SCIENTIFIC-LINUX-ERRATA Archives

July 2011

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
"Tyler L. Parsons" <[log in to unmask]>
Reply To:
Tyler L. Parsons
Date:
Wed, 13 Jul 2011 15:21:13 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (60 lines)
Synopsis:    Moderate: kernel security and bug fix update
Issue Date:  2011-07-12
CVE Numbers: CVE-2011-1767
             CVE-2011-2479


The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* It was found that the receive hook in the ipip_init() function in the
ipip module, and in the ipgre_init() function in the ip_gre module, could
be called before network namespaces setup is complete. If packets were
received at the time the ipip or ip_gre module was still being loaded into
the kernel, it could cause a denial of service. (CVE-2011-1767,
CVE-2011-1768, Moderate)

* It was found that an mmap() call with the MAP_PRIVATE flag on "/dev/zero"
would create transparent hugepages and trigger a certain robustness check.
A local, unprivileged user could use this flaw to cause a denial of
service. (CVE-2011-2479, Moderate)

This update also fixes various bugs. Documentation for these bug fixes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to resolve these issues, and fix the bugs noted in the Technical
Notes. The system must be rebooted for this update to take effect.

SL6:
  i386
     kernel-2.6.32-131.6.1.el6.i686.rpm
     perf-debuginfo-2.6.32-131.6.1.el6.i686.rpm
     perf-2.6.32-131.6.1.el6.i686.rpm
     kernel-headers-2.6.32-131.6.1.el6.i686.rpm
     kernel-devel-2.6.32-131.6.1.el6.i686.rpm
     kernel-debuginfo-common-i686-2.6.32-131.6.1.el6.i686.rpm
     kernel-debuginfo-2.6.32-131.6.1.el6.i686.rpm
     kernel-debug-devel-2.6.32-131.6.1.el6.i686.rpm
     kernel-debug-debuginfo-2.6.32-131.6.1.el6.i686.rpm
     kernel-debug-2.6.32-131.6.1.el6.i686.rpm
  noarch
     kernel-firmware-2.6.32-131.6.1.el6.noarch.rpm
     kernel-doc-2.6.32-131.6.1.el6.noarch.rpm
  x86_64
     perf-2.6.32-131.6.1.el6.x86_64.rpm
     kernel-headers-2.6.32-131.6.1.el6.x86_64.rpm
     kernel-devel-2.6.32-131.6.1.el6.x86_64.rpm
     kernel-debuginfo-common-x86_64-2.6.32-131.6.1.el6.x86_64.rpm
     kernel-debuginfo-2.6.32-131.6.1.el6.x86_64.rpm
     kernel-debug-devel-2.6.32-131.6.1.el6.x86_64.rpm
     kernel-debug-debuginfo-2.6.32-131.6.1.el6.x86_64.rpm
     kernel-debug-2.6.32-131.6.1.el6.x86_64.rpm
     kernel-2.6.32-131.6.1.el6.x86_64.rpm
     perf-debuginfo-2.6.32-131.6.1.el6.x86_64.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2