[RHSA-2010:0842-01] Important: kernel security and bug fix update

bugzilla at redhat.com bugzilla at redhat.com
Wed Nov 10 19:27:54 UTC 2010


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Important: kernel security and bug fix update
Advisory ID:       RHSA-2010:0842-01
Product:           Red Hat Enterprise Linux
Advisory URL:      https://rhn.redhat.com/errata/RHSA-2010-0842.html
Issue date:        2010-11-10
CVE Names:         CVE-2010-2803 CVE-2010-2955 CVE-2010-2962 
                   CVE-2010-3079 CVE-2010-3081 CVE-2010-3084 
                   CVE-2010-3301 CVE-2010-3432 CVE-2010-3437 
                   CVE-2010-3442 CVE-2010-3698 CVE-2010-3705 
                   CVE-2010-3904 
=====================================================================

1. Summary:

Updated kernel packages that fix multiple security issues and several bugs
are now available for Red Hat Enterprise Linux 6.

The Red Hat Security Response Team has rated this update as having
important security impact. Common Vulnerability Scoring System (CVSS) base
scores, which give detailed severity ratings, are available for each
vulnerability from the CVE links in the References section.

2. Relevant releases/architectures:

Red Hat Enterprise Linux Desktop (v. 6) - i386, noarch, x86_64
Red Hat Enterprise Linux HPC Node (v. 6) - noarch, x86_64
Red Hat Enterprise Linux Server (v. 6) - i386, noarch, ppc64, s390x, x86_64
Red Hat Enterprise Linux Workstation (v. 6) - i386, noarch, x86_64

3. Description:

The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* Missing sanity checks in the Intel i915 driver in the Linux kernel could
allow a local, unprivileged user to escalate their privileges.
(CVE-2010-2962, Important)

* compat_alloc_user_space() in the Linux kernel 32/64-bit compatibility
layer implementation was missing sanity checks. This function could be
abused in other areas of the Linux kernel if its length argument can be
controlled from user-space. On 64-bit systems, a local, unprivileged user
could use this flaw to escalate their privileges. (CVE-2010-3081,
Important)

* A buffer overflow flaw in niu_get_ethtool_tcam_all() in the niu Ethernet
driver in the Linux kernel, could allow a local user to cause a denial of
service or escalate their privileges. (CVE-2010-3084, Important)

* A flaw in the IA32 system call emulation provided in 64-bit Linux kernels
could allow a local user to escalate their privileges. (CVE-2010-3301,
Important)

* A flaw in sctp_packet_config() in the Linux kernel's Stream Control
Transmission Protocol (SCTP) implementation could allow a remote attacker
to cause a denial of service. (CVE-2010-3432, Important)

* A missing integer overflow check in snd_ctl_new() in the Linux kernel's
sound subsystem could allow a local, unprivileged user on a 32-bit system
to cause a denial of service or escalate their privileges. (CVE-2010-3442,
Important)

* A flaw was found in sctp_auth_asoc_get_hmac() in the Linux kernel's SCTP
implementation. When iterating through the hmac_ids array, it did not reset
the last id element if it was out of range. This could allow a remote
attacker to cause a denial of service. (CVE-2010-3705, Important)

* A function in the Linux kernel's Reliable Datagram Sockets (RDS) protocol
implementation was missing sanity checks, which could allow a local,
unprivileged user to escalate their privileges. (CVE-2010-3904, Important)

* A flaw in drm_ioctl() in the Linux kernel's Direct Rendering Manager
(DRM) implementation could allow a local, unprivileged user to cause an
information leak. (CVE-2010-2803, Moderate)

* It was found that wireless drivers might not always clear allocated
buffers when handling a driver-specific IOCTL information request. A local
user could trigger this flaw to cause an information leak. (CVE-2010-2955,
Moderate)

* A NULL pointer dereference flaw in ftrace_regex_lseek() in the Linux
kernel's ftrace implementation could allow a local, unprivileged user to
cause a denial of service. Note: The debugfs file system must be mounted
locally to exploit this issue. It is not mounted by default.
(CVE-2010-3079, Moderate)

* A flaw in the Linux kernel's packet writing driver could be triggered
via the PKT_CTRL_CMD_STATUS IOCTL request, possibly allowing a local,
unprivileged user with access to "/dev/pktcdvd/control" to cause an
information leak. Note: By default, only users in the cdrom group have
access to "/dev/pktcdvd/control". (CVE-2010-3437, Moderate)

* A flaw was found in the way KVM (Kernel-based Virtual Machine) handled
the reloading of fs and gs segment registers when they had invalid
selectors. A privileged host user with access to "/dev/kvm" could use this
flaw to crash the host. (CVE-2010-3698, Moderate)

Red Hat would like to thank Kees Cook for reporting CVE-2010-2962 and
CVE-2010-2803; Ben Hawkes for reporting CVE-2010-3081 and CVE-2010-3301;
Dan Rosenberg for reporting CVE-2010-3442, CVE-2010-3705, CVE-2010-3904,
and CVE-2010-3437; and Robert Swiecki for reporting CVE-2010-3079.

