Jump to content
Compatible Support Forums
Sign in to follow this  
news

[RHSA-2010:0842-01] Important: kernel security and bug fix update

Recommended Posts

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

 

=====================================================================

Red Hat Security Advisory

 

Synopsis: Important: kernel security and bug fix update

Advisory ID: RHSA-2010:0842-01

Product: Red Hat Enterprise Linux

Advisory URL: https://rhn.redhat.com/errata/RHSA-2010-0842.html

Issue date: 2010-11-10

CVE Names: CVE-2010-2803 CVE-2010-2955 CVE-2010-2962

CVE-2010-3079 CVE-2010-3081 CVE-2010-3084

CVE-2010-3301 CVE-2010-3432 CVE-2010-3437

CVE-2010-3442 CVE-2010-3698 CVE-2010-3705

CVE-2010-3904

=====================================================================

 

1. Summary:

 

Updated kernel packages that fix multiple security issues and several bugs

are now available for Red Hat Enterprise Linux 6.

 

The Red Hat Security Response Team has rated this update as having

important security impact. Common Vulnerability Scoring System (CVSS) base

scores, which give detailed severity ratings, are available for each

vulnerability from the CVE links in the References section.

 

2. Relevant releases/architectures:

 

Red Hat Enterprise Linux Desktop (v. 6) - i386, noarch, x86_64

Red Hat Enterprise Linux HPC Node (v. 6) - noarch, x86_64

Red Hat Enterprise Linux Server (v. 6) - i386, noarch, ppc64, s390x, x86_64

Red Hat Enterprise Linux Workstation (v. 6) - i386, noarch, x86_64

 

3. Description:

 

The kernel packages contain the Linux kernel, the core of any Linux

operating system.

 

This update fixes the following security issues:

 

* Missing sanity checks in the Intel i915 driver in the Linux kernel could

allow a local, unprivileged user to escalate their privileges.

(CVE-2010-2962, Important)

 

* compat_alloc_user_space() in the Linux kernel 32/64-bit compatibility

layer implementation was missing sanity checks. This function could be

abused in other areas of the Linux kernel if its length argument can be

controlled from user-space. On 64-bit systems, a local, unprivileged user

could use this flaw to escalate their privileges. (CVE-2010-3081,

Important)

 

* A buffer overflow flaw in niu_get_ethtool_tcam_all() in the niu Ethernet

driver in the Linux kernel, could allow a local user to cause a denial of

service or escalate their privileges. (CVE-2010-3084, Important)

 

* A flaw in the IA32 system call emulation provided in 64-bit Linux kernels

could allow a local user to escalate their privileges. (CVE-2010-3301,

Important)

 

* A flaw in sctp_packet_config() in the Linux kernel's Stream Control

Transmission Protocol (SCTP) implementation could allow a remote attacker

to cause a denial of service. (CVE-2010-3432, Important)

 

* A missing integer overflow check in snd_ctl_new() in the Linux kernel's

sound subsystem could allow a local, unprivileged user on a 32-bit system

to cause a denial of service or escalate their privileges. (CVE-2010-3442,

Important)

 

* A flaw was found in sctp_auth_asoc_get_hmac() in the Linux kernel's SCTP

implementation. When iterating through the hmac_ids array, it did not reset

the last id element if it was out of range. This could allow a remote

attacker to cause a denial of service. (CVE-2010-3705, Important)

 

* A function in the Linux kernel's Reliable Datagram Sockets (RDS) protocol

implementation was missing sanity checks, which could allow a local,

unprivileged user to escalate their privileges. (CVE-2010-3904, Important)

 

* A flaw in drm_ioctl() in the Linux kernel's Direct Rendering Manager

(DRM) implementation could allow a local, unprivileged user to cause an

information leak. (CVE-2010-2803, Moderate)

 

* It was found that wireless drivers might not always clear allocated

buffers when handling a driver-specific IOCTL information request. A local

user could trigger this flaw to cause an information leak. (CVE-2010-2955,

Moderate)

 

* A NULL pointer dereference flaw in ftrace_regex_lseek() in the Linux

kernel's ftrace implementation could allow a local, unprivileged user to

cause a denial of service. Note: The debugfs file system must be mounted

locally to exploit this issue. It is not mounted by default.

