RHSA-2015:1137: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linuxoperating system. It was found that the Linux kernel's implementation of vectored pipe read and write functionality did not take into account the I/O vectors that werealready processed when retrying after a failed atomic access operation,potentially resulting in memory corruption due to an I/O vector arrayoverrun. A local, unprivileged user could use this flaw to crash the systemor, potentially, escalate their privileges on the system. (CVE-2015-1805,Important) A race condition flaw was found in the way the Linux kernel keys management subsystem performed key garbage collection. A local attackercould attempt accessing a key while it was being garbage collected, whichwould cause the system to crash. (CVE-2014-9529, Moderate) A flaw was found in the way the Linux kernel's 32-bit emulation implementation handled forking or closing of a task with an 'int80' entry.A local user could potentially use this flaw to escalate their privilegeson the system. (CVE-2015-2830, Low) It was found that the Linux kernel's ISO file system implementation did not correctly limit the traversal of Rock Ridge extension ContinuationEntries (CE). An attacker with physical access to the system could use thisflaw to trigger an infinite loop in the kernel, resulting in a denial ofservice. (CVE-2014-9420, Low) An information leak flaw was found in the way the Linux kernel's ISO9660 file system implementation accessed data on an ISO9660 image with RockRidgeExtension Reference (ER) records. An attacker with physical access to thesystem could use this flaw to disclose up to 255 bytes of kernel memory.(CVE-2014-9584, Low) A flaw was found in the way the nftflushtable() function of the Linux kernel's netfilter tables implementation flushed rules that werereferencing deleted chains. A local user who has the CAPNETADMINcapability could use this flaw to crash the system. (CVE-2015-1573, Low) An integer overflow flaw was found in the way the Linux kernel randomized the stack for processes on certain 64-bit architecture systems, such asx86-64, causing the stack entropy to be reduced by four. (CVE-2015-1593,Low)Red Hat would like to thank Carl Henrik Lunde for reporting CVE-2014-9420and CVE-2014-9584. The security impact of the CVE-2015-1805 issue wasdiscovered by Red Hat.This update also fixes several bugs. Documentation for these changes isavailable from the following Knowledgebase article:https://access.redhat.com/articles/1469163 All kernel users are advised to upgrade to these updated packages, whichcontain backported patches to correct these issues. The system must berebooted for this update to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2015:1137?
The severity of RHSA-2015:1137 is classified as important.
How do I fix RHSA-2015:1137?
To fix RHSA-2015:1137, update to kernel version 3.10.0-229.7.2.el7 or later.
What packages are affected by RHSA-2015:1137?
Affected packages include kernel, kernel-debug, kernel-devel, and several others in the Red Hat repository.
What is the impact of not addressing RHSA-2015:1137?
Failure to address RHSA-2015:1137 could lead to kernel vulnerabilities that attackers may exploit.
Where can I find more information about RHSA-2015:1137?
Further details about RHSA-2015:1137 can be found in the Red Hat security advisory.