Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
200

Scientific Linux SL4 CVE-2006-5158 Important Denial of Service Kernel Update

Important: kernel security update. Date: Wed, 27 Jun 2007 15:27:22 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for kernel on SL4.x i386/x86_64 Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it. Synopsis: Important: kernel security update Issue date: 2007-06-25 CVE Names: CVE-2006-5158 CVE-2006-7203 CVE-2007-0773 CVE-2007-0958 CVE-2007-1353 CVE-2007-2172 CVE-2007-2525 CVE-2007-2876 CVE-2007-3104 These new kernel packages contain fixes for the security issues described below: * a flaw in the connection tracking support for SCTP that allowed a remote user to cause a denial of service by dereferencing a NULL pointer. (CVE-2007-2876, Important) * a flaw in the mount handling routine for 64-bit systems that allowed a local user to cause denial of service (crash). (CVE-2006-7203, Important) * a flaw in the IPv4 forwarding base that allowed a local user to cause an out-of-bounds access. (CVE-2007-2172, Important) * a flaw in the PPP over Ethernet implementation that allowed a local user to cause a denial of service (memory consumption) by creating a socket using connect and then releasing it before the PPPIOCGCHAN ioctl has been called. (CVE-2007-2525, Important) * a flaw in the fput ioctl handling of 32-bit applications running on 64-bit platforms that allowed a local user to cause a denial of service (panic). (CVE-2007-0773, Important) * a flaw in the NFS locking daemon that allowed a local user to cause denial of service (deadlock). (CVE-2006-5158, Moderate) * a flaw in the sysfs_readdir function that allowed a local user to cause a denial of service by dereferencing a NULL pointer. (CVE-2007-3104, Moderate) * a flaw in the core-dump handling that allowed a local user to create core dumps from unreadable binaries via PT_INTERP. (CVE-2007-0958, Low) * a flaw in the Bluetooth subsystem that allowed a local user to trigger an information leak. (CVE-2007-1353, Low) In addition, the following bugs were addressed: * the NFS couldrecurse on the same spinlock. Also, NFS, under certain conditions, did not completely clean up Posix locks on a file close, leading to mount failures. * the 32bit compatibility didn't return to userspace correct values for the rt_sigtimedwait system call. * the count for unused inodes could be incorrect at times, resulting in dirty data not being written to disk in a timely manner. * the cciss driver had an incorrect disk size calculation (off-by-one error) which prevented disk dumps. NOTE1: From The Upstream Vendors release notes "During PCI probing, Red Hat Enterprise Linux 4 Update 5 attempts to use information obtained from MCFG (memory-mapped PCI configuration space). On AMD-systems, this type of access does not work on some buses, as the kernel cannot parse the MCFG table. To work around this, add the parameter pci=conf1 or pci=nommconf on the kernel boot line in /etc/grub.conf. For example: title Red Hat Enterprise Linux AS (2.6.9-42.0.2.EL) root (hd0,0) kernel /vmlinuz-2.6.9-42.0.2.EL ro