(CVE-2010-3079, Moderate)

 

* A flaw in the Linux kernel's packet writing driver could be triggered

via the PKT_CTRL_CMD_STATUS IOCTL request, possibly allowing a local,

unprivileged user with access to "/dev/pktcdvd/control" to cause an

information leak. Note: By default, only users in the cdrom group have

access to "/dev/pktcdvd/control". (CVE-2010-3437, Moderate)

 

* A flaw was found in the way KVM (Kernel-based Virtual Machine) handled

the reloading of fs and gs segment registers when they had invalid

selectors. A privileged host user with access to "/dev/kvm" could use this

flaw to crash the host. (CVE-2010-3698, Moderate)

 

Red Hat would like to thank Kees Cook for reporting CVE-2010-2962 and

CVE-2010-2803; Ben Hawkes for reporting CVE-2010-3081 and CVE-2010-3301;

Dan Rosenberg for reporting CVE-2010-3442, CVE-2010-3705, CVE-2010-3904,

and CVE-2010-3437; and Robert Swiecki for reporting CVE-2010-3079.

 

This update also fixes several bugs. Documentation for these bug fixes will

be available shortly from the Technical Notes document linked to in the

References section.

 

Users should upgrade to these updated packages, which contain backported

patches to correct these issues. The system must be rebooted for this

update to take effect.

 

4. Solution:

 

Before applying this update, make sure all previously-released errata

relevant to your system have been applied.

 

This update is available via the Red Hat Network. Details on how to

use the Red Hat Network to apply this update are available at

http://kbase.redhat.com/faq/docs/DOC-11259

 

To install kernel packages manually, use "rpm -ivh [package]". Do not

use "rpm -Uvh" as that will remove the running kernel binaries from

your system. You may use "rpm -e" to remove old kernels after

determining that the new kernel functions properly on your system.

 

5. Bugs fixed (http://bugzilla.redhat.com/):

 

621435 - CVE-2010-2803 kernel: drm ioctls infoleak

628434 - CVE-2010-2955 kernel: wireless: fix 64K kernel heap content leak via ioctl

631623 - CVE-2010-3079 kernel: ftrace NULL ptr deref

632069 - CVE-2010-3084 kernel: niu: buffer overflow for ETHTOOL_GRXCLSRLALL

632292 - RHEL55.x32 crashes when installing under RHEL6 KVM on an AMD host [rhel-6.0.z]

633864 - block: fix s390 tape block driver crash that occurs when it switches the IO scheduler [rhel-6.0.z]

633865 - [FIPS140][RHEL6] kernel module should failed to load if DSA signature check fails when FIPS mode is on [rhel-6.0.z]

633964 - RHEL-UV: kernel panic on boot uvsw-sys [rhel-6.0.z]

633966 - winxp BSOD when boot with cpu mode name [rhel-6.0.z]

634449 - CVE-2010-3301 kernel: IA32 System Call Entry Point Vulnerability

634457 - CVE-2010-3081 kernel: 64-bit Compatibility Mode Stack Pointer Underflow

634973 - Detect and recover from cxgb3 adapter parity errors [rhel-6.0.z]

634984 - RHEL6 can NOT boot(displays nothing) on boards with RS880 [rhel-6.0.z]

635951 - kernel-kdump-debuginfo rpm does not contain debug symbols for s390 [rhel-6.0.z]

636116 - MADV_HUGEPAGE undeclared [rhel-6.0.z]

637087 - Kernel Memory dump to a FCP device fails with panic [rhel-6.0.z]

637675 - CVE-2010-3432 kernel: sctp: do not reset the packet during sctp_packet_config

