RHSA-2017:0501: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): A use-after-free flaw was found in the way the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation freed SKB (socket buffer) resources for a DCCPPKTREQUEST packet when the IPV6RECVPKTINFO option is set on the socket. A local, unprivileged user could use this flaw to alter the kernel memory, allowing them to escalate their privileges on the system. (CVE-2017-6074, Important) Red Hat would like to thank Andrey Konovalov (Google) for reporting this issue.Bug Fix(es): Previously, running the "ethtool -S" command to get the statistics of a Brocade Network Adapter (BNA) sometimes caused a kernel panic. This update applies a set of patches to the bna driver, and the kernel panic no longer occurs in the described scenario. (BZ#1408130) Use of a multi-threaded workload with high memory mappings sometimes caused a kernel panic, due to a race condition between the context switch and the pagetable upgrade. This update fixes the switchmm() by using the complete asce parameter instead of the ascebits parameter. As a result, the kernel no longer panics in the described scenario. (BZ#1410865) Previously, the kernel was sending a Transmission Control Protocol (TCP) window which had a size of zero for a socket with an empty receive queue. Consequently, the TCP session became unresponsive. This update fixes the ibmveth driver to set correct values of the gsosize and gsotype variables and to calculate the value of the gsosegs variable for large packets. As a result, the TCP session no longer hangs in the described scenario. (BZ#1411381) Previously, booting a kdump kernel in some cases failed with this error: Kernel panic - not syncing: Watchdog detected hard LOCKUP on CPU 0.This update ensures that the hpet timer software counters, including hpetdefaultdelta and hpett1cmp, are initialized before an interrupt request is registered, and the kdump kernel now boots without the mentioned error message. (BZ#1404183) When one of the drives became unresponsive, all other drives intermittently hung, because the megaraidsas driver incorrectly sent a reset request to the PowerEdge RAID Controller (PERC). This update fixes megaraidsas, and thus the hang of one drive no longer leads to intermittent loss of access to all drives on the system. (BZ#1398174)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability associated with RHSA-2017:0501?
RHSA-2017:0501 addresses a use-after-free flaw in the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation.
What is the severity level of RHSA-2017:0501?
The severity level of RHSA-2017:0501 is classified as important.
How do I fix the issue identified in RHSA-2017:0501?
To fix the issue in RHSA-2017:0501, update to the kernel version 3.10.0-327.49.2.el7 or later.
What systems are affected by RHSA-2017:0501?
The vulnerability RHSA-2017:0501 affects various Linux distributions using the specified kernel version.
Is there a workaround for the vulnerability described in RHSA-2017:0501?
There are no specific workarounds for the vulnerability RHSA-2017:0501; patching is recommended.