RHSA-2014:0328: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linuxoperating system. A flaw was found in the way the getrxbufs() function in the vhostnet implementation in the Linux kernel handled error conditions reported by thevhostgetvqdesc() function. A privileged guest user could use this flawto crash the host. (CVE-2014-0055, Important) A flaw was found in the way the Linux kernel processed an authenticated COOKIEECHO chunk during the initialization of an SCTP connection. A remoteattacker could use this flaw to crash the system by initiating a speciallycrafted SCTP handshake in order to trigger a NULL pointer dereference onthe system. (CVE-2014-0101, Important) A flaw was found in the way the Linux kernel's CIFS implementation handled uncached write operations with specially crafted iovec structures.An unprivileged local user with access to a CIFS share could use this flawto crash the system, leak kernel memory, or, potentially, escalate theirprivileges on the system. Note: the default cache settings for CIFS mountson Red Hat Enterprise Linux 6 prohibit a successful exploitation of thisissue. (CVE-2014-0069, Moderate) A heap-based buffer overflow flaw was found in the Linux kernel's cdc-wdm driver, used for USB CDC WCM device management. An attacker with physicalaccess to a system could use this flaw to cause a denial of service or,potentially, escalate their privileges. (CVE-2013-1860, Low)Red Hat would like to thank Nokia Siemens Networks for reportingCVE-2014-0101, and Al Viro for reporting CVE-2014-0069.This update also fixes several bugs. Documentation for these changes willbe available shortly from the Technical Notes document linked to in theReferences section.All kernel users are advised to upgrade to these updated packages, whichcontain backported patches to correct these issues. The system must berebooted for this update to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2014:0328?
The severity of RHSA-2014:0328 is classified as moderate.
How do I fix RHSA-2014:0328?
To fix RHSA-2014:0328, update the kernel package to version 2.6.32-431.11.2.el6 or later.
What are the affected software versions for RHSA-2014:0328?
Affected software versions for RHSA-2014:0328 include kernel versions prior to 2.6.32-431.11.2.el6.
What types of systems are impacted by RHSA-2014:0328?
RHSA-2014:0328 impacts systems running Red Hat Enterprise Linux release 6 with affected kernel packages.
What specific packages are affected by RHSA-2014:0328?
The specific packages affected by RHSA-2014:0328 include kernel, kernel-debug, kernel-headers, and several related kernel packages.