RHSA-2009:1233: Important: kernel security update
The kernel packages contain the Linux kernel, the core of any Linuxoperating system.These updated packages fix the following security issues: a flaw was found in the SOCKOPSWRAP macro in the Linux kernel. This macro did not initialize the sendpage operation in the protoops structurecorrectly. A local, unprivileged user could use this flaw to cause a localdenial of service or escalate their privileges. (CVE-2009-2692, Important) a flaw was found in the udpsendmsg() implementation in the Linux kernel when using the MSGMORE flag on UDP sockets. A local, unprivileged usercould use this flaw to cause a local denial of service or escalate theirprivileges. (CVE-2009-2698, Important)Red Hat would like to thank Tavis Ormandy and Julien Tinnes of the GoogleSecurity Team for responsibly reporting these flaws.All Red Hat Enterprise Linux 3 users should upgrade to these updatedpackages, which contain backported patches to resolve these issues. Thesystem must be rebooted for this update to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2009:1233?
The severity of RHSA-2009:1233 is classified as important.
How do I fix RHSA-2009:1233?
To fix RHSA-2009:1233, you should update your kernel packages to the latest version provided by your Linux distribution.
What systems are affected by RHSA-2009:1233?
RHSA-2009:1233 affects various systems running an affected version of the Linux kernel.
What vulnerabilities are addressed in RHSA-2009:1233?
RHSA-2009:1233 addresses a flaw in the SOCKOPS_WRAP macro related to the sendpage operation in the Linux kernel.
Is there a risk of exploitation for RHSA-2009:1233?
Yes, if not patched, the vulnerabilities fixed in RHSA-2009:1233 could potentially be exploited by attackers.