RHSA-2010:0631: Important: kernel-rt security and bug fix update
These packages contain the Linux kernel, the core of any Linux operatingsystem.Security fixes: unsafe sprintf() use in the Bluetooth implementation. Creating a large number of Bluetooth L2CAP, SCO, or RFCOMM sockets could result in arbitrarymemory pages being overwritten, allowing a local, unprivileged user tocause a denial of service or escalate their privileges. (CVE-2010-1084,Important) a flaw in the Unidirectional Lightweight Encapsulation implementation, allowing a remote attacker to send a specially-crafted ISO MPEG-2 TransportStream frame to a target system, resulting in a denial of service.(CVE-2010-1086, Important) NULL pointer dereference in nfswbpagecancel(), allowing a local user on a system that has an NFS-mounted file system to cause a denial ofservice or escalate their privileges on that system. (CVE-2010-1087,Important) flaw in sctpprocessunkparam(), allowing a remote attacker to send a specially-crafted SCTP packet to an SCTP listening port on a target system,causing a denial of service. (CVE-2010-1173, Important) race condition between finding a keyring by name and destroying a freed keyring in the key management facility, allowing a local, unprivilegeduser to cause a denial of service or escalate their privileges.(CVE-2010-1437, Important) systems using the kernel NFS server to export a shared memory file system and that have the sysctl overcommitmemory variable set to never overcommit(a value of 2; by default, it is set to 0), may experience a NULL pointerdereference, allowing a local, unprivileged user to cause a denial ofservice or escalate their privileges. (CVE-2008-7256, CVE-2010-1643,Important) when an application has a stack overflow, the stack could silently overwrite another memory mapped area instead of a segmentation faultoccurring, which could cause an application to execute arbitrary code.(CVE-2010-2240, Important) flaw in CIFSSMBWrite() could allow a remote attacker to send a specially-crafted SMB response packet to a target CIFS client, resulting ina denial of service. (CVE-2010-2248, Important) buffer overflow flaws in the kernel's implementation of the server-side XDR for NFSv4 could allow an attacker on the local network to send aspecially-crafted large compound request to the NFSv4 server, possiblyresulting in a denial of service or code execution. (CVE-2010-2521,Important) NULL pointer dereference in the firewire-ohci driver used for OHCI compliant IEEE 1394 controllers could allow a local, unprivileged user withaccess to /dev/fw files to issue certain IOCTL calls, causing a denial ofservice or privilege escalation. The FireWire modules are blacklisted bydefault. If enabled, only root has access to the files noted above bydefault. (CVE-2009-4138, Moderate) flaw in the linkpathwalk() function. Using the file descriptor returned by open() with the ONOFOLLOW flag on a subordinate NFS-mountedfile system, could result in a NULL pointer dereference, causing a denialof service or privilege escalation. (CVE-2010-1088, Moderate) memory leak in releaseonetty() could allow a local, unprivileged user to cause a denial of service. (CVE-2010-1162, Moderate) information leak in the USB implementation. Certain USB errors could result in an uninitialized kernel buffer being sent to user-space. Anattacker with physical access to a target system could use this flaw tocause an information leak. (CVE-2010-1083, Low)Red Hat would like to thank Neil Brown for reporting CVE-2010-1084; Ang WayChuang for reporting CVE-2010-1086; Jukka Taimisto and Olli Jarva ofCodenomicon Ltd, Nokia Siemens Networks, and Wind River on behalf of theircustomer, for responsibly reporting CVE-2010-1173; the X.Org security teamfor reporting CVE-2010-2240, with upstream acknowledging Rafal Wojtczuk asthe original reporter; and Marcus Meissner for reporting CVE-2010-1083.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2010:0631?
The severity of RHSA-2010:0631 is considered important due to the potential for arbitrary memory access through unsafe sprintf() usage in Bluetooth.
How do I fix RHSA-2010:0631?
To fix RHSA-2010:0631, you should apply the updated Linux kernel packages provided in the security advisory.
What vulnerabilities does RHSA-2010:0631 address?
RHSA-2010:0631 addresses a vulnerability related to unsafe handling of Bluetooth socket connections.
Which systems are affected by RHSA-2010:0631?
RHSA-2010:0631 affects systems running vulnerable versions of the Linux kernel that implement Bluetooth functionality.
Is there a workaround for RHSA-2010:0631?
There are no known workarounds for RHSA-2010:0631; the only solution is to update the affected kernel.