RHSA-2012:1491: Important: kernel-rt security and bug fix update
The kernel-rt packages contain the Linux kernel, the core of any Linuxoperating system.This update fixes the following security issues: A flaw was found in the way Netlink messages without SCMCREDENTIALS (used for authentication) data set were handled. When not explicitly set,the data was sent but with all values set to 0, including the process IDand user ID, causing the Netlink message to appear as if it were sent withroot privileges. A local, unprivileged user could use this flaw to sendspoofed Netlink messages to an application, possibly resulting in theapplication performing privileged operations if it relied onSCMCREDENTIALS data for the authentication of Netlink messages.(CVE-2012-3520, Important) A race condition was found in the way asynchronous I/O and fallocate() interacted when using the ext4 file system. A local, unprivileged usercould use this flaw to expose random data from an extent whose data blockshave not yet been written, and thus contain data from a deleted file.(CVE-2012-4508, Important) A use-after-free flaw was found in the Linux kernel's memory management subsystem in the way quota handling for huge pages was performed. A local,unprivileged user could use this flaw to cause a denial of service or,potentially, escalate their privileges. (CVE-2012-2133, Moderate) A use-after-free flaw was found in the madvise() system call implementation in the Linux kernel. A local, unprivileged user could usethis flaw to cause a denial of service or, potentially, escalate theirprivileges. (CVE-2012-3511, Moderate) A divide-by-zero flaw was found in the TCP Illinois congestion control algorithm implementation in the Linux kernel. If the TCP Illinoiscongestion control algorithm were in use (the sysctlnet.ipv4.tcpcongestioncontrol variable set to "illinois"), a local,unprivileged user could trigger this flaw and cause a denial of service.(CVE-2012-4565, Moderate) An information leak flaw was found in the uname() system call implementation in the Linux kernel. A local, unprivileged user could usethis flaw to leak kernel stack memory to user-space by setting the UNAME26personality and then calling the uname() system call. (CVE-2012-0957, Low) Buffer overflow flaws were found in the udfloadlogicalvol() function in the Universal Disk Format (UDF) file system implementation in the Linuxkernel. An attacker with physical access to a system could use these flawsto cause a denial of service or escalate their privileges. (CVE-2012-3400,Low) A flaw was found in the way the msgnamelen variable in the rdsrecvmsg() function of the Linux kernel's Reliable Datagram Sockets (RDS) protocolimplementation was initialized. A local, unprivileged user could use thisflaw to leak kernel stack memory to user-space. (CVE-2012-3430, Low)Red Hat would like to thank Pablo Neira Ayuso for reporting CVE-2012-3520;Theodore Ts'o for reporting CVE-2012-4508; Shachar Raindel for reportingCVE-2012-2133; and Kees Cook for reporting CVE-2012-0957. Upstreamacknowledges Dmitry Monakhov as the original reporter of CVE-2012-4508. TheCVE-2012-4565 issue was discovered by Rodrigo Freire of Red Hat, and theCVE-2012-3430 issue was discovered by the Red Hat InfiniBand team.This update also fixes multiple bugs. Documentation for these changes willbe available shortly from the Technical Notes document linked to in theReferences section.Users should upgrade to these updated packages, which upgrade the kernel-rtkernel to version kernel-rt-3.2.33-rt50, and correct these issues. Thesystem must be rebooted for this update to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2012:1491?
The severity of RHSA-2012:1491 is classified as important.
What vulnerabilities are addressed by RHSA-2012:1491?
RHSA-2012:1491 addresses multiple security issues related to the handling of Netlink messages without SCM_CREDENTIALS.
How do I fix RHSA-2012:1491?
To fix RHSA-2012:1491, you should update the affected packages to the version 3.2.33-rt50.66.el6.
Which packages are affected by RHSA-2012:1491?
The affected packages include kernel-rt, kernel-rt-debug, and several others associated with the kernel-rt series.
Is RHSA-2012:1491 relevant for my system?
RHSA-2012:1491 is relevant for systems running Red Hat Enterprise Linux 6 with the mentioned kernel-rt packages.