RHSA-2010:0041: Important: kernel-rt security and bug fix update

Published Jan 21, 2010
·
Updated

The kernel-rt packages contain the Linux kernel, the core of any Linuxoperating system.This update fixes the following security issues: an array index error was found in the gdth driver in the Linux kernel. A local user could send a specially-crafted IOCTL request that would cause adenial of service or, possibly, privilege escalation. (CVE-2009-3080,Important) a flaw was found in the FUSE implementation in the Linux kernel. When a system is low on memory, fuseputrequest() could dereference an invalidpointer, possibly leading to a local denial of service or privilegeescalation. (CVE-2009-4021, Important) a flaw was found in each of the following Intel PRO/1000 Linux drivers in the Linux kernel: e1000 and e1000e. A remote attacker using packets largerthan the MTU could bypass the existing fragment check, resulting inpartial, invalid frames being passed to the network stack. These flawscould also possibly be used to trigger a remote denial of service.(CVE-2009-4536, CVE-2009-4538, Important) a flaw was found in the Realtek r8169 Ethernet driver in the Linux kernel. Receiving overly-long frames with a certain revision of the networkcards supported by this driver could possibly result in a remote denial ofservice. (CVE-2009-4537, Important)This update also fixes the following bugs: the "function tracer" from ftrace could eventually present problems when a module was unloaded during a tracing session. Some of the related callsite entries for that module were not removed from ftrace's internal listsand could lead to confusing "oops" error messages. The call site entriesare now removed correctly, and the errors no longer occur. (BZ#537472) when using the kernel in tickless (or NOHZ) mode, time was not accumulated one tick at a time. This created latencies when the accumulatedinterval grew large. Time is now accumulated logarithmically and latenciesrelated to tickless mode no longer occur. (BZ#538370) running the "cset set" command was resulting in unsafe access to a structure that could be concurrently changed. This was eventually causingthe kernel to crash. The operations were repositioned so that they nolonger add locks, to minimize performance penalties. (BZ#541080) the function used to calculate system load called different functions to count the tasks in running and interpretable states. On systems with alarge number of CPUs, this could result in several TLB and cache misses.These functions have now been combined, and the problem has beensignificantly reduced. (BZ#552860) when legacy PCI bus checks occurred, an off-by-one error would present. Scanning 255 PCI buses is now allowed as 0xff is a valid bus, and the errorno longer occurs. (BZ#552874) on systems with 8 or more CPUs, an unnecessary anonvma lock acquisition in vmaadjust() was causing a decrease in throughput. Code from theupstream kernel was backported, and the throughput decrease no longerexists. (BZ#552876) the scheduler function doublelockbalance() favors logically lower CPUs. This could cause logically higher CPUs to be starved if run queues wereunder a lot of pressure, resulting in latencies. The algorithm has beenadjusted so that it is fairer, and logically higher CPUs no longer riskbeing starved. (BZ#552877)These updated packages also include other bug fixes. Users are directed tothe Red Hat Enterprise MRG 1.2 Release Notes for information on thosefixes, available shortly from:http://www.redhat.com/docs/en-US/RedHatEnterpriseMRG/ Users should upgrade to these updated packages, which contain backportedpatches to correct these issues. The system must be rebooted for thisupdate to take effect.

Affected Software

1 affected component
Linux kernel-rt

Remediation

Event History

Jan 21, 2010
Advisory Published
12:00 AM
Data Sourced
12:00 AM
RemedyDescriptionAffected Software

Frequently Asked Questions

1

What is the severity of RHSA-2010:0041?

RHSA-2010:0041 is considered a moderate security update.

2

How do I fix RHSA-2010:0041?

To fix RHSA-2010:0041, update the kernel-rt packages to the latest version provided by your distribution.

3

What security issues are addressed in RHSA-2010:0041?

RHSA-2010:0041 addresses an array index error found in the gdth driver within the Linux kernel.

4

Who is affected by RHSA-2010:0041?

Local users utilizing the affected kernel-rt packages may be impacted by the vulnerabilities described in RHSA-2010:0041.

5

Is there a workaround for RHSA-2010:0041?

There are no official workarounds for RHSA-2010:0041, so the recommended action is to apply the security update.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203