RHSA-2010:0046: Important: kernel security and bug fix update

Published Jan 19, 2010
·
Updated

The kernel packages contain the Linux kernel, the core of any Linuxoperating system.Security fixes: an array index error was found in the gdth driver. A local user could send a specially-crafted IOCTL request that would cause a denial of serviceor, possibly, privilege escalation. (CVE-2009-3080, Important) a flaw was found in the FUSE implementation. When a system is low on memory, fuseputrequest() could dereference an invalid pointer, possiblyleading to a local denial of service or privilege escalation.(CVE-2009-4021, Important) Tavis Ormandy discovered a deficiency in the fasynchelper() implementation. This could allow a local, unprivileged user to leverage ause-after-free of locked, asynchronous file descriptors to cause a denialof service or privilege escalation. (CVE-2009-4141, Important) the Parallels Virtuozzo Containers team reported the RHSA-2009:1243 update introduced two flaws in the routing implementation. If an attackerwas able to cause a large enough number of collisions in the routing hashtable (via specially-crafted packets) for the emergency route flush totrigger, a deadlock could occur. Secondly, if the kernel routing cache wasdisabled, an uninitialized pointer would be left behind after a routelookup, leading to a kernel panic. (CVE-2009-4272, Important) the RHSA-2009:0225 update introduced a rewrite attack flaw in the docoredump() function. A local attacker able to guess the file name aprocess is going to dump its core to, prior to the process crashing, coulduse this flaw to append data to the dumped core file. This issue onlyaffects systems that have "/proc/sys/fs/suiddumpable" set to 2 (thedefault value is 0). (CVE-2006-6304, Moderate)The fix for CVE-2006-6304 changes the expected behavior: With suiddumpableset to 2, the core file will not be recorded if the file already exists.For example, core files will not be overwritten on subsequent crashes ofprocesses whose core files map to the same name. an information leak was found in the Linux kernel. On AMD64 systems, 32-bit processes could access and read certain 64-bit registers bytemporarily switching themselves to 64-bit mode. (CVE-2009-2910, Moderate) the RHBA-2008:0314 update introduced NPort ID Virtualization (NPIV) support in the qla2xxx driver, resulting in two new sysfs pseudo files,"/sys/class/scsihost/[a qla2xxx host]/vportcreate" and "vportdelete".These two files were world-writable by default, allowing a local user tochange SCSI host attributes. This flaw only affects systems using theqla2xxx driver and NPIV capable hardware. (CVE-2009-3556, Moderate) permission issues were found in the megaraidsas driver. The "dbglvl" and "pollmodeio" files on the sysfs file system ("/sys/") hadworld-writable permissions. This could allow local, unprivileged users tochange the behavior of the driver. (CVE-2009-3889, CVE-2009-3939, Moderate) a NULL pointer dereference flaw was found in the firewire-ohci driver used for OHCI compliant IEEE 1394 controllers. A local, unprivileged userwith access to /dev/fw files could issue certain IOCTL calls, causing adenial of service or privilege escalation. The FireWire modules areblacklisted by default, and if enabled, only root has access to the filesnoted above by default. (CVE-2009-4138, Moderate) a buffer overflow flaw was found in the hfsbnoderead() function in the HFS file system implementation. This could lead to a denial of service if auser browsed a specially-crafted HFS file system, for example, by running"ls". (CVE-2009-4020, Low)Bug fix documentation for this update will be available shortly fromwww.redhat.com/docs/en-US/errata/RHSA-2010-0046/KernelSecurityUpdate/index.htmlUsers should upgrade to these updated packages, which contain backportedpatches to correct these issues. The system must be rebooted for thisupdate to take effect.

Affected Software

17 affected componentsFixes available
redhat/kernel<2.6.18-164.11.1.el5
2.6.18-164.11.1.el5
redhat/kernel<2.6.18-164.11.1.el5
2.6.18-164.11.1.el5
redhat/kernel-debug<2.6.18-164.11.1.el5
2.6.18-164.11.1.el5
redhat/kernel-debug-devel<2.6.18-164.11.1.el5
2.6.18-164.11.1.el5
redhat/kernel-devel<2.6.18-164.11.1.el5
2.6.18-164.11.1.el5
redhat/kernel-doc<2.6.18-164.11.1.el5
2.6.18-164.11.1.el5
redhat/kernel-headers<2.6.18-164.11.1.el5
2.6.18-164.11.1.el5
redhat/kernel-xen<2.6.18-164.11.1.el5
2.6.18-164.11.1.el5
redhat/kernel-xen-devel<2.6.18-164.11.1.el5
2.6.18-164.11.1.el5
redhat/kernel-debug<2.6.18-164.11.1.el5
2.6.18-164.11.1.el5
redhat/kernel-debug-devel<2.6.18-164.11.1.el5
2.6.18-164.11.1.el5
redhat/kernel-devel<2.6.18-164.11.1.el5
2.6.18-164.11.1.el5
redhat/kernel-headers<2.6.18-164.11.1.el5
2.6.18-164.11.1.el5
redhat/kernel-xen<2.6.18-164.11.1.el5
2.6.18-164.11.1.el5
redhat/kernel-xen-devel<2.6.18-164.11.1.el5
2.6.18-164.11.1.el5
redhat/kernel-kdump<2.6.18-164.11.1.el5
2.6.18-164.11.1.el5
redhat/kernel-kdump-devel<2.6.18-164.11.1.el5
2.6.18-164.11.1.el5

Remediation

Event History

Jan 19, 2010
Advisory Published
via Red Hat·12:00 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2010:0046?

The severity of RHSA-2010:0046 is classified as important due to potential denial of service vulnerabilities.

2

How do I fix RHSA-2010:0046?

To fix RHSA-2010:0046, you should upgrade the kernel packages to version 2.6.18-164.11.1.el5 or later.

3

Which systems are affected by RHSA-2010:0046?

RHSA-2010:0046 affects Red Hat Enterprise Linux 5 systems utilizing the specified kernel packages.

4

What vulnerabilities are addressed in RHSA-2010:0046?

RHSA-2010:0046 addresses an array index error in the gdth driver that could lead to denial of service.

5

Is there a workaround for RHSA-2010:0046?

There are no specific workarounds listed for RHSA-2010:0046, upgrading is recommended for protection.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203