RHSA-2009:1469: Important: kernel security update
The kernel packages contain the Linux kernel, the core of any Linuxoperating system.This update fixes the following security issues: Michael Tokarev reported a flaw in the Realtek r8169 Ethernet driver in the Linux kernel. This driver allowed interfaces using this driver toreceive frames larger than what could be handled. This could lead to aremote denial of service or code execution. (CVE-2009-1389, Important) Tavis Ormandy and Julien Tinnes of the Google Security Team reported a flaw in the SOCKOPSWRAP macro in the Linux kernel. This macro did notinitialize the sendpage operation in the protoops structure correctly. Alocal, unprivileged user could use this flaw to cause a local denial ofservice or escalate their privileges. (CVE-2009-2692, Important) Tavis Ormandy and Julien Tinnes of the Google Security Team reported a flaw in the udpsendmsg() implementation in the Linux kernel when using theMSGMORE flag on UDP sockets. A local, unprivileged user could use thisflaw to cause a local denial of service or escalate their privileges.(CVE-2009-2698, Important)Users should upgrade to these updated packages, which contain backportedpatches to correct these issues. The system must be rebooted for thisupdate to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2009:1469?
The severity of RHSA-2009:1469 is classified as important.
How do I fix RHSA-2009:1469?
You can fix RHSA-2009:1469 by updating the kernel packages to the latest version provided by your Linux distribution.
What vulnerabilities are addressed in RHSA-2009:1469?
RHSA-2009:1469 addresses a flaw in the Realtek r8169 Ethernet driver that could lead to security risks.
Is my system affected by RHSA-2009:1469?
Systems using the affected Realtek r8169 Ethernet driver in their Linux kernel could be vulnerable as per RHSA-2009:1469.
When was RHSA-2009:1469 released?
RHSA-2009:1469 was released in October 2009.