This update also fixes several bugs. Documentation for these bug fixes will
be available shortly from the Technical Notes document linked to in the
References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.

4. Solution:

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259

To install kernel packages manually, use "rpm -ivh [package]". Do not
use "rpm -Uvh" as that will remove the running kernel binaries from
your system. You may use "rpm -e" to remove old kernels after
determining that the new kernel functions properly on your system.

5. Bugs fixed (http://bugzilla.redhat.com/):

621435 - CVE-2010-2803 kernel: drm ioctls infoleak
628434 - CVE-2010-2955 kernel: wireless: fix 64K kernel heap content leak via ioctl
631623 - CVE-2010-3079 kernel: ftrace NULL ptr deref
632069 - CVE-2010-3084 kernel: niu: buffer overflow for ETHTOOL_GRXCLSRLALL
632292 - RHEL55.x32 crashes when installing under RHEL6 KVM on an AMD host [rhel-6.0.z]
633864 - block: fix s390 tape block driver crash that occurs when it switches the IO scheduler [rhel-6.0.z]
633865 - [FIPS140][RHEL6] kernel module should failed to load if DSA signature check fails when FIPS mode is on [rhel-6.0.z]
633964 - RHEL-UV: kernel panic on boot uvsw-sys [rhel-6.0.z]
633966 - winxp BSOD when boot with cpu mode name [rhel-6.0.z]
634449 - CVE-2010-3301 kernel: IA32 System Call Entry Point Vulnerability
634457 - CVE-2010-3081 kernel: 64-bit Compatibility Mode Stack Pointer Underflow
634973 - Detect and recover from cxgb3 adapter parity errors [rhel-6.0.z]
634984 - RHEL6 can NOT boot(displays nothing) on boards with RS880 [rhel-6.0.z]
635951 - kernel-kdump-debuginfo rpm does not contain debug symbols for s390 [rhel-6.0.z]
636116 - MADV_HUGEPAGE undeclared [rhel-6.0.z]
637087 - Kernel Memory dump to a FCP device fails with panic [rhel-6.0.z]
637675 - CVE-2010-3432 kernel: sctp: do not reset the packet during sctp_packet_config
637688 - CVE-2010-2962 kernel: arbitrary kernel memory write via i915 GEM ioctl
638085 - CVE-2010-3437 kernel: pktcdvd ioctl dev_minor missing range check
638478 - CVE-2010-3442 kernel: prevent heap corruption in snd_ctl_new()
638973 - [RHEL6 Snapshot 13]: The boot parameters 'nomodeset xforcevesa' is needed to install on Precision M4500 [rhel-6.0.z]
639412 - block: must prevent merges of discard and write requests [rhel-6.0.z]
639879 - CVE-2010-3698 kvm: invalid selector in fs/gs causes kernel panic
640036 - CVE-2010-3705 kernel: sctp memory corruption in HMAC handling
641258 - fix split_huge_page error like mapcount 3 page_mapcount 2 [rhel-6.0.z]
641454 - Output 'JBD: spotted dirty metadata buffer' message when usrquota is enabled [rhel-6.0.z]
641455 - [Intel 6.0 Bug] NPIV broken in SW FCoE [rhel-6.0.z]
641456 - [Intel 6.1 Bug] FCoE Boot ROM, unable to see LUN during system install thru NPV [rhel-6.0.z]
641457 - FCoE: Do not fall back to non-FIP FLOGI [rhel-6.0.z]
641458 - vmstat incorrectly reports disk IO as swap in [rhel-6.0.z]
641459 - Don't lose dirty bits leading to data corruption during KSM swapping [rhel-6.0.z]
641460 - KSM: fix page_address_in_vma anon_vma oops [rhel-6.0.z]
641483 - Stack size mapping is decreased through mlock/munlock call [rhel-6.0.z]
641907 - lpfc driver oops during rhel6 installation with snapshot 12/13 and emulex FC [rhel-6.0.z]
642043 - slow memory leak in i915 module on all intel hw [rhel-6.0.z]
642045 - major memory leak in radeon driver due when scrolling certain sites in firefox [rhel-6.0.z]
642465 - CVE-2010-2963 kernel: v4l: VIDIOCSMICROCODE arbitrary write
642679 - kernel BUG at mm/huge_memory.c:1279! [rhel-6.0.z]
642680 - XFS: accounting of reclaimable inodes is incorrect [rhel-6.0.z]
642896 - CVE-2010-3904 RDS sockets local privilege escalation
644037 - kernel BUG at mm/huge_memory.c:1267! - mapcount 5 page_mapcount 4 [rhel-6.0.z]
644038 - avoid crashes: backport hold mm->page_table_lock patch [rhel-6.0.z]
644636 - kernel wastes huge amounts of memory due to CONFIG_IMA [rhel-6.0.z]
644926 - calling elevator_change immediately after blk_init_queue results in a null pointer dereference [rhel-6.0.z]
646994 - Booting AMD Dinar system results in softlockups in ttm code [rhel-6.0.z]

