RHSA-2017:0316: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): A use-after-free flaw was found in the way the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation freed SKB (socket buffer) resources for a DCCPPKTREQUEST packet when the IPV6RECVPKTINFO option is set on the socket. A local, unprivileged user could use this flaw to alter the kernel memory, allowing them to escalate their privileges on the system. (CVE-2017-6074, Important) Red Hat would like to thank Andrey Konovalov (Google) for reporting this issue.Bug Fix(es): When an NFS server received a compound Remote Procedure Call (RPC) with multiple operations where the SECINFO operation was the ninth or later operation, the server terminated unexpectedly. This update fixes the NFS server to correctly initialize all arguments of all compound RPC operations that are beyond the first eight operations. As a result, the NFS server no longer crashes in the described situation. (BZ#1413035)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2017:0316?
The severity of RHSA-2017:0316 is classified as important.
How do I fix RHSA-2017:0316?
To fix RHSA-2017:0316, update the kernel packages to version 2.6.32-573.40.1.el6 or later.
What systems are affected by RHSA-2017:0316?
RHSA-2017:0316 affects systems running the 2.6.32 kernel version prior to 2.6.32-573.40.1.el6.
What vulnerability does RHSA-2017:0316 address?
RHSA-2017:0316 addresses a use-after-free vulnerability in the Linux kernel's Datagram Congestion Control Protocol implementation.
Are there any specific packages impacted by RHSA-2017:0316?
Yes, packages like kernel, kernel-debug, and kernel-devel for the affected version are impacted by RHSA-2017:0316.