RHSA-2015:2152: Important: kernel security, bug fix, and enhancement update

Published Nov 19, 2015
·
Updated

The kernel packages contain the Linux kernel, the core of any Linuxoperating system. A flaw was found in the way the Linux kernel's file system implementation handled rename operations in which the source was inside and thedestination was outside of a bind mount. A privileged user inside acontainer could use this flaw to escape the bind mount and, potentially,escalate their privileges on the system. (CVE-2015-2925, Important) A race condition flaw was found in the way the Linux kernel's IPC subsystem initialized certain fields in an IPC object structure that werelater used for permission checking before inserting the object into aglobally visible list. A local, unprivileged user could potentially usethis flaw to elevate their privileges on the system. (CVE-2015-7613,Important) It was found that reporting emulation failures to user space could lead to either a local (CVE-2014-7842) or a L2->L1 (CVE-2010-5313) denial ofservice. In the case of a local denial of service, an attacker must haveaccess to the MMIO area or be able to access an I/O port. (CVE-2010-5313,CVE-2014-7842, Moderate) A flaw was found in the way the Linux kernel's KVM subsystem handled non-canonical addresses when emulating instructions that change the RIP(for example, branches or calls). A guest user with access to an I/O orMMIO region could use this flaw to crash the guest. (CVE-2014-3647,Moderate) It was found that the Linux kernel memory resource controller's (memcg) handling of OOM (out of memory) conditions could lead to deadlocks.An attacker could use this flaw to lock up the system. (CVE-2014-8171,Moderate) A race condition flaw was found between the chown and execve system calls. A local, unprivileged user could potentially use this flaw toescalate their privileges on the system. (CVE-2015-3339, Moderate) A flaw was discovered in the way the Linux kernel's TTY subsystem handled the tty shutdown phase. A local, unprivileged user could use this flaw tocause a denial of service on the system. (CVE-2015-4170, Moderate) A NULL pointer dereference flaw was found in the SCTP implementation. A local user could use this flaw to cause a denial of service on the systemby triggering a kernel panic when creating multiple sockets in parallelwhile the system did not have the SCTP module loaded. (CVE-2015-5283,Moderate) A flaw was found in the way the Linux kernel's perf subsystem retrieved userlevel stack traces on PowerPC systems. A local, unprivileged user coulduse this flaw to cause a denial of service on the system. (CVE-2015-6526,Moderate) A flaw was found in the way the Linux kernel's Crypto subsystem handled automatic loading of kernel modules. A local user could use this flaw toload any installed kernel module, and thus increase the attack surface ofthe running kernel. (CVE-2013-7421, CVE-2014-9644, Low) An information leak flaw was found in the way the Linux kernel changed certain segment registers and thread-local storage (TLS) during a contextswitch. A local, unprivileged user could use this flaw to leak the userspace TLS base address of an arbitrary process. (CVE-2014-9419, Low) It was found that the Linux kernel KVM subsystem's sysenter instruction emulation was not sufficient. An unprivileged guest user could use thisflaw to escalate their privileges by tricking the hypervisor to emulate aSYSENTER instruction in 16-bit mode, if the guest OS did not initialize theSYSENTER model-specific registers (MSRs). Note: Certified guest operatingsystems for Red Hat Enterprise Linux with KVM do initialize the SYSENTERMSRs and are thus not vulnerable to this issue when running on a KVMhypervisor. (CVE-2015-0239, Low) A flaw was found in the way the Linux kernel handled the securelevel functionality after performing a kexec operation. A local attacker coulduse this flaw to bypass the security mechanism of thesecurelevel/secureboot combination. (CVE-2015-7837, Low)

Affected Software

55 affected componentsFixes available
redhat/kernel<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-abi-whitelists<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-debug<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-debug-debuginfo<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-debug-devel<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-debuginfo<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-devel<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-doc<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-headers<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-tools<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-tools-debuginfo<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-tools-libs<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-tools-libs-devel<3.10.0-327.el7
3.10.0-327.el7
redhat/perf<3.10.0-327.el7
3.10.0-327.el7
redhat/perf-debuginfo<3.10.0-327.el7
3.10.0-327.el7
redhat/python-perf<3.10.0-327.el7
3.10.0-327.el7
redhat/python-perf-debuginfo<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-debug<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-debug-debuginfo<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-debug-devel<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-debuginfo<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-debuginfo-common-s390x<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-devel<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-headers<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-kdump<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-kdump-debuginfo<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-kdump-devel<3.10.0-327.el7
3.10.0-327.el7
redhat/perf<3.10.0-327.el7
3.10.0-327.el7
redhat/perf-debuginfo<3.10.0-327.el7
3.10.0-327.el7
redhat/python-perf<3.10.0-327.el7
3.10.0-327.el7
redhat/python-perf-debuginfo<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-bootwrapper<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-debuginfo-common-ppc64<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-tools<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-tools-debuginfo<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-tools-libs<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-tools-libs-devel<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-bootwrapper<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-debug<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-debug-debuginfo<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-debug-devel<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-debuginfo<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-debuginfo-common-ppc64le<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-devel<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-headers<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-tools<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-tools-debuginfo<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-tools-libs<3.10.0-327.el7
3.10.0-327.el7
redhat/kernel-tools-libs-devel<3.10.0-327.el7
3.10.0-327.el7
redhat/perf<3.10.0-327.el7
3.10.0-327.el7
redhat/perf-debuginfo<3.10.0-327.el7
3.10.0-327.el7
redhat/python-perf<3.10.0-327.el7
3.10.0-327.el7
redhat/python-perf-debuginfo<3.10.0-327.el7
3.10.0-327.el7

Remediation

Event History

Nov 19, 2015
Advisory Published
12:00 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2015:2152?

RHSA-2015:2152 is classified as important due to the potential exploitation of the vulnerability affecting the Linux kernel.

2

How do I fix RHSA-2015:2152?

To fix RHSA-2015:2152, update the kernel packages to version 3.10.0-327.el7 or later.

3

What systems are affected by RHSA-2015:2152?

RHSA-2015:2152 affects Red Hat Enterprise Linux 7 systems using kernel versions prior to 3.10.0-327.el7.

4

What is the impact of RHSA-2015:2152?

The impact of RHSA-2015:2152 includes potential privilege escalation via the affected kernel's file system operations.

5

Is a reboot required after applying the fix for RHSA-2015:2152?

Yes, a reboot is required to ensure that the updated kernel takes effect after applying the fix for RHSA-2015:2152.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203