RHSA-2014:1318: Moderate: Red Hat Enterprise MRG Realtime 2.5 security and enhancement update
Red Hat Enterprise MRG (Messaging, Realtime, and Grid) is a next-generationIT infrastructure for enterprise computing. MRG offers increasedperformance, reliability, interoperability, and faster computing forenterprise customers.MRG Realtime provides the highest levels of predictability for consistentlow-latency response times to meet the needs of time-sensitive workloads.MRG Realtime also provides new levels of determinism by optimizing lengthykernel code paths to ensure that they do not become bottlenecks. Thisallows for better prioritization of applications, resulting in consistent,predictable response times for high-priority applications. An out-of-bounds write flaw was found in the way the Apple Magic Mouse/Trackpad multi-touch driver handled Human Interface Device (HID)reports with an invalid size. An attacker with physical access to thesystem could use this flaw to crash the system or, potentially, escalatetheir privileges on the system. (CVE-2014-3181, Moderate) A memory corruption flaw was found in the way the USB ConnectTech WhiteHEAT serial driver processed completion commands sent via USB RequestBlocks buffers. An attacker with physical access to the system could usethis flaw to crash the system or, potentially, escalate their privileges onthe system. (CVE-2014-3185, Moderate) A race condition flaw was found in the way the Linux kernel's mmap(2), madvise(2), and fallocate(2) system calls interacted with each other whileoperating on virtual memory file system files. A local user could use thisflaw to cause a denial of service. (CVE-2014-4171, Moderate) A stack overflow flaw caused by infinite recursion was found in the way the Linux kernel's Universal Disk Format (UDF) file system implementationprocessed indirect Information Control Blocks (ICBs). An attacker withphysical access to the system could use a specially crafted UDF image tocrash the system. (CVE-2014-6410, Low) An out-of-bounds read flaw was found in the way the Logitech Unifying receiver driver handled HID reports with an invalid deviceindex value.An attacker with physical access to the system could use this flaw to crashthe system or, potentially, escalate their privileges on the system.(CVE-2014-3182, Low) Multiple out-of-bounds write flaws were found in the way the Cherry Cymotion keyboard driver, KYE/Genius device drivers, Logitech devicedrivers, Monterey Genius KB29E keyboard driver, Petalynx Maxter remotecontrol driver, and Sunplus wireless desktop driver handled HID reportswith an invalid report descriptor size. An attacker with physical access tothe system could use either of these flaws to write data past an allocatedmemory buffer. (CVE-2014-3184, Low) It was found that the parserockridgeinodeinternal() function of the Linux kernel's ISOFS implementation did not correctly check relocateddirectories when processing Rock Ridge child link (CL) tags. An attackerwith physical access to the system could use a specially crafted ISO imageto crash the system or, potentially, escalate their privileges on thesystem. (CVE-2014-5471, CVE-2014-5472, Low)This update also adds the following enhancement: The Solarflare SFC9120 10GBE Ethernet NICs were not supported by the MRG Realtime kernel. With this update, the drivers have been updated to enablethe Solarflare SFC9120 cards on the Realtime kernel. (BZ#1086945)All Red Hat Enterprise MRG Realtime users are advised to upgrade to theseupdated packages, which contain backported patches to correct these issuesand add this enhancement.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2014:1318?
The severity of RHSA-2014:1318 is rated as moderate.
How do I fix RHSA-2014:1318?
To fix RHSA-2014:1318, update the affected kernel-rt packages to version 3.10.33-rt32.51.el6.
What packages are affected by RHSA-2014:1318?
The affected packages for RHSA-2014:1318 include kernel-rt, kernel-rt-debug, and several other kernel-rt related packages.
Is there a workaround for RHSA-2014:1318?
There are no recommended workarounds for RHSA-2014:1318, it's best to apply the updates.
When was RHSA-2014:1318 released?
RHSA-2014:1318 was released on October 14, 2014.