RHSA-2014:0520: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linuxoperating system. A flaw was found in the way the Linux kernel processed an authenticated COOKIEECHO chunk during the initialization of an SCTP connection. A remoteattacker could use this flaw to crash the system by initiating a speciallycrafted SCTP handshake in order to trigger a NULL pointer dereference onthe system. (CVE-2014-0101, Important) A race condition flaw, leading to heap-based buffer overflows, was found in the way the Linux kernel's NTTY line discipline (LDISC) implementationhandled concurrent processing of echo output and TTY write operationsoriginating from user space when the underlying TTY driver was PTY.An unprivileged, local user could use this flaw to crash the system or,potentially, escalate their privileges on the system. (CVE-2014-0196,Important)Red Hat would like to thank Nokia Siemens Networks for reportingCVE-2014-0101.This update also fixes the following bug: Prior to this update, a guest-provided value was used as the head length of the socket buffer allocated on the host. If the host was under heavymemory load and the guest-provided value was too large, the allocationcould have failed, resulting in stalls and packet drops in the guest's Txpath. With this update, the guest-provided value has been limited to areasonable size so that socket buffer allocations on the host succeedregardless of the memory load on the host, and guests can send packetswithout experiencing packet drops or stalls. (BZ#1092349)All kernel users are advised to upgrade to these updated packages, whichcontain backported patches to correct these issues. The system must berebooted for this update to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2014:0520?
The severity of RHSA-2014:0520 is rated as important.
How do I fix RHSA-2014:0520?
To fix RHSA-2014:0520, update to the kernel package version 2.6.32-220.51.1.el6 or later.
What vulnerabilities are addressed by RHSA-2014:0520?
RHSA-2014:0520 addresses a flaw in the way the Linux kernel processes COOKIE_ECHO chunks during SCTP connection initialization.
Which packages are affected by RHSA-2014:0520?
The affected packages include kernel, kernel-debug, kernel-debug-devel, and other related kernel packages on EL6.
Is there a workaround for RHSA-2014:0520?
There is no official workaround for RHSA-2014:0520; applying the recommended kernel patch is necessary.