root=/dev/VolGroup00/LogVol00 rhgb quiet pci=conf1 initrd /initrd-2.6.9-42.0.2.EL.img Doing this instructs the kernel to use PCI Conf1 access instead of MCFG-based access." NOTE2: From The Upstream Vendors Knowledge Base "Why did the ordering of my NIC devices change in Red Hat Enterprise Linux 4.5? The 2.6.9-55 version of the Red Hat Enterprise Linux 4 kernel (Update 5) reverts to the 2.4 ordering of network interface cards (NICs) on certain systems. Note that if the "HWADDR=MAC ADDRESS" line is present in the /etc/sysconfig/network-scripts/ifcfg-ethX files, the NIC ordering will not change. To restore the original 2.6 ordering, which is different from the 2.4 ordering, boot with the option pci=nobfsort " SL 4.x SRPMS: kernel-2.6.9-55.0.2.EL.src.rpm i386: kernel-2.6.9-55.0.2.EL.i686.rpm kernel-devel-2.6.9-55.0.2.EL.i686.rpm kernel-doc-2.6.9-55.0.2.EL.noarch.rpm kernel-hugemem-2.6.9-55.0.2.EL.i686.rpm kernel-hugemem-devel-2.6.9-55.0.2.EL.i686.rpm kernel-smp-2.6.9-55.0.2.EL.i686.rpm kernel-smp-devel-2.6.9-55.0.2.EL.i686.rpm kernel-xenU-2.6.9-55.0.2.EL.i686.rpm kernel-xenU-devel-2.6.9-55.0.2.EL.i686.rpm Dependancies: kernel-module-fuse-2.6.9-55.0.2.EL-2.5.3-1.SL.i686.rpm kernel-module-fuse-2.6.9-55.0.2.ELhugemem-2.5.3-1.SL.i686.rpm kernel-module-fuse-2.6.9-55.0.2.ELsmp-2.5.3-1.SL.i686.rpm kernel-module-fuse-2.6.9-55.0.2.ELxenU-2.5.3-1.SL.i686.rpm kernel-module-ipw3945-2.6.9-55.0.2.EL-1.1.0-1.SL4.i686.rpm kernel-module-ipw3945-2.6.9-55.0.2.ELhugemem-1.1.0-1.SL4.i686.rpm kernel-module-ipw3945-2.6.9-55.0.2.ELsmp-1.1.0-1.SL4.i686.rpm kernel-module-ipw3945-2.6.9-55.0.2.ELxenU-1.1.0-1.SL4.i686.rpm kernel-module-madwifi-2.6.9-55.0.2.EL-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-2.6.9-55.0.2.ELhugemem-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-2.6.9-55.0.2.ELsmp-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-hal-2.6.9-55.0.2.EL-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-hal-2.6.9-55.0.2.ELhugemem-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-hal-2.6.9-55.0.2.ELsmp-0.9.3.1-10.sl4.i686.rpm kernel-module-ndiswrapper-2.6.9-55.0.2.EL-1.41-1.SL.i686.rpm kernel-module-ndiswrapper-2.6.9-55.0.2.ELhugemem-1.41-1.SL.i686.rpm kernel-module-ndiswrapper-2.6.9-55.0.2.ELsmp-1.41-1.SL.i686.rpm kernel-module-ndiswrapper-2.6.9-55.0.2.ELxenU-1.41-1.SL.i686.rpm kernel-module-openafs-2.6.9-55.0.2.EL-1.4.4-46.SL4.i686.rpm kernel-module-openafs-2.6.9-55.0.2.ELhugemem-1.4.4-46.SL4.i686.rpm kernel-module-openafs-2.6.9-55.0.2.ELsmp-1.4.4-46.SL4.i686.rpm kernel-module-openafs-2.6.9-55.0.2.ELxenU-1.4.4-46.SL4.i686.rpm kernel-module-r1000-2.6.9-55.0.2.EL-2.2-2.SL4x.i686.rpm kernel-module-r1000-2.6.9-55.0.2.ELhugemem-2.2-2.SL4x.i686.rpm kernel-module-r1000-2.6.9-55.0.2.ELsmp-2.2-2.SL4x.i686.rpm kernel-module-r1000-2.6.9-55.0.2.ELxenU-2.2-2.SL4x.i686.rpm x86_64: kernel-2.6.9-55.0.2.EL.x86_64.rpm kernel-devel-2.6.9-55.0.2.EL.x86_64.rpm kernel-doc-2.6.9-55.0.2.EL.noarch.rpm kernel-largesmp-2.6.9-55.0.2.EL.x86_64.rpm kernel-largesmp-devel-2.6.9-55.0.2.EL.x86_64.rpm kernel-smp-2.6.9-55.0.2.EL.x86_64.rpm kernel-smp-devel-2.6.9-55.0.2.EL.x86_64.rpm