RHSA-2015:0783: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linuxoperating system. It was found that the Linux kernel's Infiniband subsystem did not properly sanitize input parameters while registering memory regions fromuser space via the (u)verbs API. A local user with access to a/dev/infiniband/uverbsX device could use this flaw to crash the system or,potentially, escalate their privileges on the system. (CVE-2014-8159,Important) An insufficient bound checking flaw was found in the Xen hypervisor's implementation of acceleration support for the "REP MOVS" instructions.A privileged HVM guest user could potentially use this flaw to crash thehost. (CVE-2014-8867, Important)Red Hat would like to thank Mellanox for reporting CVE-2014-8159, and theXen project for reporting CVE-2014-8867.This update also fixes the following bugs: Under memory pressure, cached data was previously flushed to the backing server using the PID of the thread responsible for flushing the data in theServer Message Block (SMB) headers instead of the PID of the thread whichactually wrote the data. As a consequence, when a file was locked by thewriting thread prior to writing, the server considered writes by the threadflushing the pagecache as being a separate process from writing to a lockedfile, and thus rejected the writes. In addition, the data to be written wasdiscarded. This update ensures that the correct PID is sent to the server,and data corruption is avoided when data is being written from a clientunder memory pressure. (BZ#1169304) This update adds support for new cryptographic hardware in toleration mode for IBM System z. (BZ#1182522)All kernel users are advised to upgrade to these updated packages, whichcontain backported patches to correct these issues. The system must berebooted for this update to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2015:0783?
The severity of RHSA-2015:0783 is categorized as important.
How do I fix RHSA-2015:0783?
To fix RHSA-2015:0783, update the affected kernel packages to version 2.6.18-404.el5.
Which versions of kernel packages are affected by RHSA-2015:0783?
The vulnerable versions include all kernel packages prior to 2.6.18-404.el5.
What is the impact of the vulnerability in RHSA-2015:0783?
The vulnerability in RHSA-2015:0783 allows local users to potentially exploit the memory registration mechanism of the Infiniband subsystem.
Is there a workaround for RHSA-2015:0783 available?
As of the details provided, there are no known workarounds for RHSA-2015:0783, and updating is recommended.