Date: Tue, 25 Aug 2009 13:55:13 -0500 Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Important: kernel on SL4.x i386/x86_64 Comments: To: "scientific-linux-errata@fnal.gov" Synopsis: Important: kernel security update Issue date: 2009-08-24 CVE Names: CVE-2009-2692 CVE-2009-2698 CVE-2009-2692 kernel: uninit op in SOCKOPS_WRAP() leads to privesc CVE-2009-2698 kernel: udp socket NULL ptr dereference These updated packages fix the following security issues: * a flaw was found in the SOCKOPS_WRAP macro in the Linux kernel. This macro did not initialize the sendpage operation in the proto_ops structure correctly. A local, unprivileged user could use this flaw to cause a local denial of service or escalate their privileges. (CVE-2009-2692, Important) * a flaw was found in the udp_sendmsg() implementation in the Linux kernel when using the MSG_MORE flag on UDP sockets. A local, unprivileged user could use this flaw to cause a local denial of service or escalate their privileges. (CVE-2009-2698, Important) The system must be rebooted for this update to take effect. SL 4.x SRPMS: kernel-2.6.9-89.0.9.EL.src.rpm i386: kernel-2.6.9-89.0.9.EL.x86_64.rpm kernel-devel-2.6.9-89.0.9.EL.x86_64.rpm kernel-doc-2.6.9-89.0.9.EL.noarch.rpm kernel-largesmp-2.6.9-89.0.9.EL.x86_64.rpm kernel-largesmp-devel-2.6.9-89.0.9.EL.x86_64.rpm kernel-smp-2.6.9-89.0.9.EL.x86_64.rpm kernel-smp-devel-2.6.9-89.0.9.EL.x86_64.rpm kernel-xenU-2.6.9-89.0.9.EL.x86_64.rpm kernel-xenU-devel-2.6.9-89.0.9.EL.x86_64.rpm Dependancies: kernel-module-fuse-2.6.9-89.0.9.EL-2.7.3-1.SL.x86_64.rpm kernel-module-fuse-2.6.9-89.0.9.ELlargesmp-2.7.3-1.SL.x86_64.rpm kernel-module-fuse-2.6.9-89.0.9.ELsmp-2.7.3-1.SL.x86_64.rpm kernel-module-fuse-2.6.9-89.0.9.ELxenU-2.7.3-1.SL.x86_64.rpm kernel-module-ipw3945-2.6.9-89.0.9.EL-1.1.0-1.SL4.x86_64.rpm kernel-module-ipw3945-2.6.9-89.0.9.ELlargesmp-1.1.0-1.SL4.x86_64.rpm kernel-module-ipw3945-2.6.9-89.0.9.ELsmp-1.1.0-1.SL4.x86_64.rpm kernel-module-ipw3945-2.6.9-89.0.9.ELxenU-1.1.0-1.SL4.x86_64.rpm kernel-module-madwifi-2.6.9-89.0.9.EL-0.9.4-10.sl4.x86_64.rpm kernel-module-madwifi-2.6.9-89.0.9.ELlargesmp-0.9.4-10.sl4.x86_64.rpm kernel-module-madwifi-2.6.9-89.0.9.ELsmp-0.9.4-10.sl4.x86_64.rpm kernel-module-madwifi-hal-2.6.9-89.0.9.EL-0.9.4-10.sl4.x86_64.rpm kernel-module-madwifi-hal-2.6.9-89.0.9.ELlargesmp-0.9.4-10.sl4.x86_64.rpm kernel-module-madwifi-hal-2.6.9-89.0.9.ELsmp-0.9.4-10.sl4.x86_64.rpm kernel-module-ndiswrapper-2.6.9-89.0.9.EL-1.41-1.SL.x86_64.rpm kernel-module-ndiswrapper-2.6.9-89.0.9.ELlargesmp-1.41-1.SL.x86_64.rpm kernel-module-ndiswrapper-2.6.9-89.0.9.ELsmp-1.41-1.SL.x86_64.rpm kernel-module-ndiswrapper-2.6.9-89.0.9.ELxenU-1.41-1.SL.x86_64.rpm kernel-module-openafs-2.6.9-89.0.9.EL-1.4.7-68.2.SL4.x86_64.rpm kernel-module-openafs-2.6.9-89.0.9.ELlargesmp-1.4.7-68.2.SL4.x86_64.rpm kernel-module-openafs-2.6.9-89.0.9.ELsmp-1.4.7-68.2.SL4.x86_64.rpm kernel-module-openafs-2.6.9-89.0.9.ELxenU-1.4.7-68.2.SL4.x86_64.rpm kernel-module-r1000-2.6.9-89.0.9.EL-2.2-2.SL4x.x86_64.rpm