kernel-xenU-2.6.9-55.0.2.EL.x86_64.rpm kernel-xenU-devel-2.6.9-55.0.2.EL.x86_64.rpm Dependancies: kernel-module-fuse-2.6.9-55.0.2.EL-2.5.3-1.SL.x86_64.rpm kernel-module-fuse-2.6.9-55.0.2.ELlargesmp-2.5.3-1.SL.x86_64.rpm kernel-module-fuse-2.6.9-55.0.2.ELsmp-2.5.3-1.SL.x86_64.rpm kernel-module-fuse-2.6.9-55.0.2.ELxenU-2.5.3-1.SL.x86_64.rpm kernel-module-ipw3945-2.6.9-55.0.2.EL-1.1.0-1.SL4.x86_64.rpm kernel-module-ipw3945-2.6.9-55.0.2.ELlargesmp-1.1.0-1.SL4.x86_64.rpm kernel-module-ipw3945-2.6.9-55.0.2.ELsmp-1.1.0-1.SL4.x86_64.rpm kernel-module-ipw3945-2.6.9-55.0.2.ELxenU-1.1.0-1.SL4.x86_64.rpm kernel-module-madwifi-2.6.9-55.0.2.EL-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-2.6.9-55.0.2.ELlargesmp-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-2.6.9-55.0.2.ELsmp-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-hal-2.6.9-55.0.2.EL-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-hal-2.6.9-55.0.2.ELlargesmp-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-hal-2.6.9-55.0.2.ELsmp-0.9.3.1-10.sl4.x86_64.rpm kernel-module-ndiswrapper-2.6.9-55.0.2.EL-1.41-1.SL.x86_64.rpm kernel-module-ndiswrapper-2.6.9-55.0.2.ELlargesmp-1.41-1.SL.x86_64.rpm kernel-module-ndiswrapper-2.6.9-55.0.2.ELsmp-1.41-1.SL.x86_64.rpm kernel-module-ndiswrapper-2.6.9-55.0.2.ELxenU-1.41-1.SL.x86_64.rpm kernel-module-openafs-2.6.9-55.0.2.EL-1.4.4-46.SL4.x86_64.rpm kernel-module-openafs-2.6.9-55.0.2.ELlargesmp-1.4.4-46.SL4.x86_64.rpm kernel-module-openafs-2.6.9-55.0.2.ELsmp-1.4.4-46.SL4.x86_64.rpm kernel-module-openafs-2.6.9-55.0.2.ELxenU-1.4.4-46.SL4.x86_64.rpm kernel-module-r1000-2.6.9-55.0.2.EL-2.2-2.SL4x.x86_64.rpm kernel-module-r1000-2.6.9-55.0.2.ELlargesmp-2.2-2.SL4x.x86_64.rpm kernel-module-r1000-2.6.9-55.0.2.ELsmp-2.2-2.SL4x.x86_64.rpm kernel-module-r1000-2.6.9-55.0.2.ELxenU-2.2-2.SL4x.x86_64.rpm The upstream vendor has not released the GFS src.rpm yet. When they release it we will rebuild and send it out. -Connie Sieh -Troy Dawson . Upgrade your Scientific Linux SL4 kernel to mitigate critical denial of service issues affecting system stability.. kernel Security Update, Scientific Linux SL4, Denial Of Service Issues. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 27, 2007 Important Scientific Linux
98

Red Hat Linux 7.1 and 7.2: RHSA-2002:028-13 Critical Kernel IRC Issue

The Linux Netfilter team has found a problem in the "IRC connectiontracking" component of the firewall within the linux kernel. This problemaffects Red Hat Linux versions 7.1 and 7.2.. ` -------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: Updated 2.4 kernel available Advisory ID: RHSA-2002:028-13 Issue date: 2002-02-13 Updated on: 2002-02-27 Product: Red Hat Linux Keywords: irc connection tracking netfilter lcall Cross references: Obsoletes: RHSA-2002:007 --------------------------------------------------------------------- 1. Topic: The Linux Netfilter team has found a problem in the "IRC connection tracking" component of the firewall within the linux kernel. This problem affects Red Hat Linux versions 7.1 and 7.2. 