RHSA-2009:1222: Important: kernel security and bug fix update

Published Aug 24, 2009
·
Updated

The kernel packages contain the Linux kernel, the core of any Linuxoperating system.These updated packages fix the following security issues: a flaw was found in the SOCKOPSWRAP macro in the Linux kernel. This macro did not initialize the sendpage operation in the protoops structurecorrectly. A local, unprivileged user could use this flaw to cause a localdenial of service or escalate their privileges. (CVE-2009-2692, Important) a flaw was found in the udpsendmsg() implementation in the Linux kernel when using the MSGMORE flag on UDP sockets. A local, unprivileged usercould use this flaw to cause a local denial of service or escalate theirprivileges. (CVE-2009-2698, Important)Red Hat would like to thank Tavis Ormandy and Julien Tinnes of the GoogleSecurity Team for responsibly reporting these flaws.These updated packages also fix the following bug: in the dlm code, a socket was allocated in tcpconnecttosock(), but was not freed in the error exit path. This bug led to a memory leak and anunresponsive system. A reported case of this bug occurred after running"cmantool kill -n [nodename]". (BZ#515432)Users should upgrade to these updated packages, which contain backportedpatches to correct these issues. The system must be rebooted for thisupdate to take effect.

Affected Software

17 affected componentsFixes available
redhat/kernel<2.6.18-128.7.1.el5
2.6.18-128.7.1.el5
redhat/kernel<2.6.18-128.7.1.el5
2.6.18-128.7.1.el5
redhat/kernel-debug<2.6.18-128.7.1.el5
2.6.18-128.7.1.el5
redhat/kernel-debug-devel<2.6.18-128.7.1.el5
2.6.18-128.7.1.el5
redhat/kernel-devel<2.6.18-128.7.1.el5
2.6.18-128.7.1.el5
redhat/kernel-doc<2.6.18-128.7.1.el5
2.6.18-128.7.1.el5
redhat/kernel-headers<2.6.18-128.7.1.el5
2.6.18-128.7.1.el5
redhat/kernel-xen<2.6.18-128.7.1.el5
2.6.18-128.7.1.el5
redhat/kernel-xen-devel<2.6.18-128.7.1.el5
2.6.18-128.7.1.el5
redhat/kernel-debug<2.6.18-128.7.1.el5
2.6.18-128.7.1.el5
redhat/kernel-debug-devel<2.6.18-128.7.1.el5
2.6.18-128.7.1.el5
redhat/kernel-devel<2.6.18-128.7.1.el5
2.6.18-128.7.1.el5
redhat/kernel-headers<2.6.18-128.7.1.el5
2.6.18-128.7.1.el5
redhat/kernel-xen<2.6.18-128.7.1.el5
2.6.18-128.7.1.el5
redhat/kernel-xen-devel<2.6.18-128.7.1.el5
2.6.18-128.7.1.el5
redhat/kernel-kdump<2.6.18-128.7.1.el5
2.6.18-128.7.1.el5
redhat/kernel-kdump-devel<2.6.18-128.7.1.el5
2.6.18-128.7.1.el5

Remediation

Event History

Aug 24, 2009
Advisory Published
via Red Hat·12:00 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2009:1222?

The severity of RHSA-2009:1222 is categorized as critical due to security vulnerabilities present in the Linux kernel.

2

How do I fix RHSA-2009:1222?

To fix RHSA-2009:1222, you should update the kernel packages to version 2.6.18-128.7.1.el5.

3

Which systems are affected by RHSA-2009:1222?

RHSA-2009:1222 affects systems running the Red Hat Enterprise Linux 5 kernel packages.

4

What are the main security issues addressed in RHSA-2009:1222?

RHSA-2009:1222 addresses vulnerabilities related to the SOCKOPS_WRAP macro and its improper initialization.

5

Is it necessary to reboot the system after applying the fix for RHSA-2009:1222?

Yes, a system reboot is typically required to fully apply the kernel update and mitigate the vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203