RHSA-2009:1522: Moderate: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linuxoperating system.This update fixes the following security issues: multiple, missing initialization flaws were found in the Linux kernel. Padding data in several core network structures was not initializedproperly before being sent to user-space. These flaws could lead toinformation leaks. (CVE-2005-4881, CVE-2009-3228, Moderate)This update also fixes the following bugs: a packet duplication issue was fixed via the RHSA-2008:0665 update; however, the fix introduced a problem for systems using network bonding:Backup slaves were unable to receive ARP packets. When using networkbonding in the "active-backup" mode and with the "arpvalidate=3" option,the bonding driver considered such backup slaves as being down (since theywere not receiving ARP packets), preventing successful failover to thesedevices. (BZ#519384) due to insufficient memory barriers in the network code, a process sleeping in select() may have missed notifications about new data. In rarecases, this bug may have caused a process to sleep forever. (BZ#519386) the driver version number in the atapiix driver was not changed between Red Hat Enterprise Linux 4.7 and Red Hat Enterprise Linux 4.8, even thoughchanges had been made between these releases. This could have prevented thedriver from loading on systems that check driver versions, as this driverappeared older than it was. (BZ#519389) a bug in nlmlookuphost() could have led to un-reclaimed locks on file systems, resulting in the umount command failing. This bug could have alsoprevented NFS services from being relocated correctly in clusteredenvironments. (BZ#519656) the data buffer ethtoolgetstrings() allocated, for the igb driver, was smaller than the amount of data that was copied in igbgetstrings(),because of a miscalculation in IGBQUEUESTATSLEN, resulting in memorycorruption. This bug could have led to a kernel panic. (BZ#522738) in some situations, write operations to a TTY device were blocked even when the ONONBLOCK flag was used. A reported case of this issue occurredwhen a single TTY device was opened by two users (one using blocking mode,and the other using non-blocking mode). (BZ#523930) a deadlock was found in the cciss driver. In rare cases, this caused an NMI lockup during boot. Messages such as "cciss: controller cciss[x]failed, stopping." and "cciss[x]: controller not responding." may havebeen displayed on the console. (BZ#525725) on 64-bit PowerPC systems, a rollover bug in the ibmveth driver could have caused a kernel panic. In a reported case, this panic occurred on asystem with a large uptime and under heavy network load. (BZ#527225)Users should upgrade to these updated packages, which contain backportedpatches to correct these issues. The system must be rebooted for thisupdate to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2009:1522?
RHSA-2009:1522 is classified as a moderate severity vulnerability affecting the Linux kernel.
How do I fix RHSA-2009:1522?
To fix RHSA-2009:1522, update your Linux kernel package to the latest version provided by your distribution.
What are the main issues addressed in RHSA-2009:1522?
RHSA-2009:1522 addresses multiple missing initialization flaws in the Linux kernel that could lead to potential security vulnerabilities.
Which systems are affected by RHSA-2009:1522?
Systems running vulnerable versions of the Linux kernel are affected by RHSA-2009:1522.
Is RHSA-2009:1522 related to any specific Linux distributions?
RHSA-2009:1522 specifically pertains to Red Hat Enterprise Linux and its derivatives.