Skip to navigation

Security Advisory Important: kernel security and bug fix update

Advisory: RHSA-2008:0957-17
Type: Security Advisory
Severity: Important
Issued on: 2008-11-04
Last updated on: 2008-11-12
Affected Products: Red Hat Enterprise Linux (v. 5 server)
Red Hat Enterprise Linux Desktop (v. 5 client)
Red Hat Enterprise Linux EUS (v. 5.2.z server)
CVEs (cve.mitre.org): CVE-2006-5755
CVE-2007-5907
CVE-2008-2372
CVE-2008-3276
CVE-2008-3527
CVE-2008-3833
CVE-2008-4210
CVE-2008-4302

Details

Updated kernel packages that resolve several security issues and fix
various bugs are now available for Red Hat Enterprise Linux 5.

This update has been rated as having important security impact by the Red
Hat Security Response Team.

[Updated 12th November 2008]
The original packages distributed with this errata had a bug which
prevented the Xen kernel booting on older hardware. We have updated the
packages to correct this bug.

The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* the Xen implementation did not prevent applications running in a
para-virtualized guest from modifying CR4 TSC. This could cause a local
denial of service. (CVE-2007-5907, Important)

* Tavis Ormandy reported missing boundary checks in the Virtual Dynamic
Shared Objects (vDSO) implementation. This could allow a local unprivileged
user to cause a denial of service or escalate privileges. (CVE-2008-3527,
Important)

* the do_truncate() and generic_file_splice_write() functions did not clear
the setuid and setgid bits. This could allow a local unprivileged user to
obtain access to privileged information. (CVE-2008-4210, CVE-2008-3833,
Important)

* a flaw was found in the Linux kernel splice implementation. This could
cause a local denial of service when there is a certain failure in the
add_to_page_cache_lru() function. (CVE-2008-4302, Important)

* a flaw was found in the Linux kernel when running on AMD64 systems.
During a context switch, EFLAGS were being neither saved nor restored. This
could allow a local unprivileged user to cause a denial of service.
(CVE-2006-5755, Low)

* a flaw was found in the Linux kernel virtual memory implementation. This
could allow a local unprivileged user to cause a denial of service.
(CVE-2008-2372, Low)

* an integer overflow was discovered in the Linux kernel Datagram
Congestion Control Protocol (DCCP) implementation. This could allow a
remote attacker to cause a denial of service. By default, remote DCCP is
blocked by SELinux. (CVE-2008-3276, Low)

In addition, these updated packages fix the following bugs:

* random32() seeding has been improved.

* in a multi-core environment, a race between the QP async event-handler
and the destro_qp() function could occur. This led to unpredictable results
during invalid memory access, which could lead to a kernel crash.

* a format string was omitted in the call to the request_module() function.

* a stack overflow caused by an infinite recursion bug in the binfmt_misc
kernel module was corrected.

* the ata_scsi_rbuf_get() and ata_scsi_rbuf_put() functions now check for
scatterlist usage before calling kmap_atomic().

* a sentinel NUL byte was added to the device_write() function to ensure
that lspace.name is NUL-terminated.

* in the character device driver, a range_is_allowed() check was added to
the read_mem() and write_mem() functions. It was possible for an
illegitimate application to bypass these checks, and access /dev/mem beyond
the 1M limit by calling mmap_mem() instead. Also, the parameters of
range_is_allowed() were changed to cleanly handle greater than 32-bits of
physical address on 32-bit architectures.

* some of the newer Nehalem-based systems declare their CPU DSDT entries as
type "Alias". During boot, this caused an "Error attaching device data"
message to be logged.

* the evtchn event channel device lacked locks and memory barriers. This
has led to xenstore becoming unresponsive on the Itanium® architecture.

* sending of gratuitous ARP packets in the Xen frontend network driver is
now delayed until the backend signals that its carrier status has been
processed by the stack.

* on forcedeth devices, whenever setting ethtool parameters for link speed,
the device could stop receiving interrupts.

* the CIFS 'forcedirectio' option did not allow text to be appended to files.

* the gettimeofday() function returned a backwards time on Intel® 64.

* residual-count corrections during UNDERRUN handling were added to the
qla2xxx driver.

* the fix for a small quirk was removed for certain Adaptec controllers for
which it caused problems.

* the "xm trigger init" command caused a domain panic if a userland
application was running on a guest on the Intel® 64 architecture.

