RHSA-2012:1491: Important: kernel-rt security and bug fix update

Published Dec 4, 2012
·
Updated

The kernel-rt packages contain the Linux kernel, the core of any Linuxoperating system.This update fixes the following security issues: A flaw was found in the way Netlink messages without SCMCREDENTIALS (used for authentication) data set were handled. When not explicitly set,the data was sent but with all values set to 0, including the process IDand user ID, causing the Netlink message to appear as if it were sent withroot privileges. A local, unprivileged user could use this flaw to sendspoofed Netlink messages to an application, possibly resulting in theapplication performing privileged operations if it relied onSCMCREDENTIALS data for the authentication of Netlink messages.(CVE-2012-3520, Important) A race condition was found in the way asynchronous I/O and fallocate() interacted when using the ext4 file system. A local, unprivileged usercould use this flaw to expose random data from an extent whose data blockshave not yet been written, and thus contain data from a deleted file.(CVE-2012-4508, Important) A use-after-free flaw was found in the Linux kernel's memory management subsystem in the way quota handling for huge pages was performed. A local,unprivileged user could use this flaw to cause a denial of service or,potentially, escalate their privileges. (CVE-2012-2133, Moderate) A use-after-free flaw was found in the madvise() system call implementation in the Linux kernel. A local, unprivileged user could usethis flaw to cause a denial of service or, potentially, escalate theirprivileges. (CVE-2012-3511, Moderate) A divide-by-zero flaw was found in the TCP Illinois congestion control algorithm implementation in the Linux kernel. If the TCP Illinoiscongestion control algorithm were in use (the sysctlnet.ipv4.tcpcongestioncontrol variable set to "illinois"), a local,unprivileged user could trigger this flaw and cause a denial of service.(CVE-2012-4565, Moderate) An information leak flaw was found in the uname() system call implementation in the Linux kernel. A local, unprivileged user could usethis flaw to leak kernel stack memory to user-space by setting the UNAME26personality and then calling the uname() system call. (CVE-2012-0957, Low) Buffer overflow flaws were found in the udfloadlogicalvol() function in the Universal Disk Format (UDF) file system implementation in the Linuxkernel. An attacker with physical access to a system could use these flawsto cause a denial of service or escalate their privileges. (CVE-2012-3400,Low) A flaw was found in the way the msgnamelen variable in the rdsrecvmsg() function of the Linux kernel's Reliable Datagram Sockets (RDS) protocolimplementation was initialized. A local, unprivileged user could use thisflaw to leak kernel stack memory to user-space. (CVE-2012-3430, Low)Red Hat would like to thank Pablo Neira Ayuso for reporting CVE-2012-3520;Theodore Ts'o for reporting CVE-2012-4508; Shachar Raindel for reportingCVE-2012-2133; and Kees Cook for reporting CVE-2012-0957. Upstreamacknowledges Dmitry Monakhov as the original reporter of CVE-2012-4508. TheCVE-2012-4565 issue was discovered by Rodrigo Freire of Red Hat, and theCVE-2012-3430 issue was discovered by the Red Hat InfiniBand team.This update also fixes multiple bugs. Documentation for these changes willbe available shortly from the Technical Notes document linked to in theReferences section.Users should upgrade to these updated packages, which upgrade the kernel-rtkernel to version kernel-rt-3.2.33-rt50, and correct these issues. Thesystem must be rebooted for this update to take effect.

Affected Software

15 affected componentsFixes available
redhat/kernel-rt<3.2.33-rt50.66.el6
3.2.33-rt50.66.el6
redhat/kernel-rt-debug<3.2.33-rt50.66.el6
3.2.33-rt50.66.el6
redhat/kernel-rt-debug-debuginfo<3.2.33-rt50.66.el6
3.2.33-rt50.66.el6
redhat/kernel-rt-debug-devel<3.2.33-rt50.66.el6
3.2.33-rt50.66.el6
redhat/kernel-rt-debuginfo<3.2.33-rt50.66.el6
3.2.33-rt50.66.el6
redhat/kernel-rt-devel<3.2.33-rt50.66.el6
3.2.33-rt50.66.el6
redhat/kernel-rt-doc<3.2.33-rt50.66.el6
3.2.33-rt50.66.el6
redhat/kernel-rt-firmware<3.2.33-rt50.66.el6
3.2.33-rt50.66.el6
redhat/kernel-rt-trace<3.2.33-rt50.66.el6
3.2.33-rt50.66.el6
redhat/kernel-rt-trace-debuginfo<3.2.33-rt50.66.el6
3.2.33-rt50.66.el6
redhat/kernel-rt-trace-devel<3.2.33-rt50.66.el6
3.2.33-rt50.66.el6
redhat/kernel-rt-vanilla<3.2.33-rt50.66.el6
3.2.33-rt50.66.el6
redhat/kernel-rt-vanilla-debuginfo<3.2.33-rt50.66.el6
3.2.33-rt50.66.el6
redhat/kernel-rt-vanilla-devel<3.2.33-rt50.66.el6
3.2.33-rt50.66.el6
redhat/mrg-rt-release<3.2.33-rt50.66.el6
3.2.33-rt50.66.el6

Remediation

Event History

Dec 4, 2012
Advisory Published
12:00 AM

Frequently Asked Questions

1

What is the severity of RHSA-2012:1491?

The severity of RHSA-2012:1491 is classified as important.

2

What vulnerabilities are addressed by RHSA-2012:1491?

RHSA-2012:1491 addresses multiple security issues related to the handling of Netlink messages without SCM_CREDENTIALS.

3

How do I fix RHSA-2012:1491?

To fix RHSA-2012:1491, you should update the affected packages to the version 3.2.33-rt50.66.el6.

4

Which packages are affected by RHSA-2012:1491?

The affected packages include kernel-rt, kernel-rt-debug, and several others associated with the kernel-rt series.

5

Is RHSA-2012:1491 relevant for my system?

RHSA-2012:1491 is relevant for systems running Red Hat Enterprise Linux 6 with the mentioned kernel-rt packages.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203