Date:         Mon, 18 Jun 2007 15:57:56 -0500
Reply-To:     Troy Dawson 
Sender:       Security Errata for Scientific Linux
              
From:         Troy Dawson 
Subject:      Security ERRATA for kernel on SL3,x i386/x86_64
Comments: To: scientific-linux-errata@fnal.gov

Synopsis:	Important: Updated kernel packages for Scientific Linux 3.0.x
Issue date:	2007-06-11
CVE Names:	CVE-2006-5823 CVE-2006-6054 CVE-2007-1592

There were no new features introduced by this update.  The only changes
that have been included address critical customer needs or security
issues (elaborated below).

Key areas affected by fixes in this update include the networking
subsystem, dcache handling, the ext2 and ext3 file systems, the USB
subsystem, ACPI handling, and the audit subsystem.  There were also
several isolated fixes in the tg3, e1000, megaraid_sas, and aacraid
device drivers.

The following security bugs were fixed in this update:

  * a flaw in the cramfs file system that allowed invalid compressed
     data to cause memory corruption (CVE-2006-5823, low)

  * a flaw in the ext2 file system that allowed an invalid inode size
     to cause a denial of service (system hang)  (CVE-2006-6054, low)

  * a flaw in IPV6 flow label handling that allowed a local user to
     cause a denial of service (crash)  (CVE-2007-1592, important)

SL 3.0.x

   SRPMS:
	kernel-2.4.21-50.EL.src.rpm
   i386:
	kernel-2.4.21-50.EL.athlon.rpm
	kernel-2.4.21-50.EL.i686.rpm
	kernel-BOOT-2.4.21-50.EL.i386.rpm
	kernel-doc-2.4.21-50.EL.i386.rpm
	kernel-hugemem-2.4.21-50.EL.i686.rpm
	kernel-hugemem-unsupported-2.4.21-50.EL.i686.rpm
	kernel-smp-2.4.21-50.EL.athlon.rpm
	kernel-smp-2.4.21-50.EL.i686.rpm
	kernel-smp-unsupported-2.4.21-50.EL.athlon.rpm
	kernel-smp-unsupported-2.4.21-50.EL.i686.rpm
	kernel-source-2.4.21-50.EL.i386.rpm
	kernel-unsupported-2.4.21-50.EL.athlon.rpm
	kernel-unsupported-2.4.21-50.EL.i686.rpm
Dependancies:
  kernel-module-openafs-2.4.21-50.EL-1.2.13-15.17.SL.athlon.rpm
  kernel-module-openafs-2.4.21-50.EL-1.2.13-15.17.SL.i686.rpm
  kernel-module-openafs-2.4.21-50.ELsmp-1.2.13-15.17.SL.athlon.rpm
  kernel-module-openafs-2.4.21-50.ELsmp-1.2.13-15.17.SL.i686.rpm
  GFS-6.0.2.36-2.i686.rpm
  GFS-devel-6.0.2.36-2.i686.rpm
  GFS-modules-6.0.2.36-2.i686.rpm
  GFS-modules-hugemem-6.0.2.36-2.i686.rpm
  GFS-modules-smp-6.0.2.36-2.i686.rpm

   x86_64:
	kernel-2.4.21-50.EL.ia32e.rpm
	kernel-2.4.21-50.EL.x86_64.rpm
	kernel-doc-2.4.21-50.EL.x86_64.rpm
	kernel-smp-2.4.21-50.EL.x86_64.rpm
	kernel-smp-unsupported-2.4.21-50.EL.x86_64.rpm
	kernel-source-2.4.21-50.EL.x86_64.rpm
	kernel-unsupported-2.4.21-50.EL.ia32e.rpm
	kernel-unsupported-2.4.21-50.EL.x86_64.rpm
Dependancies:
  kernel-module-openafs-2.4.21-50.EL-1.2.13-15.17.SL.ia32e.rpm
  kernel-module-openafs-2.4.21-50.EL-1.2.13-15.17.SL.x86_64.rpm
  kernel-module-openafs-2.4.21-50.ELsmp-1.2.13-15.17.SL.x86_64.rpm
  GFS-6.0.2.36-2.x86_64.rpm
  GFS-devel-6.0.2.36-2.x86_64.rpm
  GFS-modules-6.0.2.36-2.x86_64.rpm
  GFS-modules-smp-6.0.2.36-2.x86_64.rpm