Users of kernel should upgrade to these updated packages, which contain
backported patches to correct these issues.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

Red Hat Enterprise Linux (v. 5 server)

SRPMS:
kernel-2.6.18-92.1.18.el5.src.rpm
File outdated by:  RHSA-2010:0148
    MD5: 91c29973610e75bd6a5bebd5e01c9562
 
IA-32:
kernel-2.6.18-92.1.18.el5.i686.rpm
File outdated by:  RHSA-2013:0847
    MD5: 0dddb2645fe53b1f4d80ac0089ad78de
kernel-PAE-2.6.18-92.1.18.el5.i686.rpm
File outdated by:  RHSA-2013:0847
    MD5: 57280634ccda872018d5edf89e960739
kernel-PAE-devel-2.6.18-92.1.18.el5.i686.rpm
File outdated by:  RHSA-2013:0847
    MD5: 30eb862a42f95ee540002e2413720cb6
kernel-debug-2.6.18-92.1.18.el5.i686.rpm
File outdated by:  RHSA-2013:0847
    MD5: 2cb753886f61644631071a2d30910ab7
kernel-debug-devel-2.6.18-92.1.18.el5.i686.rpm
File outdated by:  RHSA-2013:0847
    MD5: 5de6456536d3f75e1a3f835ef875fdf5
kernel-devel-2.6.18-92.1.18.el5.i686.rpm
File outdated by:  RHSA-2013:0847
    MD5: 6bdac525b394cb82e5db4108ee26290a
kernel-doc-2.6.18-92.1.18.el5.noarch.rpm
File outdated by:  RHSA-2013:0847
    MD5: 4e6e568df7dcacdee7e13210a20b536f
kernel-headers-2.6.18-92.1.18.el5.i386.rpm
File outdated by:  RHSA-2013:0847
    MD5: 87e8304c34e6b2010326b81f5c138920
kernel-xen-2.6.18-92.1.18.el5.i686.rpm
File outdated by:  RHSA-2013:0847
    MD5: 218274a1f0820e10d7afc2601d8d59ca
kernel-xen-devel-2.6.18-92.1.18.el5.i686.rpm
File outdated by:  RHSA-2013:0847
    MD5: efdaeeab1ed69aa66493ce9d4c62fcfc
 
IA-64:
kernel-2.6.18-92.1.18.el5.ia64.rpm
File outdated by:  RHSA-2013:0847
    MD5: 3e00939a3b0a39472e6e40b93f0df8d7
kernel-debug-2.6.18-92.1.18.el5.ia64.rpm
File outdated by:  RHSA-2013:0847
    MD5: 20e21e78f2e1c0fa987aa41461e5cf11
kernel-debug-devel-2.6.18-92.1.18.el5.ia64.rpm
File outdated by:  RHSA-2013:0847
    MD5: dc574fa0d8e9f5e76563a760957269ee
kernel-devel-2.6.18-92.1.18.el5.ia64.rpm
File outdated by:  RHSA-2013:0847
    MD5: a6ebec2e1ccfff691f919f1d61eab6c8
kernel-doc-2.6.18-92.1.18.el5.noarch.rpm
File outdated by:  RHSA-2013:0847
    MD5: 4e6e568df7dcacdee7e13210a20b536f
kernel-headers-2.6.18-92.1.18.el5.ia64.rpm
File outdated by:  RHSA-2013:0847
    MD5: dc315a85fa8ff2483556e96a4b368e20
kernel-xen-2.6.18-92.1.18.el5.ia64.rpm
File outdated by:  RHSA-2013:0847
    MD5: ab0c8ae884febfa09aedd7eb382b86a7
kernel-xen-devel-2.6.18-92.1.18.el5.ia64.rpm
File outdated by:  RHSA-2013:0847
    MD5: b72c1ef2d5709171489f1d13e1d2533b
 
PPC:
kernel-2.6.18-92.1.18.el5.ppc64.rpm
File outdated by:  RHSA-2013:0847
    MD5: f10476d060326bb81f78ca05905ea72b
kernel-debug-2.6.18-92.1.18.el5.ppc64.rpm
File outdated by:  RHSA-2013:0847
    MD5: 44e32a2ec9d8d0517117b6d664e77696
kernel-debug-devel-2.6.18-92.1.18.el5.ppc64.rpm
File outdated by:  RHSA-2013:0847
    MD5: 103db513e2c161fcde53c4b59a5644f4
kernel-devel-2.6.18-92.1.18.el5.ppc64.rpm
File outdated by:  RHSA-2013:0847
    MD5: 5eb9365251a47492af0ef04f8f624a8d
kernel-doc-2.6.18-92.1.18.el5.noarch.rpm
File outdated by:  RHSA-2013:0847
    MD5: 4e6e568df7dcacdee7e13210a20b536f
kernel-headers-2.6.18-92.1.18.el5.ppc.rpm
File outdated by:  RHSA-2013:0847
    MD5: 6d47f86d23d38f500d1e256248013a86
kernel-headers-2.6.18-92.1.18.el5.ppc64.rpm
File outdated by:  RHSA-2013:0847
    MD5: ef7bb51fce839219d52c2bd02a3fe6f6
kernel-kdump-2.6.18-92.1.18.el5.ppc64.rpm
File outdated by:  RHSA-2013:0847
    MD5: efb704d79df0b988784f5fa39cb9b04d
kernel-kdump-devel-2.6.18-92.1.18.el5.ppc64.rpm
File outdated by:  RHSA-2013:0847
    MD5: 517595f9f197f711e4a35d1bff1495f3
 
