kernel security update
| Advisory: | RHSA-2002:227-11 |
|---|---|
| Type: | Security Advisory |
| Severity: | Important |
| Issued on: | 2002-10-08 |
| Last updated on: | 2002-10-28 |
| Affected Products: | Red Hat Enterprise Linux AS (v. 2.1) |
| CVEs (cve.mitre.org): |
CVE-2002-1572 CVE-2002-1573 |
Details
This kernel update for Red Hat Linux Advanced Server 2.1 addresses some
security issues and provides minor bug fixes.
The Linux kernel handles the basic functions of the operating system. A
number of vulnerabilities were found in the Red Hat Linux Advanced Server
kernel. These vulnerabilities could allow a local user to obtain elevated
(root) privileges.
The vulnerabilities existed in a number of drivers, including
stradis, rio500, se401, apm, usbserial, and usbvideo.
Additionally, a number of bugs have been fixed, and some small feature
enhancements have been added.
- Failed READA requests could be interpreted as I/O errors under high
load on SMP; this has been fixed.
- In rare cases, TLB entries could be corrupted on SMP Pentium IV
systems; this potential for corruption has been fixed. Third-party modules
will need to be recompiled to take advantage of these fixes.
- The latest tg3 driver fixes have been included; the tg3 driver
now supports more hardware.
- A mechanism is provided to specify the location of core files and to
set the name pattern to include the UID, program, hostname, and PID of
the process that caused the core dump.
A number of SCSI fixes have also been included:
- Configure sparse LUNs in the qla2200 driver
- Clean up erroneous accounting data as seen by /proc/partitions and iostat
- Allow up to 128 scsi disks
- Do not start logical units that require manual intervention, avoiding
unnecessary startup delays
- Improve SCSI layer throughput by properly clustering DMA requests
All users of Red Hat Linux Advanced Server are advised to upgrade to the
errata packages.
Solution
relevant to your system have been applied.
The procedure for upgrading the kernel is documented at:
http://www.redhat.com/support/docs/howto/kernel-upgrade/kernel-upgrade.html
Please read the directions for your architecture carefully before
proceeding with the kernel upgrade.
This update is available via Red Hat Network. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:
up2date
This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.
Updated packages
| Red Hat Enterprise Linux AS (v. 2.1) | |
| SRPMS: | |
| kernel-2.4.9-e.9.src.rpm File outdated by: RHSA-2009:0001 |
MD5: 93b90b462050cd36b277189e4d9b3458 |
| IA-32: | |
| kernel-2.4.9-e.9.athlon.rpm File outdated by: RHSA-2009:0001 |
MD5: 700597b6bdcdb84b26b75fcf4102b070 |
| kernel-2.4.9-e.9.i686.rpm File outdated by: RHSA-2009:0001 |
MD5: 076252b110b29adc74fb550eb741e598 |
| kernel-BOOT-2.4.9-e.9.i386.rpm File outdated by: RHSA-2009:0001 |
MD5: db8c95daa9c82c039e4fceb21553f555 |
| kernel-debug-2.4.9-e.9.i686.rpm File outdated by: RHSA-2009:0001 |
MD5: 2f7a7613c30404e11acbce941804c48d |
| kernel-doc-2.4.9-e.9.i386.rpm File outdated by: RHSA-2009:0001 |
MD5: 6a422564641af3d9641b213bcfefb23a |
| kernel-enterprise-2.4.9-e.9.i686.rpm File outdated by: RHSA-2009:0001 |
MD5: 97f998d76fe8544c32f85f2cd8beb637 |
| kernel-headers-2.4.9-e.9.i386.rpm File outdated by: RHSA-2009:0001 |
MD5: 3e4219b063528fc1f750f753da6206e2 |
| kernel-smp-2.4.9-e.9.athlon.rpm File outdated by: RHSA-2009:0001 |
MD5: 7aac072909667beeff70d6768b760158 |
| kernel-smp-2.4.9-e.9.i686.rpm File outdated by: RHSA-2009:0001 |
MD5: 1142f3e74257261276fd52109b05f195 |
| kernel-source-2.4.9-e.9.i386.rpm File outdated by: RHSA-2009:0001 |
MD5: 96020345c71d1dbbac6aa4c9c988ff0d |
| kernel-summit-2.4.9-e.9.i686.rpm File outdated by: RHSA-2009:0001 |
MD5: 117312cf7fccf3cbdeea92d9dc6e30bb |
Bugs fixed (see bugzilla for more information)
58442 - RFE: split allocate hd_struct per major in sd
64067 - qla2200.o driver does not recognize sparse luns
64149 - Bug in scsi_merge.c
67555 - Accounting leak in /proc/partitions; confuses iostat(1)
68883 - sd_init_onedisk() waits approximately 100 seconds for passive-mode device to spin up.
References
https://www.redhat.com/security/data/cve/CVE-2002-1573.html
Keywords
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package
The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/