RHSA-2015:2636: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linuxoperating system. A flaw was found in the way the Linux kernel's file system implementation handled rename operations in which the source was inside and thedestination was outside of a bind mount. A privileged user inside acontainer could use this flaw to escape the bind mount and, potentially,escalate their privileges on the system. (CVE-2015-2925, Important) It was found that the x86 ISA (Instruction Set Architecture) is prone to a denial of service attack inside a virtualized environment in the form ofan infinite loop in the microcode due to the way (sequential) delivering ofbenign exceptions such as #AC (alignment check exception) and #DB (debugexception) is handled. A privileged user inside a guest could use theseflaws to create denial of service conditions on the host kernel.(CVE-2015-5307, CVE-2015-8104, Important) A race condition flaw was found in the way the Linux kernel's IPC subsystem initialized certain fields in an IPC object structure that werelater used for permission checking before inserting the object into aglobally visible list. A local, unprivileged user could potentially usethis flaw to elevate their privileges on the system. (CVE-2015-7613,Important) It was found that the Linux kernel's keys subsystem did not correctly garbage collect uninstantiated keyrings. A local attacker could use thisflaw to crash the system or, potentially, escalate their privileges onthe system. (CVE-2015-7872, Important)Red Hat would like to thank Ben Serebrin of Google Inc. for reporting theCVE-2015-5307 issue.This update also fixes the following bugs: Previously, Human Interface Device (HID) ran a report on an unaligned buffer, which could cause a page fault interrupt and an oops when the endof the report was read. This update fixes this bug by padding the end ofthe report with extra bytes, so the reading of the report never crosses apage boundary. As a result, a page fault and subsequent oops no longeroccur. (BZ#1268203) The NFS client was previously failing to detect a directory loop for some NFS server directory structures. This failure could cause NFS inodes toremain referenced after attempting to unmount the file system, leading to akernel crash. Loop checks have been added to VFS, which effectivelyprevents this problem from occurring. (BZ#1272858) Due to a race whereby the nfswbpagescancel() and nfscommitreleasepages() calls both removed a request from the nfsinodestruct type, the kernel panicked with negative nfsinode.npages count.The provided upstream patch performs the required serialization by holdingthe inode ilock over the check of PagePrivate and locking the request,thus preventing the race and kernel panic from occurring. (BZ#1273721) Due to incorrect URBISOASAP semantics, playing an audio file using a USB sound card could previously fail for some hardware configurations.This update fixes the bug, and playing audio from a USB sound card nowworks as expected. (BZ#1273916) Inside hugetlb, region data structures were protected by a combination of a memory map semaphore and a single hugetlb instance mutex. However, apage-fault scalability improvement backported to the kernel on previousreleases removed the single hugetlb instance mutex and introduced a newmutex table, making the locking combination insufficient, leading topossible race windows that could cause corruption and undefined behavior.This update fixes the problem by introducing a required spinlock to theregion tracking functions for proper serialization. The problem onlyaffects software using huge pages through hugetlb interface. (BZ#1274599)All kernel users are advised to upgrade to these updated packages, whichcontain backported patches to correct these issues. The system must berebooted for this update to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2015:2636?
The severity of RHSA-2015:2636 is classified as moderate.
How do I fix RHSA-2015:2636?
To fix RHSA-2015:2636, update the kernel packages to version 2.6.32-573.12.1.el6 or newer.
Which systems are affected by RHSA-2015:2636?
RHSA-2015:2636 affects systems running the Linux kernel version prior to 2.6.32-573.12.1.el6.
What vulnerabilities does RHSA-2015:2636 address?
RHSA-2015:2636 addresses a flaw in the Linux kernel's file system implementation during rename operations.
Is it safe to ignore the RHSA-2015:2636 advisory?
It is not advisable to ignore RHSA-2015:2636, as it could pose a risk of privilege escalation.