SCIENTIFIC-LINUX-ERRATA Archives

October 2017

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Fri, 6 Oct 2017 13:42:19 -0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (82 lines)
Synopsis:          Moderate: kernel security and bug fix update
Advisory ID:       SLSA-2017:2863-1
Issue Date:        2017-10-06
CVE Numbers:       CVE-2017-7541
--

Security Fix(es):

* Kernel memory corruption due to a buffer overflow was found in
brcmf_cfg80211_mgmt_tx() function in Linux kernels from v3.9-rc1 to
v4.13-rc1. The vulnerability can be triggered by sending a crafted
NL80211_CMD_FRAME packet via netlink. This flaw is unlikely to be
triggered remotely as certain userspace code is needed for this. An
unprivileged local user could use this flaw to induce kernel memory
corruption on the system, leading to a crash. Due to the nature of the
flaw, privilege escalation cannot be fully ruled out, although it is
unlikely. (CVE-2017-7541, Moderate)

Bug Fix(es):

* Previously, removal of a rport during ISCSI target scanning could cause
a kernel panic. This was happening because addition of STARGET_REMOVE to
the rport state introduced a race condition to the SCSI code. This update
adds the STARGET_CREATED_REMOVE state as a possible state of the rport and
appropriate handling of that state, thus fixing the bug. As a result, the
kernel panic no longer occurs under the described circumstances.

* Previously, GFS2 contained multiple bugs where the wrong inode was
assigned to GFS2 cluster-wide locks (glocks), or the assigned inode was
cleared incorrectly. Consequently, kernel panic could occur when using
GFS2. With this update, GFS2 has been fixed, and the kernel no longer
panics due to those bugs.

* Previously, VMs with memory larger than 64GB running on Hyper-V with
Windows Server hosts reported potential memory size of 4TB and more, but
could not use more than 64GB. This was happening because the Memory Type
Range Register (MTRR) for memory above 64GB was omitted. With this update,
the /proc/mtrr file has been fixed to show correct base/size if they are
more than 44 bit wide. As a result, the whole size of memory is now
available as expected under the described circumstances.
--

SL6
  x86_64
    kernel-2.6.32-696.13.2.el6.x86_64.rpm
    kernel-debug-2.6.32-696.13.2.el6.x86_64.rpm
    kernel-debug-debuginfo-2.6.32-696.13.2.el6.i686.rpm
    kernel-debug-debuginfo-2.6.32-696.13.2.el6.x86_64.rpm
    kernel-debug-devel-2.6.32-696.13.2.el6.i686.rpm
    kernel-debug-devel-2.6.32-696.13.2.el6.x86_64.rpm
    kernel-debuginfo-2.6.32-696.13.2.el6.i686.rpm
    kernel-debuginfo-2.6.32-696.13.2.el6.x86_64.rpm
    kernel-debuginfo-common-i686-2.6.32-696.13.2.el6.i686.rpm
    kernel-debuginfo-common-x86_64-2.6.32-696.13.2.el6.x86_64.rpm
    kernel-devel-2.6.32-696.13.2.el6.x86_64.rpm
    kernel-headers-2.6.32-696.13.2.el6.x86_64.rpm
    perf-2.6.32-696.13.2.el6.x86_64.rpm
    perf-debuginfo-2.6.32-696.13.2.el6.i686.rpm
    perf-debuginfo-2.6.32-696.13.2.el6.x86_64.rpm
    python-perf-debuginfo-2.6.32-696.13.2.el6.i686.rpm
    python-perf-debuginfo-2.6.32-696.13.2.el6.x86_64.rpm
    python-perf-2.6.32-696.13.2.el6.x86_64.rpm
  i386
    kernel-2.6.32-696.13.2.el6.i686.rpm
    kernel-debug-2.6.32-696.13.2.el6.i686.rpm
    kernel-debug-debuginfo-2.6.32-696.13.2.el6.i686.rpm
    kernel-debug-devel-2.6.32-696.13.2.el6.i686.rpm
    kernel-debuginfo-2.6.32-696.13.2.el6.i686.rpm
    kernel-debuginfo-common-i686-2.6.32-696.13.2.el6.i686.rpm
    kernel-devel-2.6.32-696.13.2.el6.i686.rpm
    kernel-headers-2.6.32-696.13.2.el6.i686.rpm
    perf-2.6.32-696.13.2.el6.i686.rpm
    perf-debuginfo-2.6.32-696.13.2.el6.i686.rpm
    python-perf-debuginfo-2.6.32-696.13.2.el6.i686.rpm
    python-perf-2.6.32-696.13.2.el6.i686.rpm
  noarch
    kernel-abi-whitelists-2.6.32-696.13.2.el6.noarch.rpm
    kernel-doc-2.6.32-696.13.2.el6.noarch.rpm
    kernel-firmware-2.6.32-696.13.2.el6.noarch.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2