RHSA-2014:0159: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linuxoperating system. A buffer overflow flaw was found in the way the qethsnmpcommand() function in the Linux kernel's QETH network device driver implementationhandled SNMP IOCTL requests with an out-of-bounds length. A local,unprivileged user could use this flaw to crash the system or, potentially,escalate their privileges on the system. (CVE-2013-6381, Important) A flaw was found in the way the getdumpable() function return value was interpreted in the ptrace subsystem of the Linux kernel. When'fs.suiddumpable' was set to 2, a local, unprivileged local user coulduse this flaw to bypass intended ptrace restrictions and obtainpotentially sensitive information. (CVE-2013-2929, Low) It was found that certain protocol handlers in the Linux kernel's networking implementation could set the addrlen value without initializingthe associated data structure. A local, unprivileged user could use thisflaw to leak kernel stack memory to user space using the recvmsg, recvfrom,and recvmmsg system calls (CVE-2013-7263, CVE-2013-7265, Low).This update also fixes several bugs. Documentation for these changes willbe available shortly from the Technical Notes document linked to in theReferences section.All kernel users are advised to upgrade to these updated packages, whichcontain backported patches to correct these issues. The system must berebooted for this update to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2014:0159?
The severity of RHSA-2014:0159 is classified as important due to a buffer overflow vulnerability in the Linux kernel.
How do I fix RHSA-2014:0159?
To fix RHSA-2014:0159, update the kernel package to version 2.6.32-431.5.1.el6 or later.
Which systems are affected by RHSA-2014:0159?
RHSA-2014:0159 affects systems running the Red Hat Enterprise Linux kernel version prior to 2.6.32-431.5.1.el6.
What type of flaw does RHSA-2014:0159 address?
RHSA-2014:0159 addresses a buffer overflow flaw in the qeth_snmp_command() function of the Linux kernel.
Is there a workaround for RHSA-2014:0159?
There are no official workarounds for RHSA-2014:0159; the recommended solution is to apply the kernel update.