RHSA-2011:1479: Important: kernel security, bug fix, and enhancement update

Published Nov 29, 2011
·
Updated

The kernel packages contain the Linux kernel, the core of any Linuxoperating system.This update fixes the following security issues: Using PCI passthrough without interrupt remapping support allowed Xen hypervisor guests to generate MSI interrupts and thus potentially injecttraps. A privileged guest user could use this flaw to crash the host orpossibly escalate their privileges on the host. The fix for this issue canprevent PCI passthrough working and guests starting. Refer to Red HatBugzilla bug 715555 for details. (CVE-2011-1898, Important) A flaw was found in the way CIFS (Common Internet File System) shares with DFS referrals at their root were handled. An attacker on the localnetwork who is able to deploy a malicious CIFS server could create a CIFSnetwork share that, when mounted, would cause the client system to crash.(CVE-2011-3363, Moderate) A NULL pointer dereference flaw was found in the way the Linux kernel's key management facility handled user-defined key types. A local,unprivileged user could use the keyctl utility to cause a denial ofservice. (CVE-2011-4110, Moderate) A flaw in the way memory containing security-related data was handled in tpmread() could allow a local, unprivileged user to read the results of apreviously run TPM command. (CVE-2011-1162, Low) A NULL pointer dereference flaw was found in the Linux kernel's HFS file system implementation. A local attacker could use this flaw to cause adenial of service by mounting a disk that contains a specially-crafted HFSfile system with a corrupted MDB extent record. (CVE-2011-2203, Low) The I/O statistics from the taskstats subsystem could be read without any restrictions. A local, unprivileged user could use this flaw to gatherconfidential information, such as the length of a password used in aprocess. (CVE-2011-2494, Low)Red Hat would like to thank Yogesh Sharma for reporting CVE-2011-3363;Peter Huewe for reporting CVE-2011-1162; Clement Lecigne for reportingCVE-2011-2203; and Vasiliy Kulikov of Openwall for reporting CVE-2011-2494.This update also fixes several bugs and adds one enhancement. Documentationfor these changes will be available shortly from the Technical Notesdocument linked to in the References section.Users should upgrade to these updated packages, which contain backportedpatches to correct these issues, and fix the bugs and add the enhancementnoted in the Technical Notes. The system must be rebooted for this updateto take effect.

Affected Software

17 affected componentsFixes available
redhat/kernel<2.6.18-274.12.1.el5
2.6.18-274.12.1.el5
redhat/kernel<2.6.18-274.12.1.el5
2.6.18-274.12.1.el5
redhat/kernel-debug<2.6.18-274.12.1.el5
2.6.18-274.12.1.el5
redhat/kernel-debug-devel<2.6.18-274.12.1.el5
2.6.18-274.12.1.el5
redhat/kernel-devel<2.6.18-274.12.1.el5
2.6.18-274.12.1.el5
redhat/kernel-doc<2.6.18-274.12.1.el5
2.6.18-274.12.1.el5
redhat/kernel-headers<2.6.18-274.12.1.el5
2.6.18-274.12.1.el5
redhat/kernel-xen<2.6.18-274.12.1.el5
2.6.18-274.12.1.el5
redhat/kernel-xen-devel<2.6.18-274.12.1.el5
2.6.18-274.12.1.el5
redhat/kernel-debug<2.6.18-274.12.1.el5
2.6.18-274.12.1.el5
redhat/kernel-debug-devel<2.6.18-274.12.1.el5
2.6.18-274.12.1.el5
redhat/kernel-devel<2.6.18-274.12.1.el5
2.6.18-274.12.1.el5
redhat/kernel-headers<2.6.18-274.12.1.el5
2.6.18-274.12.1.el5
redhat/kernel-xen<2.6.18-274.12.1.el5
2.6.18-274.12.1.el5
redhat/kernel-xen-devel<2.6.18-274.12.1.el5
2.6.18-274.12.1.el5
redhat/kernel-kdump<2.6.18-274.12.1.el5
2.6.18-274.12.1.el5
redhat/kernel-kdump-devel<2.6.18-274.12.1.el5
2.6.18-274.12.1.el5

Remediation

Event History

Nov 29, 2011
Advisory Published
12:00 AM

Frequently Asked Questions

1

What is the severity of RHSA-2011:1479?

The severity of RHSA-2011:1479 is categorized as important due to potential security issues in the Linux kernel.

2

How do I fix RHSA-2011:1479?

You can fix RHSA-2011:1479 by updating the kernel packages to version 2.6.18-274.12.1.el5.

3

What vulnerabilities are addressed in RHSA-2011:1479?

RHSA-2011:1479 addresses security issues related to PCI passthrough and interrupt remapping in the Linux kernel.

4

What packages are affected by RHSA-2011:1479?

Packages affected include kernel, kernel-debug, kernel-devel, kernel-headers, and kernel-xen, all requiring an update to version 2.6.18-274.12.1.el5.

5

Is there a specific environment where RHSA-2011:1479 is applicable?

RHSA-2011:1479 is applicable to systems running Red Hat Enterprise Linux 5 with the specified kernel version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203