RHSA-2013:0829: Important: kernel-rt security and bug fix update

Published May 20, 2013
·
Updated

Security fixes: It was found that the kernel-rt update RHBA-2012:0044 introduced an integer conversion issue in the Linux kernel's Performance Eventsimplementation. This led to a user-supplied index into theperfsweventenabled array not being validated properly, resulting inout-of-bounds kernel memory access. A local, unprivileged user could usethis flaw to escalate their privileges. (CVE-2013-2094, Important)A public exploit for CVE-2013-2094 that affects Red Hat Enterprise MRG 2 isavailable. Refer to Red Hat Knowledge Solution 373743, linked to in theReferences, for further information and mitigation instructions for userswho are unable to immediately apply this update. An integer overflow flaw, leading to a heap-based buffer overflow, was found in the way the Intel i915 driver in the Linux kernel handled theallocation of the buffer used for relocation copies. A local user withconsole access could use this flaw to cause a denial of service or escalatetheir privileges. (CVE-2013-0913, Important) It was found that the Linux kernel used effective user and group IDs instead of real ones when passing messages with SCMCREDENTIALS ancillarydata. A local, unprivileged user could leverage this flaw with a set userID (setuid) application, allowing them to escalate their privileges.(CVE-2013-1979, Important) A race condition in installuserkeyrings(), leading to a NULL pointer dereference, was found in the key management facility. A local,unprivileged user could use this flaw to cause a denial of service.(CVE-2013-1792, Moderate) A NULL pointer dereference flaw was found in the Linux kernel's XFS file system implementation. A local user who is able to mount an XFS filesystem could use this flaw to cause a denial of service. (CVE-2013-1819,Moderate) An information leak was found in the Linux kernel's POSIX signals implementation. A local, unprivileged user could use this flaw to bypassthe Address Space Layout Randomization (ASLR) security feature.(CVE-2013-0914, Low) A use-after-free flaw was found in the tmpfs implementation. A local user able to mount and unmount a tmpfs file system could use this flaw to causea denial of service or, potentially, escalate their privileges.(CVE-2013-1767, Low) A NULL pointer dereference flaw was found in the Linux kernel's USB Inside Out Edgeport Serial Driver implementation. A local user withphysical access to a system and with access to a USB device's tty filecould use this flaw to cause a denial of service. (CVE-2013-1774, Low) A format string flaw was found in the ext3msg() function in the Linux kernel's ext3 file system implementation. A local user who is able tomount an ext3 file system could use this flaw to cause a denial of serviceor, potentially, escalate their privileges. (CVE-2013-1848, Low) A heap-based buffer overflow flaw was found in the Linux kernel's cdc-wdm driver, used for USB CDC WCM device management. An attacker withphysical access to a system could use this flaw to cause a denial ofservice or, potentially, escalate their privileges. (CVE-2013-1860, Low) A heap-based buffer overflow in the way the tg3 Ethernet driver parsed the vital product data (VPD) of devices could allow an attacker withphysical access to a system to cause a denial of service or, potentially,escalate their privileges. (CVE-2013-1929, Low) Information leaks in the Linux kernel's cryptographic API could allow a local user who has the CAPNETADMIN capability to leak kernel stack memoryto user-space. (CVE-2013-2546, CVE-2013-2547, CVE-2013-2548, Low) Information leaks in the Linux kernel could allow a local, unprivileged user to leak kernel stack memory to user-space. (CVE-2013-2634,CVE-2013-2635, CVE-2013-3076, CVE-2013-3222, CVE-2013-3224, CVE-2013-3225,CVE-2013-3231, Low)Red Hat would like to thank Andy Lutomirski for reporting CVE-2013-1979.CVE-2013-1792 was discovered by Mateusz Guzik of Red Hat EMEA GSS SEG Team.

Affected Software

15 affected componentsFixes available
redhat/kernel-rt<3.6.11.2-rt33.39.el6
3.6.11.2-rt33.39.el6
redhat/kernel-rt-debug<3.6.11.2-rt33.39.el6
3.6.11.2-rt33.39.el6
redhat/kernel-rt-debug-debuginfo<3.6.11.2-rt33.39.el6
3.6.11.2-rt33.39.el6
redhat/kernel-rt-debug-devel<3.6.11.2-rt33.39.el6
3.6.11.2-rt33.39.el6
redhat/kernel-rt-debuginfo<3.6.11.2-rt33.39.el6
3.6.11.2-rt33.39.el6
redhat/kernel-rt-devel<3.6.11.2-rt33.39.el6
3.6.11.2-rt33.39.el6
redhat/kernel-rt-doc<3.6.11.2-rt33.39.el6
3.6.11.2-rt33.39.el6
redhat/kernel-rt-firmware<3.6.11.2-rt33.39.el6
3.6.11.2-rt33.39.el6
redhat/kernel-rt-trace<3.6.11.2-rt33.39.el6
3.6.11.2-rt33.39.el6
redhat/kernel-rt-trace-debuginfo<3.6.11.2-rt33.39.el6
3.6.11.2-rt33.39.el6
redhat/kernel-rt-trace-devel<3.6.11.2-rt33.39.el6
3.6.11.2-rt33.39.el6
redhat/kernel-rt-vanilla<3.6.11.2-rt33.39.el6
3.6.11.2-rt33.39.el6
redhat/kernel-rt-vanilla-debuginfo<3.6.11.2-rt33.39.el6
3.6.11.2-rt33.39.el6
redhat/kernel-rt-vanilla-devel<3.6.11.2-rt33.39.el6
3.6.11.2-rt33.39.el6
redhat/mrg-rt-release<3.6.11.2-rt33.39.el6
3.6.11.2-rt33.39.el6

Remediation

Event History

May 20, 2013
Advisory Published
12:00 AM

Frequently Asked Questions

1

What is the severity of RHSA-2013:0829?

The severity of RHSA-2013:0829 is categorized as important due to the potential for integer conversion issues leading to security vulnerabilities in the Linux kernel.

2

How do I fix RHSA-2013:0829?

To fix RHSA-2013:0829, update to kernel-rt version 3.6.11.2-rt33.39.el6 or a later version available.

3

What software is affected by RHSA-2013:0829?

RHSA-2013:0829 affects various Red Hat kernel-rt packages, including kernel-rt, kernel-rt-debug, and their respective devel and debuginfo versions.

4

What is the impact of not addressing RHSA-2013:0829?

Not addressing RHSA-2013:0829 may leave systems vulnerable to exploitation, potentially leading to privilege escalation or system instability.

5

Is there a specific version that resolves RHSA-2013:0829?

Yes, the resolution for RHSA-2013:0829 is found in the kernel-rt package version 3.6.11.2-rt33.39.el6 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203