RHSA-2009:1223: Important: kernel security update
The kernel packages contain the Linux kernel, the core of any Linuxoperating system.These updated packages fix the following security issues: a flaw was found in the SOCKOPSWRAP macro in the Linux kernel. This macro did not initialize the sendpage operation in the protoops structurecorrectly. A local, unprivileged user could use this flaw to cause a localdenial of service or escalate their privileges. (CVE-2009-2692, Important) a flaw was found in the udpsendmsg() implementation in the Linux kernel when using the MSGMORE flag on UDP sockets. A local, unprivileged usercould use this flaw to cause a local denial of service or escalate theirprivileges. (CVE-2009-2698, Important)Red Hat would like to thank Tavis Ormandy and Julien Tinnes of the GoogleSecurity Team for responsibly reporting these flaws.Users should upgrade to these updated packages, which contain backportedpatches to correct these issues. The system must be rebooted for thisupdate to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2009:1223?
The severity of RHSA-2009:1223 is classified as important due to security vulnerabilities present in the Linux kernel.
How do I fix RHSA-2009:1223?
To fix RHSA-2009:1223, update your Linux kernel packages to the latest versions provided by Red Hat.
What vulnerabilities are addressed in RHSA-2009:1223?
RHSA-2009:1223 addresses security vulnerabilities related to flaws in the SOCKOPS_WRAP macro in the Linux kernel.
Which systems are affected by RHSA-2009:1223?
RHSA-2009:1223 affects systems running the impacted versions of the Linux kernel as specified by Red Hat.
Is being vulnerable to RHSA-2009:1223 a risk to my system?
Yes, being vulnerable to RHSA-2009:1223 can expose your system to potential security threats and exploits.