Security Advisory Updated kernel packages address security vulnerabilities, bugfixes

Advisory: RHSA-2003:408-05
Type: Security Advisory
Severity: Important
Issued on: 2003-12-19
Last updated on: 2003-12-19
Affected Products: Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Enterprise Linux ES (v. 2.1)
Red Hat Enterprise Linux WS (v. 2.1)
OVAL: N/A
CVEs (cve.mitre.org): CVE-2003-0476

Details

Updated kernel packages that address various security vulnerabilities, fix a
number of bugs, and update various drivers are now available.

The Linux kernel handles the basic functions of the operating system.

The execve system call in Linux 2.4.x records the file descriptor of the
executable process in the file table of the calling process, which allows
local users to gain read access to restricted file descriptors. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2003-0476 to this issue.

A number of bugfixes are included, including important fixes for the ext3
file system and timer code.

New features include limited support for non-cached NFS file sytems, Serial
ATA (SATA) devices, and new alt-sysreq debugging options.

In addition, the following drivers have been updated:

- e100 2.3.30-k1
- e1000 5.2.20-k1
- fusion 2.05.05+
- ips 6.10.52
- aic7xxx 6.2.36
- aic79xxx 1.3.10
- megaraid 2 2.00.9
- cciss 2.4.49

All users are advised to upgrade to these erratum packages, which contain
backported patches addressing these issues.


Solution

Release notes, driver notes, and driver disks for this update are available
at the following URL:

http://www.redhat.com/support/errata/rhel/

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

The procedure for upgrading the kernel manually is documented at:

http://www.redhat.com/support/docs/howto/kernel-upgrade/

Please read the directions for your architecture carefully before
proceeding with the kernel upgrade.

Please note that this update is also available via Red Hat Network. Many
people find this to be an easier way to apply updates. To use Red Hat
Network, launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system. Note that you need to select the kernel
explicitly on default configurations of up2date.

Updated packages

Red Hat Enterprise Linux AS (v. 2.1)

SRPMS:
kernel-2.4.9-e.34.src.rpm
File outdated by:  RHSA-2009:0001
    9a2fec8ea266a96e7e9027663567bcc8
 
IA-32:
kernel-2.4.9-e.34.athlon.rpm
File outdated by:  RHSA-2009:0001
    a7f341ff87ef2ec7ac5fc98b6faf4733
kernel-2.4.9-e.34.i686.rpm
File outdated by:  RHSA-2009:0001
    c4e713cdbc4c6073a64d75b4dad203bd
kernel-BOOT-2.4.9-e.34.i386.rpm
File outdated by:  RHSA-2009:0001
    751dcca290aef19f97441735581f752e
kernel-debug-2.4.9-e.34.i686.rpm
File outdated by:  RHSA-2009:0001
    1234399c9c43711dac5a08d6577634ea
kernel-doc-2.4.9-e.34.i386.rpm
File outdated by:  RHSA-2009:0001
    833b9a87e12666a7a3bab95ef0d839e5
kernel-enterprise-2.4.9-e.34.i686.rpm
File outdated by:  RHSA-2009:0001
    4aa1653dc861991cd07554bd28e5f7e2
kernel-headers-2.4.9-e.34.i386.rpm
File outdated by:  RHSA-2009:0001
    87333913c671d0e3e7a749de0e335e76
kernel-smp-2.4.9-e.34.athlon.rpm
File outdated by:  RHSA-2009:0001
    314929f994c284817dba78a98f7e4ab6
kernel-smp-2.4.9-e.34.i686.rpm
File outdated by:  RHSA-2009:0001
    1f51cb729dd1e51dbb42e9ba1f6a4436
kernel-source-2.4.9-e.34.i386.rpm
File outdated by:  RHSA-2009:0001
    a9b3d5e9d162b3a194eaf3008b0eb072
kernel-summit-2.4.9-e.34.i686.rpm
File outdated by:  RHSA-2009:0001
    bd95e8651a275ad1e5de780e52211ba0
 
