First published: Tue Jan 26 2016(Updated: )
The kernel packages contain the Linux kernel, the core of any Linux<br>operating system.<br><li> A use-after-free flaw was found in the way the Linux kernel's key</li> management subsystem handled keyring object reference counting in certain<br>error path of the join_session_keyring() function. A local, unprivileged<br>user could use this flaw to escalate their privileges on the system.<br>(CVE-2016-0728, Important)<br>Red Hat would like to thank the Perception Point research team for<br>reporting this issue.<br>All kernel-rt users are advised to upgrade to these updated packages, which<br>contain a backported patch to correct this issue. The system must be<br>rebooted for this update to take effect.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel-rt | <3.10.0-327.rt56.170.el6 | 3.10.0-327.rt56.170.el6 |
redhat/kernel-rt-debug | <3.10.0-327.rt56.170.el6 | 3.10.0-327.rt56.170.el6 |
redhat/kernel-rt-debug-debuginfo | <3.10.0-327.rt56.170.el6 | 3.10.0-327.rt56.170.el6 |
redhat/kernel-rt-debug-devel | <3.10.0-327.rt56.170.el6 | 3.10.0-327.rt56.170.el6 |
redhat/kernel-rt-debuginfo | <3.10.0-327.rt56.170.el6 | 3.10.0-327.rt56.170.el6 |
redhat/kernel-rt-devel | <3.10.0-327.rt56.170.el6 | 3.10.0-327.rt56.170.el6 |
redhat/kernel-rt-doc | <3.10.0-327.rt56.170.el6 | 3.10.0-327.rt56.170.el6 |
redhat/kernel-rt-firmware | <3.10.0-327.rt56.170.el6 | 3.10.0-327.rt56.170.el6 |
redhat/kernel-rt-trace | <3.10.0-327.rt56.170.el6 | 3.10.0-327.rt56.170.el6 |
redhat/kernel-rt-trace-debuginfo | <3.10.0-327.rt56.170.el6 | 3.10.0-327.rt56.170.el6 |
redhat/kernel-rt-trace-devel | <3.10.0-327.rt56.170.el6 | 3.10.0-327.rt56.170.el6 |
redhat/kernel-rt-vanilla | <3.10.0-327.rt56.170.el6 | 3.10.0-327.rt56.170.el6 |
redhat/kernel-rt-vanilla-debuginfo | <3.10.0-327.rt56.170.el6 | 3.10.0-327.rt56.170.el6 |
redhat/kernel-rt-vanilla-devel | <3.10.0-327.rt56.170.el6 | 3.10.0-327.rt56.170.el6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.