SCIENTIFIC-LINUX-ERRATA Archives

February 2017

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Fri, 24 Feb 2017 21:20:38 -0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (60 lines)
Synopsis:          Important: kernel security update
Advisory ID:       SLSA-2017:0323-1
Issue Date:        2017-02-24
CVE Numbers:       CVE-2017-6074
                   CVE-2017-2634
--

Security Fix(es):

* A use-after-free flaw was found in the way the Linux kernel's Datagram
Congestion Control Protocol (DCCP) implementation freed SKB (socket
buffer) resources for a DCCP_PKT_REQUEST packet when the IPV6_RECVPKTINFO
option is set on the socket. A local, unprivileged user could use this
flaw to alter the kernel memory, allowing them to escalate their
privileges on the system. (CVE-2017-6074, Important)

* It was found that the Linux kernel's Datagram Congestion Control
Protocol (DCCP) implementation used the IPv4-only inet_sk_rebuild_header()
function for both IPv4 and IPv6 DCCP connections, which could result in
memory corruptions. A remote attacker could use this flaw to crash the
system. (CVE-2017-2634, Moderate)

Important: This update disables the DCCP kernel module at load time by
using the kernel module blacklist method. The module is disabled in an
attempt to reduce further exposure to additional issues.
--

SL5
  x86_64
    kernel-2.6.18-419.el5.x86_64.rpm
    kernel-debug-2.6.18-419.el5.x86_64.rpm
    kernel-debug-debuginfo-2.6.18-419.el5.x86_64.rpm
    kernel-debug-devel-2.6.18-419.el5.x86_64.rpm
    kernel-debuginfo-2.6.18-419.el5.x86_64.rpm
    kernel-debuginfo-common-2.6.18-419.el5.x86_64.rpm
    kernel-devel-2.6.18-419.el5.x86_64.rpm
    kernel-headers-2.6.18-419.el5.x86_64.rpm
    kernel-xen-2.6.18-419.el5.x86_64.rpm
    kernel-xen-debuginfo-2.6.18-419.el5.x86_64.rpm
    kernel-xen-devel-2.6.18-419.el5.x86_64.rpm
  i386
    kernel-2.6.18-419.el5.i686.rpm
    kernel-PAE-2.6.18-419.el5.i686.rpm
    kernel-PAE-debuginfo-2.6.18-419.el5.i686.rpm
    kernel-PAE-devel-2.6.18-419.el5.i686.rpm
    kernel-debug-2.6.18-419.el5.i686.rpm
    kernel-debug-debuginfo-2.6.18-419.el5.i686.rpm
    kernel-debug-devel-2.6.18-419.el5.i686.rpm
    kernel-debuginfo-2.6.18-419.el5.i686.rpm
    kernel-debuginfo-common-2.6.18-419.el5.i686.rpm
    kernel-devel-2.6.18-419.el5.i686.rpm
    kernel-headers-2.6.18-419.el5.i386.rpm
    kernel-xen-2.6.18-419.el5.i686.rpm
    kernel-xen-debuginfo-2.6.18-419.el5.i686.rpm
    kernel-xen-devel-2.6.18-419.el5.i686.rpm
  noarch
    kernel-doc-2.6.18-419.el5.noarch.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2