637688 - CVE-2010-2962 kernel: arbitrary kernel memory write via i915 GEM ioctl

638085 - CVE-2010-3437 kernel: pktcdvd ioctl dev_minor missing range check

638478 - CVE-2010-3442 kernel: prevent heap corruption in snd_ctl_new()

638973 - [RHEL6 Snapshot 13]: The boot parameters 'nomodeset xforcevesa' is needed to install on Precision M4500 [rhel-6.0.z]

639412 - block: must prevent merges of discard and write requests [rhel-6.0.z]

639879 - CVE-2010-3698 kvm: invalid selector in fs/gs causes kernel panic

640036 - CVE-2010-3705 kernel: sctp memory corruption in HMAC handling

641258 - fix split_huge_page error like mapcount 3 page_mapcount 2 [rhel-6.0.z]

641454 - Output 'JBD: spotted dirty metadata buffer' message when usrquota is enabled [rhel-6.0.z]

641455 - [intel 6.0 Bug] NPIV broken in SW FCoE [rhel-6.0.z]

641456 - [intel 6.1 Bug] FCoE Boot ROM, unable to see LUN during system install thru NPV [rhel-6.0.z]

641457 - FCoE: Do not fall back to non-FIP FLOGI [rhel-6.0.z]

641458 - vmstat incorrectly reports disk IO as swap in [rhel-6.0.z]

641459 - Don't lose dirty bits leading to data corruption during KSM swapping [rhel-6.0.z]

641460 - KSM: fix page_address_in_vma anon_vma oops [rhel-6.0.z]

641483 - Stack size mapping is decreased through mlock/munlock call [rhel-6.0.z]

641907 - lpfc driver oops during rhel6 installation with snapshot 12/13 and emulex FC [rhel-6.0.z]

642043 - slow memory leak in i915 module on all intel hw [rhel-6.0.z]

642045 - major memory leak in radeon driver due when scrolling certain sites in firefox [rhel-6.0.z]

642465 - CVE-2010-2963 kernel: v4l: VIDIOCSMICROCODE arbitrary write

642679 - kernel BUG at mm/huge_memory.c:1279! [rhel-6.0.z]

642680 - XFS: accounting of reclaimable inodes is incorrect [rhel-6.0.z]

642896 - CVE-2010-3904 RDS sockets local privilege escalation

644037 - kernel BUG at mm/huge_memory.c:1267! - mapcount 5 page_mapcount 4 [rhel-6.0.z]

644038 - avoid crashes: backport hold mm->page_table_lock patch [rhel-6.0.z]

644636 - kernel wastes huge amounts of memory due to CONFIG_IMA [rhel-6.0.z]

644926 - calling elevator_change immediately after blk_init_queue results in a null pointer dereference [rhel-6.0.z]

646994 - Booting AMD Dinar system results in softlockups in ttm code [rhel-6.0.z]

 

6. Package List:

 

Red Hat Enterprise Linux Desktop (v. 6):

 

Source:

ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Client/en/os/SRPMS/kernel-2.6.32-71.7.1.el6.src.rpm

 

i386:

kernel-2.6.32-71.7.1.el6.i686.rpm

kernel-debug-2.6.32-71.7.1.el6.i686.rpm

kernel-debug-debuginfo-2.6.32-71.7.1.el6.i686.rpm

kernel-debug-devel-2.6.32-71.7.1.el6.i686.rpm

kernel-debuginfo-2.6.32-71.7.1.el6.i686.rpm

kernel-devel-2.6.32-71.7.1.el6.i686.rpm

kernel-headers-2.6.32-71.7.1.el6.i686.rpm

 

noarch:

kernel-doc-2.6.32-71.7.1.el6.noarch.rpm

kernel-firmware-2.6.32-71.7.1.el6.noarch.rpm

perf-2.6.32-71.7.1.el6.noarch.rpm

 

x86_64:

kernel-2.6.32-71.7.1.el6.x86_64.rpm

kernel-debug-2.6.32-71.7.1.el6.x86_64.rpm

kernel-debug-debuginfo-2.6.32-71.7.1.el6.x86_64.rpm

kernel-debug-devel-2.6.32-71.7.1.el6.x86_64.rpm

kernel-debuginfo-2.6.32-71.7.1.el6.x86_64.rpm

kernel-devel-2.6.32-71.7.1.el6.x86_64.rpm

kernel-headers-2.6.32-71.7.1.el6.x86_64.rpm

 

