RHSA-2010:0958: Important: kernel-rt security and bug fix update
The kernel-rt packages contain the Linux kernel, the core of any Linuxoperating system.Security fixes: Missing sanity checks in the Intel i915 driver in the Linux kernel could allow a local, unprivileged user to escalate their privileges.(CVE-2010-2962, Important) A flaw in sctppacketconfig() in the Linux kernel's Stream Control Transmission Protocol (SCTP) implementation could allow a remote attackerto cause a denial of service. (CVE-2010-3432, Important) A missing integer overflow check in sndctlnew() in the Linux kernel's sound subsystem could allow a local, unprivileged user on a 32-bit systemto cause a denial of service or escalate their privileges. (CVE-2010-3442,Important) A flaw in sctpauthasocgethmac() in the Linux kernel's SCTP implementation. When iterating through the hmacids array, it did not resetthe last id element if it was out of range. This could allow a remoteattacker to cause a denial of service. (CVE-2010-3705, Important) Missing sanity checks in setupargpages() in the Linux kernel. When making the size of the argument and environment area on the stack verylarge, it could trigger a BUGON(), resulting in a local denial of service.(CVE-2010-3858, Moderate) A flaw in ethtoolgetrxnfc() in the Linux kernel's ethtool IOCTL handler. When it is called with a large info.rulecnt, it could allow alocal user to cause an information leak. (CVE-2010-3861, Moderate) A flaw in bcmconnect() in the Linux kernel's Controller Area Network (CAN) Broadcast Manager. On 64-bit systems, writing the socket address mayoverflow the procname character array. (CVE-2010-3874, Moderate) A flaw in inetcskdiagdump() in the Linux kernel's module for monitoring the sockets of INET transport protocols. By sending a netlinkmessage with certain bytecode, a local, unprivileged user could cause adenial of service. (CVE-2010-3880, Moderate) Missing sanity checks in gdthioctlalloc() in the gdth driver in the Linux kernel, could allow a local user with access to "/dev/gdth" on a64-bit system to cause a denial of service or escalate their privileges.(CVE-2010-4157, Moderate) A use-after-free flaw in the mprotect() system call could allow a local, unprivileged user to cause a local denial of service. (CVE-2010-4169,Moderate) Missing initialization flaws in the Linux kernel could lead to information leaks. (CVE-2010-3876, CVE-2010-4072, CVE-2010-4073,CVE-2010-4074, CVE-2010-4075, CVE-2010-4077, CVE-2010-4079, CVE-2010-4080,CVE-2010-4082, CVE-2010-4083, CVE-2010-4158, Low)Red Hat would like to thank Kees Cook for reporting CVE-2010-2962,CVE-2010-3861, and CVE-2010-4072; Dan Rosenberg for reportingCVE-2010-3442, CVE-2010-3705, CVE-2010-3874, CVE-2010-4073, CVE-2010-4074,CVE-2010-4075, CVE-2010-4077, CVE-2010-4079, CVE-2010-4080, CVE-2010-4082,CVE-2010-4083, and CVE-2010-4158; Brad Spengler for reportingCVE-2010-3858; Nelson Elhage for reporting CVE-2010-3880; and VasiliyKulikov for reporting CVE-2010-3876.Bug fixes: A vulnerability in the 32-bit compatibility code for the VIDIOCSMICROCODE IOCTL in the Video4Linux implementation. It does not affect Red HatEnterprise MRG, but as a preventive measure, this update removes the code.Red Hat would like to thank Kees Cook for reporting this vulnerability.(BZ#642469) The kernel-rt spec file was missing the crypto, drm, generated, and trace header directories when generating the kernel-rt-devel package, resultingin out-of-tree modules failing to build. (BZ#608784) On computers without a supported Performance Monitoring Unit, a crash would occur when running the "perf top" command, and occasionally otherperf commands. perf software events are now marked as IRQ safe to avoidthis crash. (BZ#647434)Users should upgrade to these updated packages, which contain backportedpatches to correct these issues. The system must be rebooted for thisupdate to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2010:0958?
The severity of RHSA-2010:0958 is classified as moderate due to potential privilege escalation risks.
How do I fix RHSA-2010:0958?
To fix RHSA-2010:0958, you should update the kernel-rt packages to the latest version released by Red Hat.
Who is affected by RHSA-2010:0958?
RHSA-2010:0958 affects systems utilizing the kernel-rt packages in the Linux operating system.
What vulnerability is addressed in RHSA-2010:0958?
RHSA-2010:0958 addresses a vulnerability in the Intel i915 driver that allows a local, unprivileged user to escalate their privileges.
Is RHSA-2010:0958 related to any specific Linux kernel version?
Yes, RHSA-2010:0958 specifically pertains to certain versions of the Linux kernel within the kernel-rt package.