2. Relevant releases/architectures: Red Hat Linux 7.1 - alpha, athlon, i386, i586, i686, ia64 Red Hat Linux 7.2 - athlon, i386, i586, i686, ia64, s390 3. Problem description: The Linux Netfilter team has found a problem in the IRC connection tracking component of the firewall within the linux kernel. This component is distributed with kernels in Red Hat Linux 7.1 and 7.2, although it is not used in default installations. The problem consists of an excessively broad netmask setting which is applied to check if an "IRC DCC" connection through a masquerading firewall should be allowed. This results in unwanted ports being opened on the firewall, which could, depending on the firewall filter ruleset, allow inbound connections. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2002-0060 to this issue. Thanks to Jozsef Kadlecsik and Harald Welte of the netfilter team. Users are advised to upgrade to this errata kernel containing patches which fix these issues. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. Red Hat Linux 7.1 usersshould update the packages in the XFree86 Erratum (RHEA-2002:010). The procedure for upgrading the kernel is documented at: Support Please read the directions for your architecture carefully before proceeding with the kernel upgrade. Please note that this update is also available via Red Hat Network. Many people find this to be an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. Note that you need to select the kernel explicitly on default configurations of up2date. Note for customers using Red Hat Linux for the IBM s/390: Users of Red Hat Linux for the IBM s/390 with binary only kernel modules (OCO) should contact their vendor to obtain updated modules for this kernel patch. 5. Bug IDs fixed ( for more info): 6. RPMs required: Red Hat Linux 7.1: SRPMS: alpha: athlon: i386: i586: i686: ia64: Red Hat Linux 7.2: SRPMS: athlon: i386: i586: i686: ia64: s390: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- 599a9027496067a54b46716c4af2184a 7.1/en/os/SRPMS/kernel-2.4.9-31.src.rpm 4bccc363fdf0f00805ef4c34bbf8b43d 7.1/en/os/alpha/kernel-2.4.9-31.alpha.rpm 92f4dd670944fd607181089b04a1dcd9 7.1/en/os/alpha/kernel-BOOT-2.4.9-31.alpha.rpm 5cb53f48285237d8027b17604ab39616 7.1/en/os/alpha/kernel-doc-2.4.9-31.alpha.rpm 9f95ed2c259c6eeb2cbc13a8e21a447c 7.1/en/os/alpha/kernel-headers-2.4.9-31.alpha.rpm d43622963a55e817233a258d8318a120 7.1/en/os/alpha/kernel-smp-2.4.9-31.alpha.rpm 9d43960cc26be1783d8004addbb2bb9b 7.1/en/os/alpha/kernel-source-2.4.9-31.alpha.rpm 8b0c9d11ee3f66790b4dca48f018e10b 7.1/en/os/athlon/kernel-2.4.9-31.athlon.rpm 8e710a5f2a98932c2bc9e0d3d073e2447.1/en/os/athlon/kernel-smp-2.4.9-31.athlon.rpm 64705698f9f5eaf1e79185863382f941 7.1/en/os/i386/kernel-2.4.9-31.i386.rpm b239ceebf5b5c28a348cd960d3195f03 7.1/en/os/i386/kernel-BOOT-2.4.9-31.i386.rpm 6883d71ffe17dff75514ac38228cd5f0 7.1/en/os/i386/kernel-doc-2.4.9-31.i386.rpm dae89931407ae5832e374e49d8347234 7.1/en/os/i386/kernel-headers-2.4.9-31.i386.rpm cba833ad4e2b45392e4de085ca0e920f 7.1/en/os/i386/kernel-source-2.4.9-31.i386.rpm 8e50430f6c4f452d2625819ba7464c47 7.1/en/os/i586/kernel-2.4.9-31.i586.rpm e72f4fd75463bba1d51b7c7df1999704 