RHSA-2015:0782: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linuxoperating system. It was found that the Linux kernel's Infiniband subsystem did not properly sanitize input parameters while registering memory regions fromuser space via the (u)verbs API. A local user with access to a/dev/infiniband/uverbsX device could use this flaw to crash the system or,potentially, escalate their privileges on the system. (CVE-2014-8159,Important) A use-after-free flaw was found in the way the Linux kernel's SCTP implementation handled authentication key reference counting during INITcollisions. A remote attacker could use this flaw to crash the system or,potentially, escalate their privileges on the system. (CVE-2015-1421,Important) An integer overflow flaw was found in the way the Linux kernel's Frame Buffer device implementation mapped kernel memory to user space via themmap syscall. A local user able to access a frame buffer device file(/dev/fb) could possibly use this flaw to escalate their privileges on thesystem. (CVE-2013-2596, Important) It was found that the Linux kernel's KVM implementation did not ensure that the host CR4 control register value remained unchanged across VMentries on the same virtual CPU. A local, unprivileged user could use thisflaw to cause a denial of service on the system. (CVE-2014-3690, Moderate) It was found that the parserockridgeinodeinternal() function of the Linux kernel's ISOFS implementation did not correctly check relocateddirectories when processing Rock Ridge child link (CL) tags. An attackerwith physical access to the system could use a specially crafted ISO imageto crash the system or, potentially, escalate their privileges on thesystem. (CVE-2014-5471, CVE-2014-5472, Low) A stack-based buffer overflow flaw was found in the TechnoTrend/Hauppauge DEC USB device driver. A local user with write access to the correspondingdevice could use this flaw to crash the kernel or, potentially, elevatetheir privileges on the system. (CVE-2014-8884, Low)Red Hat would like to thank Mellanox for reporting CVE-2014-8159, and AndyLutomirski for reporting CVE-2014-3690. The CVE-2015-1421 issue wasdiscovered by Sun Baoliang of Red Hat.This update also fixes the following bugs: Previously, a NULL pointer check that is needed to prevent an oops in the nfsasyncinodereturndelegation() function was removed. As a consequence,a NFS4 client could terminate unexpectedly. The missing NULL pointer checkhas been added back, and NFS4 client no longer crashes in this situation.(BZ#1187638) Due to unbalanced multicast join and leave processing, the attempt to leave a multicast group that had not previously completed a join becameunresponsive. This update resolves multiple locking issues in the IPoIBmulticast code that allowed multicast groups to be left before the joiningwas entirely completed. Now, multicast join and leave failures or lockupsno longer occur in the described situation. (BZ#1187663) A failure to leave a multicast group which had previously been joined prevented the attempt to unregister from the "sa" service. Multiple lockingissues in the IPoIB multicast join and leave processing have been fixed sothat leaving a group that has completed its join process is successful.As a result, attempts to unregister from the "sa" service no longer lock updue to leaked resources. (BZ#1187665) Due to a regression, when large reads which partially extended beyond the end of the underlying device were done, the raw driver returned the EIOerror code instead of returning a short read covering the valid part of thedevice. The underlying source code has been patched, and the raw driver nowreturns a short read for the remainder of the device. (BZ#1195746)All kernel users are advised to upgrade to these updated packages, whichcontain backported patches to correct these issues. The system must berebooted for this update to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2015:0782?
The severity of RHSA-2015:0782 is classified as important due to the potential for a local attacker to exploit the vulnerability.
How do I fix RHSA-2015:0782?
To fix RHSA-2015:0782, you should update to the kernel version 2.6.32-431.53.2.el6 or later.
What systems are affected by RHSA-2015:0782?
RHSA-2015:0782 affects systems running the Red Hat Enterprise Linux kernel version before 2.6.32-431.53.2.el6.
What does RHSA-2015:0782 address?
RHSA-2015:0782 addresses an input sanitization issue in the Linux kernel's Infiniband subsystem.
Is there a workaround for RHSA-2015:0782?
There are no documented workarounds for RHSA-2015:0782; updating to the recommended kernel version is essential.