RHSA-2011:0500: Important: kernel-rt security and bug fix update
The kernel-rt packages contain the Linux kernel, the core of any Linuxoperating system.This update fixes the following security issues: A race condition in the way the Linux kernel's InfiniBand implementation set up new connections could allow a remote user to cause a denial ofservice. (CVE-2011-0695, Important) An integer signedness flaw in drmmodesetctl() could allow a local, unprivileged user to cause a denial of service or escalate theirprivileges. (CVE-2011-1013, Important) A flaw in dccprcvstateprocess() could allow a remote attacker to cause a denial of service, even when the socket was already closed.(CVE-2011-1093, Important) A missing validation of a null-terminated string data structure element in bnepsockioctl() could allow a local user to cause an information leakor a denial of service. (CVE-2011-1079, Moderate) A flaw in the Linux kernel's Event Poll (epoll) implementation could allow a local, unprivileged user to cause a denial of service.(CVE-2011-1082, Moderate) A missing initialization flaw in the XFS file system implementation could lead to an information leak. (CVE-2011-0711, Low) The startcode and endcode values in "/proc/[pid]/stat" were not protected. In certain scenarios, this flaw could be used to defeat AddressSpace Layout Randomization (ASLR). (CVE-2011-0726, Low) A missing validation check in the Linux kernel's macpartition() implementation, used for supporting file systems created on Mac OSoperating systems, could allow a local attacker to cause a denial ofservice by mounting a disk that contains specially-crafted partitions.(CVE-2011-1010, Low) A flaw in devload() could allow a local user who has the CAPNETADMIN capability to load arbitrary modules from "/lib/modules/", instead of onlynetdev modules. (CVE-2011-1019, Low) A missing initialization flaw in scosockgetsockoptold() could allow a local, unprivileged user to cause an information leak. (CVE-2011-1078, Low) A buffer overflow flaw in the DEC Alpha OSF partition implementation in the Linux kernel could allow a local attacker to cause an information leakby mounting a disk that contains specially-crafted partition tables.(CVE-2011-1163, Low) Missing validations of null-terminated string data structure elements in the doreplace(), compatdoreplace(), doiptgetctl(),doip6tgetctl(), and doarptgetctl() functions could allow a local userwho has the CAPNETADMIN capability to cause an information leak.(CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-1080, Low)Red Hat would like to thank Jens Kuehnel for reporting CVE-2011-0695;Vasiliy Kulikov for reporting CVE-2011-1079, CVE-2011-1019, CVE-2011-1078,CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, and CVE-2011-1080; NelsonElhage for reporting CVE-2011-1082; Dan Rosenberg for reportingCVE-2011-0711; Kees Cook for reporting CVE-2011-0726; and Timo Warns forreporting CVE-2011-1010 and CVE-2011-1163.This update also fixes various bugs. Documentation for these bug fixes willbe available shortly from the Technical Notes document linked to in theReferences section.Users should upgrade to these updated packages, which upgrade the kernel-rtkernel to version 2.6.33.9-rt31, and correct these issues. The system mustbe rebooted for this update to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2011:0500?
The severity of RHSA-2011:0500 is classified as critical due to the potential for remote exploitation.
How do I fix RHSA-2011:0500?
To fix RHSA-2011:0500, update the kernel-rt packages to the latest version provided in the advisory.
What are the risks associated with RHSA-2011:0500?
The risks associated with RHSA-2011:0500 include potential remote code execution and system compromise.
Which systems are affected by RHSA-2011:0500?
RHSA-2011:0500 affects systems running vulnerable versions of the Linux kernel implementations.
Is there a workaround for RHSA-2011:0500?
No official workaround exists for RHSA-2011:0500, so it is recommended to apply the security update.