Red Hat Enterprise Linux ES (v. 2.1)

SRPMS:
kernel-2.4.9-e.34.src.rpm
File outdated by:  RHSA-2009:0001
    9a2fec8ea266a96e7e9027663567bcc8
 
IA-32:
kernel-2.4.9-e.34.athlon.rpm
File outdated by:  RHSA-2009:0001
    a7f341ff87ef2ec7ac5fc98b6faf4733
kernel-2.4.9-e.34.i686.rpm
File outdated by:  RHSA-2009:0001
    c4e713cdbc4c6073a64d75b4dad203bd
kernel-BOOT-2.4.9-e.34.i386.rpm
File outdated by:  RHSA-2009:0001
    751dcca290aef19f97441735581f752e
kernel-debug-2.4.9-e.34.i686.rpm
File outdated by:  RHSA-2009:0001
    1234399c9c43711dac5a08d6577634ea
kernel-doc-2.4.9-e.34.i386.rpm
File outdated by:  RHSA-2009:0001
    833b9a87e12666a7a3bab95ef0d839e5
kernel-headers-2.4.9-e.34.i386.rpm
File outdated by:  RHSA-2009:0001
    87333913c671d0e3e7a749de0e335e76
kernel-smp-2.4.9-e.34.athlon.rpm
File outdated by:  RHSA-2009:0001
    314929f994c284817dba78a98f7e4ab6
kernel-smp-2.4.9-e.34.i686.rpm
File outdated by:  RHSA-2009:0001
    1f51cb729dd1e51dbb42e9ba1f6a4436
kernel-source-2.4.9-e.34.i386.rpm
File outdated by:  RHSA-2009:0001
    a9b3d5e9d162b3a194eaf3008b0eb072
 
Red Hat Enterprise Linux WS (v. 2.1)

SRPMS:
kernel-2.4.9-e.34.src.rpm
File outdated by:  RHSA-2009:0001
    9a2fec8ea266a96e7e9027663567bcc8
 
IA-32:
kernel-2.4.9-e.34.athlon.rpm
File outdated by:  RHSA-2009:0001
    a7f341ff87ef2ec7ac5fc98b6faf4733
kernel-2.4.9-e.34.i686.rpm
File outdated by:  RHSA-2009:0001
    c4e713cdbc4c6073a64d75b4dad203bd
kernel-BOOT-2.4.9-e.34.i386.rpm
File outdated by:  RHSA-2009:0001
    751dcca290aef19f97441735581f752e
kernel-debug-2.4.9-e.34.i686.rpm
File outdated by:  RHSA-2009:0001
    1234399c9c43711dac5a08d6577634ea
kernel-doc-2.4.9-e.34.i386.rpm
File outdated by:  RHSA-2009:0001
    833b9a87e12666a7a3bab95ef0d839e5
kernel-enterprise-2.4.9-e.34.i686.rpm
File outdated by:  RHSA-2009:0001
    4aa1653dc861991cd07554bd28e5f7e2
kernel-headers-2.4.9-e.34.i386.rpm
File outdated by:  RHSA-2009:0001
    87333913c671d0e3e7a749de0e335e76
kernel-smp-2.4.9-e.34.athlon.rpm
File outdated by:  RHSA-2009:0001
    314929f994c284817dba78a98f7e4ab6
kernel-smp-2.4.9-e.34.i686.rpm
File outdated by:  RHSA-2009:0001
    1f51cb729dd1e51dbb42e9ba1f6a4436
kernel-source-2.4.9-e.34.i386.rpm
File outdated by:  RHSA-2009:0001
    a9b3d5e9d162b3a194eaf3008b0eb072
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

74516 - NFS DATA CORRUPTION
75669 - SG queue function getting null pointer
84452 - RHEL AS2.1 QU3 errata: System hangs with 2.1 AS (timer.c)
85211 - USB CDROM crashes with dd on IBM Bladecenter
90872 - md device can be stopped when it should return -EBUSY
99203 - NFS tcp client retransmission with large wsize.


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/