s390 tape block driver crash that occurs when it switches the IO scheduler [rhel-6.0.z]

633865 - [FIPS140][RHEL6] kernel module should failed to load if DSA signature check fails when FIPS mode is on [rhel-6.0.z]

633964 - RHEL-UV: kernel panic on boot uvsw-sys [rhel-6.0.z]

633966 - winxp BSOD when boot with cpu mode name [rhel-6.0.z]

634449 - CVE-2010-3301 kernel: IA32 System Call Entry Point Vulnerability

634457 - CVE-2010-3081 kernel: 64-bit Compatibility Mode Stack Pointer Underflow

634973 - Detect and recover from cxgb3 adapter parity errors [rhel-6.0.z]

634984 - RHEL6 can NOT boot(displays nothing) on boards with RS880 [rhel-6.0.z]

635951 - kernel-kdump-debuginfo rpm does not contain debug symbols for s390 [rhel-6.0.z]

636116 - MADV_HUGEPAGE undeclared [rhel-6.0.z]

637087 - Kernel Memory dump to a FCP device fails with panic [rhel-6.0.z]

637675 - CVE-2010-3432 kernel: sctp: do not reset the packet during sctp_packet_config

637688 - CVE-2010-2962 kernel: arbitrary kernel memory write via i915 GEM ioctl

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here