7.1/en/os/i586/kernel-smp-2.4.9-31.i586.rpm 5e2b0b72141cbba077eb9c6b4d99991c 7.1/en/os/i686/kernel-2.4.9-31.i686.rpm a744dabe626acd95740aeb9af88b6d5b 7.1/en/os/i686/kernel-debug-2.4.9-31.i686.rpm aea058a30a30b3708b988c326ada6d0a 7.1/en/os/i686/kernel-enterprise-2.4.9-31.i686.rpm 3af0f1894a0c8b80486146298144727a 7.1/en/os/i686/kernel-smp-2.4.9-31.i686.rpm 322164648ff900315ea8d062f43de2e8 7.1/en/os/ia64/kernel-2.4.9-31.ia64.rpm 3f7c2c541be3797083cc7ac32e0fdebd 7.1/en/os/ia64/kernel-doc-2.4.9-31.ia64.rpm c8681048d6817a289ca59e0b4c38e611 7.1/en/os/ia64/kernel-headers-2.4.9-31.ia64.rpm 19026b6d0ce77ce6ced75aa5de77b49a 7.1/en/os/ia64/kernel-smp-2.4.9-31.ia64.rpm 2bdf102fd5b9e7b7e04c6e14d258eeae 7.1/en/os/ia64/kernel-source-2.4.9-31.ia64.rpm 599a9027496067a54b46716c4af2184a 7.2/en/os/SRPMS/kernel-2.4.9-31.src.rpm 8b0c9d11ee3f66790b4dca48f018e10b 7.2/en/os/athlon/kernel-2.4.9-31.athlon.rpm 8e710a5f2a98932c2bc9e0d3d073e244 7.2/en/os/athlon/kernel-smp-2.4.9-31.athlon.rpm 64705698f9f5eaf1e79185863382f941 7.2/en/os/i386/kernel-2.4.9-31.i386.rpm b239ceebf5b5c28a348cd960d3195f03 7.2/en/os/i386/kernel-BOOT-2.4.9-31.i386.rpm 6883d71ffe17dff75514ac38228cd5f0 7.2/en/os/i386/kernel-doc-2.4.9-31.i386.rpm dae89931407ae5832e374e49d8347234 7.2/en/os/i386/kernel-headers-2.4.9-31.i386.rpm cba833ad4e2b45392e4de085ca0e920f 7.2/en/os/i386/kernel-source-2.4.9-31.i386.rpm 8e50430f6c4f452d2625819ba7464c47 7.2/en/os/i586/kernel-2.4.9-31.i586.rpm e72f4fd75463bba1d51b7c7df19997047.2/en/os/i586/kernel-smp-2.4.9-31.i586.rpm 5e2b0b72141cbba077eb9c6b4d99991c 7.2/en/os/i686/kernel-2.4.9-31.i686.rpm a744dabe626acd95740aeb9af88b6d5b 7.2/en/os/i686/kernel-debug-2.4.9-31.i686.rpm aea058a30a30b3708b988c326ada6d0a 7.2/en/os/i686/kernel-enterprise-2.4.9-31.i686.rpm 3af0f1894a0c8b80486146298144727a 7.2/en/os/i686/kernel-smp-2.4.9-31.i686.rpm 322164648ff900315ea8d062f43de2e8 7.2/en/os/ia64/kernel-2.4.9-31.ia64.rpm 3f7c2c541be3797083cc7ac32e0fdebd 7.2/en/os/ia64/kernel-doc-2.4.9-31.ia64.rpm c8681048d6817a289ca59e0b4c38e611 7.2/en/os/ia64/kernel-headers-2.4.9-31.ia64.rpm 19026b6d0ce77ce6ced75aa5de77b49a 7.2/en/os/ia64/kernel-smp-2.4.9-31.ia64.rpm 2bdf102fd5b9e7b7e04c6e14d258eeae 7.2/en/os/ia64/kernel-source-2.4.9-31.ia64.rpm 03414b5deff2f6f673342ea3b8d5cf63 7.2/en/os/s390/kernel-2.4.9-31.s390.rpm 29db2044bac2e46027afa7479f39a394 7.2/en/os/s390/kernel-BOOT-2.4.9-31.s390.rpm b24851e70837659048e8416e0552fb0f 7.2/en/os/s390/kernel-doc-2.4.9-31.s390.rpm b5ad515e3bffc79fdbc73a3e0b07b5cc 7.2/en/os/s390/kernel-headers-2.4.9-31.s390.rpm 27d48439af20ab9f9b6ad84942913fe7 7.2/en/os/s390/kernel-source-2.4.9-31.s390.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: About You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: CVE -CVE-2002-0060 Copyright(c) 2000, 2001 Red Hat, Inc. `. Addressing potential weaknesses in IRC connection handling in Red Hat's kernel to enhance firewall security for versions 7.1 and 7.2.. Red Hat kernel exploits, Connection Tracking Risks, Firewall Patches, Linux Netfilter Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 27, 2002 Critical Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here