RHSA-2010:0046: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linuxoperating system.Security fixes: an array index error was found in the gdth driver. A local user could send a specially-crafted IOCTL request that would cause a denial of serviceor, possibly, privilege escalation. (CVE-2009-3080, Important) a flaw was found in the FUSE implementation. When a system is low on memory, fuseputrequest() could dereference an invalid pointer, possiblyleading to a local denial of service or privilege escalation.(CVE-2009-4021, Important) Tavis Ormandy discovered a deficiency in the fasynchelper() implementation. This could allow a local, unprivileged user to leverage ause-after-free of locked, asynchronous file descriptors to cause a denialof service or privilege escalation. (CVE-2009-4141, Important) the Parallels Virtuozzo Containers team reported the RHSA-2009:1243 update introduced two flaws in the routing implementation. If an attackerwas able to cause a large enough number of collisions in the routing hashtable (via specially-crafted packets) for the emergency route flush totrigger, a deadlock could occur. Secondly, if the kernel routing cache wasdisabled, an uninitialized pointer would be left behind after a routelookup, leading to a kernel panic. (CVE-2009-4272, Important) the RHSA-2009:0225 update introduced a rewrite attack flaw in the docoredump() function. A local attacker able to guess the file name aprocess is going to dump its core to, prior to the process crashing, coulduse this flaw to append data to the dumped core file. This issue onlyaffects systems that have "/proc/sys/fs/suiddumpable" set to 2 (thedefault value is 0). (CVE-2006-6304, Moderate)The fix for CVE-2006-6304 changes the expected behavior: With suiddumpableset to 2, the core file will not be recorded if the file already exists.For example, core files will not be overwritten on subsequent crashes ofprocesses whose core files map to the same name. an information leak was found in the Linux kernel. On AMD64 systems, 32-bit processes could access and read certain 64-bit registers bytemporarily switching themselves to 64-bit mode. (CVE-2009-2910, Moderate) the RHBA-2008:0314 update introduced NPort ID Virtualization (NPIV) support in the qla2xxx driver, resulting in two new sysfs pseudo files,"/sys/class/scsihost/[a qla2xxx host]/vportcreate" and "vportdelete".These two files were world-writable by default, allowing a local user tochange SCSI host attributes. This flaw only affects systems using theqla2xxx driver and NPIV capable hardware. (CVE-2009-3556, Moderate) permission issues were found in the megaraidsas driver. The "dbglvl" and "pollmodeio" files on the sysfs file system ("/sys/") hadworld-writable permissions. This could allow local, unprivileged users tochange the behavior of the driver. (CVE-2009-3889, CVE-2009-3939, Moderate) a NULL pointer dereference flaw was found in the firewire-ohci driver used for OHCI compliant IEEE 1394 controllers. A local, unprivileged userwith access to /dev/fw files could issue certain IOCTL calls, causing adenial of service or privilege escalation. The FireWire modules areblacklisted by default, and if enabled, only root has access to the filesnoted above by default. (CVE-2009-4138, Moderate) a buffer overflow flaw was found in the hfsbnoderead() function in the HFS file system implementation. This could lead to a denial of service if auser browsed a specially-crafted HFS file system, for example, by running"ls". (CVE-2009-4020, Low)Bug fix documentation for this update will be available shortly fromwww.redhat.com/docs/en-US/errata/RHSA-2010-0046/KernelSecurityUpdate/index.htmlUsers should upgrade to these updated packages, which contain backportedpatches to correct these issues. The system must be rebooted for thisupdate to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2010:0046?
The severity of RHSA-2010:0046 is classified as important due to potential denial of service vulnerabilities.
How do I fix RHSA-2010:0046?
To fix RHSA-2010:0046, you should upgrade the kernel packages to version 2.6.18-164.11.1.el5 or later.
Which systems are affected by RHSA-2010:0046?
RHSA-2010:0046 affects Red Hat Enterprise Linux 5 systems utilizing the specified kernel packages.
What vulnerabilities are addressed in RHSA-2010:0046?
RHSA-2010:0046 addresses an array index error in the gdth driver that could lead to denial of service.
Is there a workaround for RHSA-2010:0046?
There are no specific workarounds listed for RHSA-2010:0046, upgrading is recommended for protection.