First published: Mon Aug 24 2009(Updated: )
The kernel packages contain the Linux kernel, the core of any Linux<br>operating system.<br>These updated packages fix the following security issues:<br><li> a flaw was found in the SOCKOPS_WRAP macro in the Linux kernel. This</li> macro did not initialize the sendpage operation in the proto_ops structure<br>correctly. A local, unprivileged user could use this flaw to cause a local<br>denial of service or escalate their privileges. (CVE-2009-2692, Important)<br><li> a flaw was found in the udp_sendmsg() implementation in the Linux kernel</li> when using the MSG_MORE flag on UDP sockets. A local, unprivileged user<br>could use this flaw to cause a local denial of service or escalate their<br>privileges. (CVE-2009-2698, Important)<br>Red Hat would like to thank Tavis Ormandy and Julien Tinnes of the Google<br>Security Team for responsibly reporting these flaws.<br>These updated packages also fix the following bug:<br><li> in the dlm code, a socket was allocated in tcp_connect_to_sock(), but was</li> not freed in the error exit path. This bug led to a memory leak and an<br>unresponsive system. A reported case of this bug occurred after running<br>"cman_tool kill -n [nodename]". (BZ#515432)<br>Users should upgrade to these updated packages, which contain backported<br>patches to correct these issues. The system must be rebooted for this<br>update to take effect.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel | <2.6.18-128.7.1.el5 | 2.6.18-128.7.1.el5 |
redhat/kernel | <2.6.18-128.7.1.el5 | 2.6.18-128.7.1.el5 |
redhat/kernel-debug | <2.6.18-128.7.1.el5 | 2.6.18-128.7.1.el5 |
redhat/kernel-debug-devel | <2.6.18-128.7.1.el5 | 2.6.18-128.7.1.el5 |
redhat/kernel-devel | <2.6.18-128.7.1.el5 | 2.6.18-128.7.1.el5 |
redhat/kernel-doc | <2.6.18-128.7.1.el5 | 2.6.18-128.7.1.el5 |
redhat/kernel-headers | <2.6.18-128.7.1.el5 | 2.6.18-128.7.1.el5 |
redhat/kernel-xen | <2.6.18-128.7.1.el5 | 2.6.18-128.7.1.el5 |
redhat/kernel-xen-devel | <2.6.18-128.7.1.el5 | 2.6.18-128.7.1.el5 |
redhat/kernel-debug | <2.6.18-128.7.1.el5 | 2.6.18-128.7.1.el5 |
redhat/kernel-debug-devel | <2.6.18-128.7.1.el5 | 2.6.18-128.7.1.el5 |
redhat/kernel-devel | <2.6.18-128.7.1.el5 | 2.6.18-128.7.1.el5 |
redhat/kernel-headers | <2.6.18-128.7.1.el5 | 2.6.18-128.7.1.el5 |
redhat/kernel-xen | <2.6.18-128.7.1.el5 | 2.6.18-128.7.1.el5 |
redhat/kernel-xen-devel | <2.6.18-128.7.1.el5 | 2.6.18-128.7.1.el5 |
redhat/kernel-kdump | <2.6.18-128.7.1.el5 | 2.6.18-128.7.1.el5 |
redhat/kernel-kdump-devel | <2.6.18-128.7.1.el5 | 2.6.18-128.7.1.el5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.