RHSA-2011:0833: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linuxoperating system.This update fixes the following security issues: A flaw in the dccprcvstateprocess() function could allow a remote attacker to cause a denial of service, even when the socket was alreadyclosed. (CVE-2011-1093, Important) Multiple buffer overflow flaws were found in the Linux kernel's Management Module Support for Message Passing Technology (MPT) basedcontrollers. A local, unprivileged user could use these flaws to cause adenial of service, an information leak, or escalate their privileges.(CVE-2011-1494, CVE-2011-1495, Important) A missing validation of a null-terminated string data structure element in the bnepsockioctl() function could allow a local user to cause aninformation leak or a denial of service. (CVE-2011-1079, Moderate) Missing error checking in the way page tables were handled in the Xen hypervisor implementation could allow a privileged guest user to cause thehost, and the guests, to lock up. (CVE-2011-1166, Moderate) A flaw was found in the way the Xen hypervisor implementation checked for the upper boundary when getting a new event channel port. A privilegedguest user could use this flaw to cause a denial of service or escalatetheir privileges. (CVE-2011-1763, Moderate) The startcode and endcode values in "/proc/[pid]/stat" were not protected. In certain scenarios, this flaw could be used to defeat AddressSpace Layout Randomization (ASLR). (CVE-2011-0726, Low) A missing initialization flaw in the scosockgetsockopt() function could allow a local, unprivileged user to cause an information leak.(CVE-2011-1078, Low) A missing validation of a null-terminated string data structure element in the doreplace() function could allow a local user who has theCAPNETADMIN capability to cause an information leak. (CVE-2011-1080, Low) A buffer overflow flaw in the DEC Alpha OSF partition implementation in the Linux kernel could allow a local attacker to cause an information leakby mounting a disk that contains specially-crafted partition tables.(CVE-2011-1163, Low) Missing validations of null-terminated string data structure elements in the doreplace(), compatdoreplace(), doiptgetctl(), doip6tgetctl(),and doarptgetctl() functions could allow a local user who has theCAPNETADMIN capability to cause an information leak. (CVE-2011-1170,CVE-2011-1171, CVE-2011-1172, Low) A heap overflow flaw in the Linux kernel's EFI GUID Partition Table (GPT) implementation could allow a local attacker to cause a denial of serviceby mounting a disk that contains specially-crafted partition tables.(CVE-2011-1577, Low)Red Hat would like to thank Dan Rosenberg for reporting CVE-2011-1494 andCVE-2011-1495; Vasiliy Kulikov for reporting CVE-2011-1079, CVE-2011-1078,CVE-2011-1080, CVE-2011-1170, CVE-2011-1171, and CVE-2011-1172; Kees Cookfor reporting CVE-2011-0726; and Timo Warns for reporting CVE-2011-1163and CVE-2011-1577.This update also fixes several bugs. Documentation for these bug fixes willbe available shortly from the Technical Notes document linked to in theReferences section.Users should upgrade to these updated packages, which contain backportedpatches to correct these issues, and fix the bugs noted in the TechnicalNotes. The system must be rebooted for this update to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2011:0833?
The severity of RHSA-2011:0833 is classified as important due to the potential denial of service caused by the vulnerability.
How do I fix RHSA-2011:0833?
To fix RHSA-2011:0833, you should update your kernel package to version 2.6.18-238.12.1.el5 or later.
What types of systems are affected by RHSA-2011:0833?
RHSA-2011:0833 affects systems running the 2.6.18-238.12.1.el5 kernel version on Red Hat Enterprise Linux.
Are there any known exploits for RHSA-2011:0833?
As of now, there are no publicly known exploits specifically targeting RHSA-2011:0833.
What are the potential impacts if RHSA-2011:0833 is not patched?
If RHSA-2011:0833 is not patched, a remote attacker could potentially trigger a denial of service on the affected system.