-Connie Sieh
-Troy Dawson

SciLinux: CVE-2006-5823 kernel SL3,x i386/x86_64

Important: Updated kernel packages for Scientific Linux 3.0.x

Summary

Date:         Mon, 18 Jun 2007 15:57:56 -0500Reply-To:     Troy Dawson Sender:       Security Errata for Scientific Linux              From:         Troy Dawson Subject:      Security ERRATA for kernel on SL3,x i386/x86_64Comments: To: scientific-linux-errata@fnal.govSynopsis:	Important: Updated kernel packages for Scientific Linux 3.0.xIssue date:	2007-06-11CVE Names:	CVE-2006-5823 CVE-2006-6054 CVE-2007-1592There were no new features introduced by this update.  The only changesthat have been included address critical customer needs or securityissues (elaborated below).Key areas affected by fixes in this update include the networkingsubsystem, dcache handling, the ext2 and ext3 file systems, the USBsubsystem, ACPI handling, and the audit subsystem.  There were alsoseveral isolated fixes in the tg3, e1000, megaraid_sas, and aacraiddevice drivers.The following security bugs were fixed in this update:  * a flaw in the cramfs file system that allowed invalid compressed     data to cause memory corruption (CVE-2006-5823, low)  * a flaw in the ext2 file system that allowed an invalid inode size     to cause a denial of service (system hang)  (CVE-2006-6054, low)  * a flaw in IPV6 flow label handling that allowed a local user to     cause a denial of service (crash)  (CVE-2007-1592, important)SL 3.0.x   SRPMS:	kernel-2.4.21-50.EL.src.rpm   i386:	kernel-2.4.21-50.EL.athlon.rpm	kernel-2.4.21-50.EL.i686.rpm	kernel-BOOT-2.4.21-50.EL.i386.rpm	kernel-doc-2.4.21-50.EL.i386.rpm	kernel-hugemem-2.4.21-50.EL.i686.rpm	kernel-hugemem-unsupported-2.4.21-50.EL.i686.rpm	kernel-smp-2.4.21-50.EL.athlon.rpm	kernel-smp-2.4.21-50.EL.i686.rpm	kernel-smp-unsupported-2.4.21-50.EL.athlon.rpm	kernel-smp-unsupported-2.4.21-50.EL.i686.rpm	kernel-source-2.4.21-50.EL.i386.rpm	kernel-unsupported-2.4.21-50.EL.athlon.rpm	kernel-unsupported-2.4.21-50.EL.i686.rpmDependancies:  kernel-module-openafs-2.4.21-50.EL-1.2.13-15.17.SL.athlon.rpm  kernel-module-openafs-2.4.21-50.EL-1.2.13-15.17.SL.i686.rpm  kernel-module-openafs-2.4.21-50.ELsmp-1.2.13-15.17.SL.athlon.rpm  kernel-module-openafs-2.4.21-50.ELsmp-1.2.13-15.17.SL.i686.rpm  GFS-6.0.2.36-2.i686.rpm  GFS-devel-6.0.2.36-2.i686.rpm  GFS-modules-6.0.2.36-2.i686.rpm  GFS-modules-hugemem-6.0.2.36-2.i686.rpm  GFS-modules-smp-6.0.2.36-2.i686.rpm   x86_64:	kernel-2.4.21-50.EL.ia32e.rpm	kernel-2.4.21-50.EL.x86_64.rpm	kernel-doc-2.4.21-50.EL.x86_64.rpm	kernel-smp-2.4.21-50.EL.x86_64.rpm	kernel-smp-unsupported-2.4.21-50.EL.x86_64.rpm	kernel-source-2.4.21-50.EL.x86_64.rpm	kernel-unsupported-2.4.21-50.EL.ia32e.rpm	kernel-unsupported-2.4.21-50.EL.x86_64.rpmDependancies:  kernel-module-openafs-2.4.21-50.EL-1.2.13-15.17.SL.ia32e.rpm  kernel-module-openafs-2.4.21-50.EL-1.2.13-15.17.SL.x86_64.rpm  kernel-module-openafs-2.4.21-50.ELsmp-1.2.13-15.17.SL.x86_64.rpm  GFS-6.0.2.36-2.x86_64.rpm  GFS-devel-6.0.2.36-2.x86_64.rpm  GFS-modules-6.0.2.36-2.x86_64.rpm  GFS-modules-smp-6.0.2.36-2.x86_64.rpm-Connie Sieh-Troy Dawson



Security Fixes

Severity

Related News