Red Hat Enterprise Linux HPC Node (v. 6):

 

Source:

ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6ComputeNode/en/os/SRPMS/kernel-2.6.32-71.7.1.el6.src.rpm

 

noarch:

kernel-doc-2.6.32-71.7.1.el6.noarch.rpm

kernel-firmware-2.6.32-71.7.1.el6.noarch.rpm

perf-2.6.32-71.7.1.el6.noarch.rpm

 

x86_64:

kernel-2.6.32-71.7.1.el6.x86_64.rpm

kernel-debug-2.6.32-71.7.1.el6.x86_64.rpm

kernel-debug-debuginfo-2.6.32-71.7.1.el6.x86_64.rpm

kernel-debug-devel-2.6.32-71.7.1.el6.x86_64.rpm

kernel-debuginfo-2.6.32-71.7.1.el6.x86_64.rpm

kernel-devel-2.6.32-71.7.1.el6.x86_64.rpm

kernel-headers-2.6.32-71.7.1.el6.x86_64.rpm

 

Red Hat Enterprise Linux Server (v. 6):

 

Source:

ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Server/en/os/SRPMS/kernel-2.6.32-71.7.1.el6.src.rpm

 

i386:

kernel-2.6.32-71.7.1.el6.i686.rpm

kernel-debug-2.6.32-71.7.1.el6.i686.rpm

kernel-debug-debuginfo-2.6.32-71.7.1.el6.i686.rpm

kernel-debug-devel-2.6.32-71.7.1.el6.i686.rpm

kernel-debuginfo-2.6.32-71.7.1.el6.i686.rpm

kernel-devel-2.6.32-71.7.1.el6.i686.rpm

kernel-headers-2.6.32-71.7.1.el6.i686.rpm

 

noarch:

kernel-doc-2.6.32-71.7.1.el6.noarch.rpm

kernel-firmware-2.6.32-71.7.1.el6.noarch.rpm

perf-2.6.32-71.7.1.el6.noarch.rpm

 

ppc64:

kernel-2.6.32-71.7.1.el6.ppc64.rpm

kernel-bootwrapper-2.6.32-71.7.1.el6.ppc64.rpm

kernel-debug-2.6.32-71.7.1.el6.ppc64.rpm

kernel-debug-debuginfo-2.6.32-71.7.1.el6.ppc64.rpm

kernel-debug-devel-2.6.32-71.7.1.el6.ppc64.rpm

kernel-debuginfo-2.6.32-71.7.1.el6.ppc64.rpm

kernel-devel-2.6.32-71.7.1.el6.ppc64.rpm

kernel-headers-2.6.32-71.7.1.el6.ppc64.rpm

 

s390x:

kernel-2.6.32-71.7.1.el6.s390x.rpm

kernel-debug-2.6.32-71.7.1.el6.s390x.rpm

kernel-debug-debuginfo-2.6.32-71.7.1.el6.s390x.rpm

kernel-debug-devel-2.6.32-71.7.1.el6.s390x.rpm

kernel-debuginfo-2.6.32-71.7.1.el6.s390x.rpm

kernel-devel-2.6.32-71.7.1.el6.s390x.rpm

kernel-headers-2.6.32-71.7.1.el6.s390x.rpm

kernel-kdump-2.6.32-71.7.1.el6.s390x.rpm

kernel-kdump-debuginfo-2.6.32-71.7.1.el6.s390x.rpm

kernel-kdump-devel-2.6.32-71.7.1.el6.s390x.rpm

 

x86_64:

kernel-2.6.32-71.7.1.el6.x86_64.rpm

kernel-debug-2.6.32-71.7.1.el6.x86_64.rpm

kernel-debug-debuginfo-2.6.32-71.7.1.el6.x86_64.rpm

kernel-debug-devel-2.6.32-71.7.1.el6.x86_64.rpm

kernel-debuginfo-2.6.32-71.7.1.el6.x86_64.rpm

kernel-devel-2.6.32-71.7.1.el6.x86_64.rpm

kernel-headers-2.6.32-71.7.1.el6.x86_64.rpm

 

