Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Scientific Linux 6: 2014:0328-1 Important Kernel Update

Scientific Large Esm H446
Important: kernel security and bug fix update
Date: Tue, 25 Mar 2014 10:07:10 -0500
Reply-To: Bonnie King 
Sender: Security Errata for Scientific Linux
 
From: Bonnie King 
Subject: FASTBUGS for SL 6x i386, x86_64 now available
Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it.
In-Reply-To: <5328767C.1010900@fnal.gov>
MIME-Version: 1.0

The following FASTBUGS have been uploaded to

i386:
autofs-5.0.5-89.el6_5.1.i686.rpm
dmidecode-2.12-5.el6_5.i686.rpm
environment-modules-3.2.10-1.el6_5.i686.rpm
grep-2.6.3-4.el6_5.1.i686.rpm
quota-3.17-21.el6_5.i686.rpm
quota-devel-3.17-21.el6_5.i686.rpm
spice-vdagent-0.14.0-3.el6_5.i686.rpm

x86_64:
autofs-5.0.5-89.el6_5.1.x86_64.rpm
dmidecode-2.12-5.el6_5.x86_64.rpm
environment-modules-3.2.10-1.el6_5.x86_64.rpm
grep-2.6.3-4.el6_5.1.x86_64.rpm
quota-3.17-21.el6_5.x86_64.rpm
quota-devel-3.17-21.el6_5.i686.rpm
quota-devel-3.17-21.el6_5.x86_64.rpm
spice-vdagent-0.14.0-3.el6_5.x86_64.rpm
Date: Tue, 25 Mar 2014 21:07:58 +0000
Reply-To: scientific-linux-users@
Sender: Security Errata for Scientific Linux
 
From: Pat Riehecky 
Subject: Security ERRATA Important: kernel on SL6.x i386/x86_64
MIME-Version: 1.0

Synopsis: Important: kernel security and bug fix update
Advisory ID: SLSA-2014:0328-1
Issue Date: 2014-03-25
CVE Numbers: CVE-2013-1860
 CVE-2014-0055
 CVE-2014-0069
 CVE-2014-0101
--

* A flaw was found in the way the get_rx_bufs() function in the vhost_net
implementation in the Linux kernel handled error conditions reported by
the vhost_get_vq_desc() function. A privileged guest user could use this
flaw to crash the host. (CVE-2014-0055, Important)

* A flaw was found in the way the Linux kernel processed an authenticated
COOKIE_ECHO chunk during the initialization of an SCTP connection. A
remote attacker could use this flaw to crash the system by initiating a
specially crafted SCTP handshake in order to trigger a NULL pointer
dereference on the system. (CVE-2014-0101, Important)

* A flaw was found in the way the Linux kernel's CIFS implementation
handled uncached write operations with specially crafted iovec structures.
An unprivileged local user with access to a CIFS share could use this flaw
to crash the system, leak kernel memory, or, potentially, escalate their
privileges on the system. Note: the default cache settings for CIFS mounts
on Scientific Linux 6 prohibit a successful exploitation of this issue.
(CVE-2014-0069, Moderate)

* A heap-based buffer overflow flaw was found in the Linux kernel's cdc-
wdm driver, used for USB CDC WCM device management. An attacker with
physical access to a system could use this flaw to cause a denial of
service or, potentially, escalate their privileges. (CVE-2013-1860, Low)

The system must be rebooted for this update to take effect.
--

SL6
 x86_64
 kernel-2.6.32-431.11.2.el6.x86_64.rpm
 kernel-debug-2.6.32-431.11.2.el6.x86_64.rpm
 kernel-debug-debuginfo-2.6.32-431.11.2.el6.x86_64.rpm
 kernel-debug-devel-2.6.32-431.11.2.el6.x86_64.rpm
 kernel-debuginfo-2.6.32-431.11.2.el6.x86_64.rpm
 kernel-debuginfo-common-x86_64-2.6.32-431.11.2.el6.x86_64.rpm
 kernel-devel-2.6.32-431.11.2.el6.x86_64.rpm
 kernel-headers-2.6.32-431.11.2.el6.x86_64.rpm
 perf-2.6.32-431.11.2.el6.x86_64.rpm
 perf-debuginfo-2.6.32-431.11.2.el6.x86_64.rpm
 python-perf-debuginfo-2.6.32-431.11.2.el6.x86_64.rpm
 python-perf-2.6.32-431.11.2.el6.x86_64.rpm
 i386
 kernel-2.6.32-431.11.2.el6.i686.rpm
 kernel-debug-2.6.32-431.11.2.el6.i686.rpm
 kernel-debug-debuginfo-2.6.32-431.11.2.el6.i686.rpm
 kernel-debug-devel-2.6.32-431.11.2.el6.i686.rpm
 kernel-debuginfo-2.6.32-431.11.2.el6.i686.rpm
 kernel-debuginfo-common-i686-2.6.32-431.11.2.el6.i686.rpm
 kernel-devel-2.6.32-431.11.2.el6.i686.rpm
 kernel-headers-2.6.32-431.11.2.el6.i686.rpm
 perf-2.6.32-431.11.2.el6.i686.rpm
 perf-debuginfo-2.6.32-431.11.2.el6.i686.rpm
 python-perf-debuginfo-2.6.32-431.11.2.el6.i686.rpm
 python-perf-2.6.32-431.11.2.el6.i686.rpm
 noarch
 kernel-abi-whitelists-2.6.32-431.11.2.el6.noarch.rpm
 kernel-doc-2.6.32-431.11.2.el6.noarch.rpm
 kernel-firmware-2.6.32-431.11.2.el6.noarch.rpm

- Scientific Linux Development Team