RHSA-2014:0557: Important: kernel-rt security update
The kernel-rt packages contain the Linux kernel, the core of any Linuxoperating system. A race condition leading to a use-after-free flaw was found in the way the Linux kernel's TCP/IP protocol suite implementation handled theaddition of fragments to the LRU (Last-Recently Used) list under certainconditions. A remote attacker could use this flaw to crash the system or,potentially, escalate their privileges on the system by sending a largeamount of specially crafted fragmented packets to that system.(CVE-2014-0100, Important) A race condition flaw, leading to heap-based buffer overflows, was found in the way the Linux kernel's NTTY line discipline (LDISC) implementationhandled concurrent processing of echo output and TTY write operationsoriginating from user space when the underlying TTY driver was PTY.An unprivileged, local user could use this flaw to crash the system or,potentially, escalate their privileges on the system. (CVE-2014-0196,Important) A flaw was found in the way the Linux kernel's floppy driver handled user space provided data in certain error code paths while processing FDRAWCMDIOCTL commands. A local user with write access to /dev/fdX could use thisflaw to free (using the kfree() function) arbitrary kernel memory.(CVE-2014-1737, Important) It was found that the Linux kernel's floppy driver leaked internal kernel memory addresses to user space during the processing of the FDRAWCMD IOCTLcommand. A local user with write access to /dev/fdX could use this flaw toobtain information about the kernel heap arrangement. (CVE-2014-1738, Low)Note: A local user with write access to /dev/fdX could use these two flaws(CVE-2014-1737 in combination with CVE-2014-1738) to escalate theirprivileges on the system. A use-after-free flaw was found in the way the pinginitsock() function of the Linux kernel handled the groupinfo reference counter. A local,unprivileged user could use this flaw to crash the system or, potentially,escalate their privileges on the system. (CVE-2014-2851, Important) It was found that a remote attacker could use a race condition flaw in the athtxaggrsleep() function to crash the system by creating largenetwork traffic on the system's Atheros 9k wireless network adapter.(CVE-2014-2672, Moderate) A NULL pointer dereference flaw was found in the rdsiwladdrcheck() function in the Linux kernel's implementation of Reliable Datagram Sockets(RDS). A local, unprivileged user could use this flaw to crash the system.(CVE-2014-2678, Moderate) A race condition flaw was found in the way the Linux kernel's mac80211 subsystem implementation handled synchronization between TX and STA wake-upcode paths. A remote attacker could use this flaw to crash the system.(CVE-2014-2706, Moderate) It was found that the trytounmapcluster() function in the Linux kernel's Memory Managment subsystem did not properly handle page locking incertain cases, which could potentially trigger the BUGON() macro in themlockvmapage() function. A local, unprivileged user could use this flawto crash the system. (CVE-2014-3122, Moderate)Red Hat would like to thank Matthew Daley for reporting CVE-2014-1737 andCVE-2014-1738. The CVE-2014-0100 issue was discovered by NikolayAleksandrov of Red Hat.Users are advised to upgrade to these updated packages, which upgrade thekernel-rt kernel to version kernel-rt-3.10.33-rt32.34 and correct theseissues. The system must be rebooted for this update to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2014:0557?
The severity of RHSA-2014:0557 is classified as important due to a potential security vulnerability in the Linux kernel.
How do I fix RHSA-2014:0557?
To resolve RHSA-2014:0557, update your kernel-rt packages to version 3.10.33-rt32.34.el6.
What types of packages are affected by RHSA-2014:0557?
RHSA-2014:0557 affects several packages including kernel-rt, kernel-rt-debug, and kernel-rt-devel among others.
What kind of vulnerability is described in RHSA-2014:0557?
RHSA-2014:0557 describes a race condition leading to a use-after-free flaw in the Linux kernel's TCP/IP protocol suite.
Is RHSA-2014:0557 specific to a certain version of the Linux kernel?
Yes, RHSA-2014:0557 pertains specifically to the 3.10 kernel series, particularly within the real-time kernel packages.