6. Package List:

Red Hat Enterprise Linux Desktop (v. 6):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Client/en/os/SRPMS/kernel-2.6.32-71.7.1.el6.src.rpm

i386:
kernel-2.6.32-71.7.1.el6.i686.rpm
kernel-debug-2.6.32-71.7.1.el6.i686.rpm
kernel-debug-debuginfo-2.6.32-71.7.1.el6.i686.rpm
kernel-debug-devel-2.6.32-71.7.1.el6.i686.rpm
kernel-debuginfo-2.6.32-71.7.1.el6.i686.rpm
kernel-devel-2.6.32-71.7.1.el6.i686.rpm
kernel-headers-2.6.32-71.7.1.el6.i686.rpm

noarch:
kernel-doc-2.6.32-71.7.1.el6.noarch.rpm
kernel-firmware-2.6.32-71.7.1.el6.noarch.rpm
perf-2.6.32-71.7.1.el6.noarch.rpm

x86_64:
kernel-2.6.32-71.7.1.el6.x86_64.rpm
kernel-debug-2.6.32-71.7.1.el6.x86_64.rpm
kernel-debug-debuginfo-2.6.32-71.7.1.el6.x86_64.rpm
kernel-debug-devel-2.6.32-71.7.1.el6.x86_64.rpm
kernel-debuginfo-2.6.32-71.7.1.el6.x86_64.rpm
kernel-devel-2.6.32-71.7.1.el6.x86_64.rpm
kernel-headers-2.6.32-71.7.1.el6.x86_64.rpm

Red Hat Enterprise Linux HPC Node (v. 6):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6ComputeNode/en/os/SRPMS/kernel-2.6.32-71.7.1.el6.src.rpm

noarch:
kernel-doc-2.6.32-71.7.1.el6.noarch.rpm
kernel-firmware-2.6.32-71.7.1.el6.noarch.rpm
perf-2.6.32-71.7.1.el6.noarch.rpm

x86_64:
kernel-2.6.32-71.7.1.el6.x86_64.rpm
kernel-debug-2.6.32-71.7.1.el6.x86_64.rpm
kernel-debug-debuginfo-2.6.32-71.7.1.el6.x86_64.rpm
kernel-debug-devel-2.6.32-71.7.1.el6.x86_64.rpm
kernel-debuginfo-2.6.32-71.7.1.el6.x86_64.rpm
kernel-devel-2.6.32-71.7.1.el6.x86_64.rpm
kernel-headers-2.6.32-71.7.1.el6.x86_64.rpm

Red Hat Enterprise Linux Server (v. 6):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Server/en/os/SRPMS/kernel-2.6.32-71.7.1.el6.src.rpm

i386:
kernel-2.6.32-71.7.1.el6.i686.rpm
kernel-debug-2.6.32-71.7.1.el6.i686.rpm
kernel-debug-debuginfo-2.6.32-71.7.1.el6.i686.rpm
kernel-debug-devel-2.6.32-71.7.1.el6.i686.rpm
kernel-debuginfo-2.6.32-71.7.1.el6.i686.rpm
kernel-devel-2.6.32-71.7.1.el6.i686.rpm
kernel-headers-2.6.32-71.7.1.el6.i686.rpm

noarch:
kernel-doc-2.6.32-71.7.1.el6.noarch.rpm
kernel-firmware-2.6.32-71.7.1.el6.noarch.rpm
perf-2.6.32-71.7.1.el6.noarch.rpm

ppc64:
kernel-2.6.32-71.7.1.el6.ppc64.rpm
kernel-bootwrapper-2.6.32-71.7.1.el6.ppc64.rpm
kernel-debug-2.6.32-71.7.1.el6.ppc64.rpm
kernel-debug-debuginfo-2.6.32-71.7.1.el6.ppc64.rpm
kernel-debug-devel-2.6.32-71.7.1.el6.ppc64.rpm
kernel-debuginfo-2.6.32-71.7.1.el6.ppc64.rpm
kernel-devel-2.6.32-71.7.1.el6.ppc64.rpm
kernel-headers-2.6.32-71.7.1.el6.ppc64.rpm