Red Hat Enterprise Linux Workstation (v. 6):

 

Source:

ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Workstation/en/os/SRPMS/kernel-2.6.32-71.7.1.el6.src.rpm

 

i386:

kernel-2.6.32-71.7.1.el6.i686.rpm

kernel-debug-2.6.32-71.7.1.el6.i686.rpm

kernel-debug-debuginfo-2.6.32-71.7.1.el6.i686.rpm

kernel-debug-devel-2.6.32-71.7.1.el6.i686.rpm

kernel-debuginfo-2.6.32-71.7.1.el6.i686.rpm

kernel-devel-2.6.32-71.7.1.el6.i686.rpm

kernel-headers-2.6.32-71.7.1.el6.i686.rpm

 

noarch:

kernel-doc-2.6.32-71.7.1.el6.noarch.rpm

kernel-firmware-2.6.32-71.7.1.el6.noarch.rpm

perf-2.6.32-71.7.1.el6.noarch.rpm

 

x86_64:

kernel-2.6.32-71.7.1.el6.x86_64.rpm

kernel-debug-2.6.32-71.7.1.el6.x86_64.rpm

kernel-debug-debuginfo-2.6.32-71.7.1.el6.x86_64.rpm

kernel-debug-devel-2.6.32-71.7.1.el6.x86_64.rpm

kernel-debuginfo-2.6.32-71.7.1.el6.x86_64.rpm

kernel-devel-2.6.32-71.7.1.el6.x86_64.rpm

kernel-headers-2.6.32-71.7.1.el6.x86_64.rpm

 

These packages are GPG signed by Red Hat for security. Our key and

details on how to verify the signature are available from

https://www.redhat.com/security/team/key/#package

 

7. References:

 

https://www.redhat.com/security/data/cve/CVE-2010-2803.html

https://www.redhat.com/security/data/cve/CVE-2010-2955.html

https://www.redhat.com/security/data/cve/CVE-2010-2962.html

https://www.redhat.com/security/data/cve/CVE-2010-3079.html

https://www.redhat.com/security/data/cve/CVE-2010-3081.html

https://www.redhat.com/security/data/cve/CVE-2010-3084.html

https://www.redhat.com/security/data/cve/CVE-2010-3301.html

https://www.redhat.com/security/data/cve/CVE-2010-3432.html

https://www.redhat.com/security/data/cve/CVE-2010-3437.html

https://www.redhat.com/security/data/cve/CVE-2010-3442.html

https://www.redhat.com/security/data/cve/CVE-2010-3698.html

https://www.redhat.com/security/data/cve/CVE-2010-3705.html

https://www.redhat.com/security/data/cve/CVE-2010-3904.html

http://www.redhat.com/security/updates/classification/#important

http://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/6/html-single/Technical_Notes/index.html#RHSA-2010:0842

 

8. Contact:

 

The Red Hat security contact is . More contact

details at https://www.redhat.com/security/team/contact/

 

Copyright 2010 Red Hat, Inc.

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.4 (GNU/Linux)

 

iD8DBQFM2vIpXlSAg2UNWIIRAhP5AKC0brl5x5ea/40EJlXWeMsduhLJUQCdE8oY

pU9zeM5DaNHONahSCqnBcuQ=

=j8JK

-----END PGP SIGNATURE-----

 

 

--

 

Share this post


Link to post

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
Sign in to follow this  

×