RHSA-2015:1138: Important: kernel-rt security, bug fix, and enhancement update

Published Jun 23, 2015
·
Updated

The kernel-rt packages contain the Linux kernel, the core of any Linuxoperating system. It was found that the Linux kernel's implementation of vectored pipe read and write functionality did not take into account the I/O vectors that werealready processed when retrying after a failed atomic access operation,potentially resulting in memory corruption due to an I/O vector arrayoverrun. A local, unprivileged user could use this flaw to crash the systemor, potentially, escalate their privileges on the system. (CVE-2015-1805,Important) A race condition flaw was found in the way the Linux kernel keys management subsystem performed key garbage collection. A local attackercould attempt accessing a key while it was being garbage collected, whichwould cause the system to crash. (CVE-2014-9529, Moderate) A flaw was found in the way the Linux kernel's 32-bit emulation implementation handled forking or closing of a task with an 'int80' entry.A local user could potentially use this flaw to escalate their privilegeson the system. (CVE-2015-2830, Low) It was found that the Linux kernel's ISO file system implementation did not correctly limit the traversal of Rock Ridge extension ContinuationEntries (CE). An attacker with physical access to the system could use thisflaw to trigger an infinite loop in the kernel, resulting in a denial ofservice. (CVE-2014-9420, Low) An information leak flaw was found in the way the Linux kernel's ISO9660 file system implementation accessed data on an ISO9660 image with RockRidgeExtension Reference (ER) records. An attacker with physical access to thesystem could use this flaw to disclose up to 255 bytes of kernel memory.(CVE-2014-9584, Low) A flaw was found in the way the nftflushtable() function of the Linux kernel's netfilter tables implementation flushed rules that werereferencing deleted chains. A local user who has the CAPNETADMINcapability could use this flaw to crash the system. (CVE-2015-1573, Low) An integer overflow flaw was found in the way the Linux kernel randomized the stack for processes on certain 64-bit architecture systems, such asx86-64, causing the stack entropy to be reduced by four. (CVE-2015-1593,Low)Red Hat would like to thank Carl Henrik Lunde for reporting CVE-2014-9420and CVE-2014-9584. The security impact of CVE-2015-1805 was discovered byRed Hat.This update provides a build of the kernel-rt package for Red HatEnterprise MRG 2.5 that is layered on Red Hat Enterprise Linux 6, andfixes the following issues: storvsc: get rid of overly verbose warning messages storvsc: force discovery of LUNs that may have been removed storvsc: in responce to a scan event, scan the hos storvsc: NULL pointer dereference fix futex: Mention key referencing differences between shared and private futexes futex: Ensure getfutexkeyrefs() always implies a barrier kernel module: set nx before marking module MODULESTATECOMING kernel module: Clean up ro/nx after early module load failures btrfs: make xattr replace operations atomic megaraidsas: revert: Add release date and update driver version radeon: fix kernel segfault in hwmonitor (BZ#1223077)Bug fix: There is an XFS optimization that depended on a spinlock to disable preemption using the preemptdisable() function. When CONFIGPREEMPTRT isenabled on realtime kernels, spinlocks do not disable preemption whileheld, so the XFS critical section was not protected from preemption.Systems on the Realtime kernel-rt could lock up in this XFS optimizationwhen a task that locked all the counters was then preempted by a realtimetask, causing all callers of that lock to block indefinitely. This updatedisables the optimization when building a kernel withCONFIGPREEMPTRTFULL enabled. (BZ#1217849)All kernel-rt users are advised to upgrade to these updated packages, whichcorrect these issues and add these enhancements. The system must berebooted for this update to take effect.

Affected Software

14 affected componentsFixes available
redhat/kernel-rt<3.10.0-229.rt56.153.el6
3.10.0-229.rt56.153.el6
redhat/kernel-rt-debug<3.10.0-229.rt56.153.el6
3.10.0-229.rt56.153.el6
redhat/kernel-rt-debug-debuginfo<3.10.0-229.rt56.153.el6
3.10.0-229.rt56.153.el6
redhat/kernel-rt-debug-devel<3.10.0-229.rt56.153.el6
3.10.0-229.rt56.153.el6
redhat/kernel-rt-debuginfo<3.10.0-229.rt56.153.el6
3.10.0-229.rt56.153.el6
redhat/kernel-rt-devel<3.10.0-229.rt56.153.el6
3.10.0-229.rt56.153.el6
redhat/kernel-rt-doc<3.10.0-229.rt56.153.el6
3.10.0-229.rt56.153.el6
redhat/kernel-rt-firmware<3.10.0-229.rt56.153.el6
3.10.0-229.rt56.153.el6
redhat/kernel-rt-trace<3.10.0-229.rt56.153.el6
3.10.0-229.rt56.153.el6
redhat/kernel-rt-trace-debuginfo<3.10.0-229.rt56.153.el6
3.10.0-229.rt56.153.el6
redhat/kernel-rt-trace-devel<3.10.0-229.rt56.153.el6
3.10.0-229.rt56.153.el6
redhat/kernel-rt-vanilla<3.10.0-229.rt56.153.el6
3.10.0-229.rt56.153.el6
redhat/kernel-rt-vanilla-debuginfo<3.10.0-229.rt56.153.el6
3.10.0-229.rt56.153.el6
redhat/kernel-rt-vanilla-devel<3.10.0-229.rt56.153.el6
3.10.0-229.rt56.153.el6

Remediation

Event History

Jun 23, 2015
Advisory Published
12:00 AM

Frequently Asked Questions

1

What is the severity of RHSA-2015:1138?

The severity of RHSA-2015:1138 is classified as important.

2

How do I fix RHSA-2015:1138?

You can fix RHSA-2015:1138 by updating to kernel-rt version 3.10.0-229.rt56.153.el6.

3

Which systems are affected by RHSA-2015:1138?

RHSA-2015:1138 affects systems running kernel-rt versions prior to 3.10.0-229.rt56.153.el6.

4

What type of vulnerability is described in RHSA-2015:1138?

RHSA-2015:1138 describes a vulnerability related to the Linux kernel's vectored pipe read and write functionality.

5

Is there any risk of exploitation with RHSA-2015:1138?

Yes, there is a potential risk of exploitation if systems are not updated to the patched version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203