s390x:
kernel-2.6.32-71.7.1.el6.s390x.rpm
kernel-debug-2.6.32-71.7.1.el6.s390x.rpm
kernel-debug-debuginfo-2.6.32-71.7.1.el6.s390x.rpm
kernel-debug-devel-2.6.32-71.7.1.el6.s390x.rpm
kernel-debuginfo-2.6.32-71.7.1.el6.s390x.rpm
kernel-devel-2.6.32-71.7.1.el6.s390x.rpm
kernel-headers-2.6.32-71.7.1.el6.s390x.rpm
kernel-kdump-2.6.32-71.7.1.el6.s390x.rpm
kernel-kdump-debuginfo-2.6.32-71.7.1.el6.s390x.rpm
kernel-kdump-devel-2.6.32-71.7.1.el6.s390x.rpm

x86_64:
kernel-2.6.32-71.7.1.el6.x86_64.rpm
kernel-debug-2.6.32-71.7.1.el6.x86_64.rpm
kernel-debug-debuginfo-2.6.32-71.7.1.el6.x86_64.rpm
kernel-debug-devel-2.6.32-71.7.1.el6.x86_64.rpm
kernel-debuginfo-2.6.32-71.7.1.el6.x86_64.rpm
kernel-devel-2.6.32-71.7.1.el6.x86_64.rpm
kernel-headers-2.6.32-71.7.1.el6.x86_64.rpm

Red Hat Enterprise Linux Workstation (v. 6):

Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Workstation/en/os/SRPMS/kernel-2.6.32-71.7.1.el6.src.rpm

i386:
kernel-2.6.32-71.7.1.el6.i686.rpm
kernel-debug-2.6.32-71.7.1.el6.i686.rpm
kernel-debug-debuginfo-2.6.32-71.7.1.el6.i686.rpm
kernel-debug-devel-2.6.32-71.7.1.el6.i686.rpm
kernel-debuginfo-2.6.32-71.7.1.el6.i686.rpm
kernel-devel-2.6.32-71.7.1.el6.i686.rpm
kernel-headers-2.6.32-71.7.1.el6.i686.rpm

noarch:
kernel-doc-2.6.32-71.7.1.el6.noarch.rpm
kernel-firmware-2.6.32-71.7.1.el6.noarch.rpm
perf-2.6.32-71.7.1.el6.noarch.rpm

x86_64:
kernel-2.6.32-71.7.1.el6.x86_64.rpm
kernel-debug-2.6.32-71.7.1.el6.x86_64.rpm
kernel-debug-debuginfo-2.6.32-71.7.1.el6.x86_64.rpm
kernel-debug-devel-2.6.32-71.7.1.el6.x86_64.rpm
kernel-debuginfo-2.6.32-71.7.1.el6.x86_64.rpm
kernel-devel-2.6.32-71.7.1.el6.x86_64.rpm
kernel-headers-2.6.32-71.7.1.el6.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and 
details on how to verify the signature are available from
https://www.redhat.com/security/team/key/#package

7. References:

https://www.redhat.com/security/data/cve/CVE-2010-2803.html
https://www.redhat.com/security/data/cve/CVE-2010-2955.html
https://www.redhat.com/security/data/cve/CVE-2010-2962.html
https://www.redhat.com/security/data/cve/CVE-2010-3079.html
https://www.redhat.com/security/data/cve/CVE-2010-3081.html
https://www.redhat.com/security/data/cve/CVE-2010-3084.html
https://www.redhat.com/security/data/cve/CVE-2010-3301.html
https://www.redhat.com/security/data/cve/CVE-2010-3432.html
https://www.redhat.com/security/data/cve/CVE-2010-3437.html
https://www.redhat.com/security/data/cve/CVE-2010-3442.html
https://www.redhat.com/security/data/cve/CVE-2010-3698.html
https://www.redhat.com/security/data/cve/CVE-2010-3705.html
https://www.redhat.com/security/data/cve/CVE-2010-3904.html
http://www.redhat.com/security/updates/classification/#important
http://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/6/html-single/Technical_Notes/index.html#RHSA-2010:0842

8. Contact:

The Red Hat security contact is <secalert at redhat.com>.  More contact
details at https://www.redhat.com/security/team/contact/

Copyright 2010 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (GNU/Linux)

iD8DBQFM2vIpXlSAg2UNWIIRAhP5AKC0brl5x5ea/40EJlXWeMsduhLJUQCdE8oY
pU9zeM5DaNHONahSCqnBcuQ=
=j8JK
-----END PGP SIGNATURE-----





More information about the Enterprise-watch-list mailing list