kernel-module-r1000-2.6.9-89.0.9.ELlargesmp-2.2-2.SL4x.x86_64.rpm kernel-module-r1000-2.6.9-89.0.9.ELsmp-2.2-2.SL4x.x86_64.rpm kernel-module-r1000-2.6.9-89.0.9.ELxenU-2.2-2.SL4x.x86_64.rpm kernel-module-squashfs-2.6.9-89.0.9.EL-3.1.2-3.x86_64.rpm kernel-module-squashfs-2.6.9-89.0.9.ELlargesmp-3.1.2-3.x86_64.rpm kernel-module-squashfs-2.6.9-89.0.9.ELsmp-3.1.2-3.x86_64.rpm kernel-module-squashfs-2.6.9-89.0.9.ELxenU-3.1.2-3.x86_64.rpm kernel-module-unionfs-2.6.9-89.0.9.EL-1.1.5-3.x86_64.rpm kernel-module-unionfs-2.6.9-89.0.9.ELsmp-1.1.5-3.x86_64.rpm x86_64: kernel-2.6.9-89.0.9.EL.x86_64.rpm kernel-devel-2.6.9-89.0.9.EL.x86_64.rpm kernel-doc-2.6.9-89.0.9.EL.noarch.rpm kernel-largesmp-2.6.9-89.0.9.EL.x86_64.rpm kernel-largesmp-devel-2.6.9-89.0.9.EL.x86_64.rpm kernel-smp-2.6.9-89.0.9.EL.x86_64.rpm kernel-smp-devel-2.6.9-89.0.9.EL.x86_64.rpm kernel-xenU-2.6.9-89.0.9.EL.x86_64.rpm kernel-xenU-devel-2.6.9-89.0.9.EL.x86_64.rpm Dependancies: kernel-module-fuse-2.6.9-89.0.9.EL-2.7.3-1.SL.x86_64.rpm kernel-module-fuse-2.6.9-89.0.9.ELlargesmp-2.7.3-1.SL.x86_64.rpm kernel-module-fuse-2.6.9-89.0.9.ELsmp-2.7.3-1.SL.x86_64.rpm kernel-module-fuse-2.6.9-89.0.9.ELxenU-2.7.3-1.SL.x86_64.rpm kernel-module-ipw3945-2.6.9-89.0.9.EL-1.1.0-1.SL4.x86_64.rpm kernel-module-ipw3945-2.6.9-89.0.9.ELlargesmp-1.1.0-1.SL4.x86_64.rpm kernel-module-ipw3945-2.6.9-89.0.9.ELsmp-1.1.0-1.SL4.x86_64.rpm kernel-module-ipw3945-2.6.9-89.0.9.ELxenU-1.1.0-1.SL4.x86_64.rpm kernel-module-madwifi-2.6.9-89.0.9.EL-0.9.4-10.sl4.x86_64.rpm kernel-module-madwifi-2.6.9-89.0.9.ELlargesmp-0.9.4-10.sl4.x86_64.rpm kernel-module-madwifi-2.6.9-89.0.9.ELsmp-0.9.4-10.sl4.x86_64.rpm kernel-module-madwifi-hal-2.6.9-89.0.9.EL-0.9.4-10.sl4.x86_64.rpm kernel-module-madwifi-hal-2.6.9-89.0.9.ELlargesmp-0.9.4-10.sl4.x86_64.rpm kernel-module-madwifi-hal-2.6.9-89.0.9.ELsmp-0.9.4-10.sl4.x86_64.rpm kernel-module-ndiswrapper-2.6.9-89.0.9.EL-1.41-1.SL.x86_64.rpm kernel-module-ndiswrapper-2.6.9-89.0.9.ELlargesmp-1.41-1.SL.x86_64.rpm kernel-module-ndiswrapper-2.6.9-89.0.9.ELsmp-1.41-1.SL.x86_64.rpm kernel-module-ndiswrapper-2.6.9-89.0.9.ELxenU-1.41-1.SL.x86_64.rpm kernel-module-openafs-2.6.9-89.0.9.EL-1.4.7-68.2.SL4.x86_64.rpm kernel-module-openafs-2.6.9-89.0.9.ELlargesmp-1.4.7-68.2.SL4.x86_64.rpm kernel-module-openafs-2.6.9-89.0.9.ELsmp-1.4.7-68.2.SL4.x86_64.rpm kernel-module-openafs-2.6.9-89.0.9.ELxenU-1.4.7-68.2.SL4.x86_64.rpm kernel-module-r1000-2.6.9-89.0.9.EL-2.2-2.SL4x.x86_64.rpm kernel-module-r1000-2.6.9-89.0.9.ELlargesmp-2.2-2.SL4x.x86_64.rpm kernel-module-r1000-2.6.9-89.0.9.ELsmp-2.2-2.SL4x.x86_64.rpm kernel-module-r1000-2.6.9-89.0.9.ELxenU-2.2-2.SL4x.x86_64.rpm kernel-module-squashfs-2.6.9-89.0.9.EL-3.1.2-3.x86_64.rpm kernel-module-squashfs-2.6.9-89.0.9.ELlargesmp-3.1.2-3.x86_64.rpm kernel-module-squashfs-2.6.9-89.0.9.ELsmp-3.1.2-3.x86_64.rpm kernel-module-squashfs-2.6.9-89.0.9.ELxenU-3.1.2-3.x86_64.rpm kernel-module-unionfs-2.6.9-89.0.9.EL-1.1.5-3.x86_64.rpm kernel-module-unionfs-2.6.9-89.0.9.ELsmp-1.1.5-3.x86_64.rpm -Connie Sieh -Troy Dawson