s390x:
kernel-2.6.18-92.1.18.el5.s390x.rpm
File outdated by:  RHSA-2013:0847
    MD5: f31b1f3f0a22ba5b4366e3555d38343a
kernel-debug-2.6.18-92.1.18.el5.s390x.rpm
File outdated by:  RHSA-2013:0847
    MD5: 2efeae115a71521b54d34325958db5b0
kernel-debug-devel-2.6.18-92.1.18.el5.s390x.rpm
File outdated by:  RHSA-2013:0847
    MD5: 5703756f6a04a5488f359b081bd91e22
kernel-devel-2.6.18-92.1.18.el5.s390x.rpm
File outdated by:  RHSA-2013:0847
    MD5: f921887e2b31599bdc155ffaa92ca848
kernel-doc-2.6.18-92.1.18.el5.noarch.rpm
File outdated by:  RHSA-2013:0847
    MD5: 4e6e568df7dcacdee7e13210a20b536f
kernel-headers-2.6.18-92.1.18.el5.s390x.rpm
File outdated by:  RHSA-2013:0847
    MD5: a3e4edf4fdef14be7125429ace672c1e
kernel-kdump-2.6.18-92.1.18.el5.s390x.rpm
File outdated by:  RHSA-2013:0847
    MD5: 0a99e9dcbfcd0a36d5bddd93ce8809a8
kernel-kdump-devel-2.6.18-92.1.18.el5.s390x.rpm
File outdated by:  RHSA-2013:0847
    MD5: 87eee30c4d9b0df38e67fbce0b93f525
 
x86_64:
kernel-2.6.18-92.1.18.el5.x86_64.rpm
File outdated by:  RHSA-2013:0847
    MD5: ac69be76d5f159067862c3ab95441ea5
kernel-debug-2.6.18-92.1.18.el5.x86_64.rpm
File outdated by:  RHSA-2013:0847
    MD5: 49efc15079be6de8011ffc22e9454ccc
kernel-debug-devel-2.6.18-92.1.18.el5.x86_64.rpm
File outdated by:  RHSA-2013:0847
    MD5: 175264b18f93758cb29fd3541ac1da61
kernel-devel-2.6.18-92.1.18.el5.x86_64.rpm
File outdated by:  RHSA-2013:0847
    MD5: d3bc9843fab91986ffd68a8e2ce08f78
kernel-doc-2.6.18-92.1.18.el5.noarch.rpm
File outdated by:  RHSA-2013:0847
    MD5: 4e6e568df7dcacdee7e13210a20b536f
kernel-headers-2.6.18-92.1.18.el5.x86_64.rpm
File outdated by:  RHSA-2013:0847
    MD5: 6bd435661a86de8291acde1fb2528900
kernel-xen-2.6.18-92.1.18.el5.x86_64.rpm
File outdated by:  RHSA-2013:0847
    MD5: 5c23e99ff2994ad1eca9a02fe0bcf4ee
kernel-xen-devel-2.6.18-92.1.18.el5.x86_64.rpm
File outdated by:  RHSA-2013:0847
    MD5: f813e17b326faea3e88ad947e353301d
 
Red Hat Enterprise Linux Desktop (v. 5 client)

SRPMS:
kernel-2.6.18-92.1.18.el5.src.rpm
File outdated by:  RHSA-2010:0148
    MD5: 91c29973610e75bd6a5bebd5e01c9562
 
IA-32:
kernel-2.6.18-92.1.18.el5.i686.rpm
File outdated by:  RHSA-2013:0847
    MD5: 0dddb2645fe53b1f4d80ac0089ad78de
kernel-PAE-2.6.18-92.1.18.el5.i686.rpm
File outdated by:  RHSA-2013:0847
    MD5: 57280634ccda872018d5edf89e960739
kernel-PAE-devel-2.6.18-92.1.18.el5.i686.rpm
File outdated by:  RHSA-2013:0847
    MD5: 30eb862a42f95ee540002e2413720cb6
kernel-debug-2.6.18-92.1.18.el5.i686.rpm
File outdated by:  RHSA-2013:0847
    MD5: 2cb753886f61644631071a2d30910ab7
kernel-debug-devel-2.6.18-92.1.18.el5.i686.rpm
File outdated by:  RHSA-2013:0847
    MD5: 5de6456536d3f75e1a3f835ef875fdf5
kernel-devel-2.6.18-92.1.18.el5.i686.rpm
File outdated by:  RHSA-2013:0847
    MD5: 6bdac525b394cb82e5db4108ee26290a
kernel-doc-2.6.18-92.1.18.el5.noarch.rpm
File outdated by:  RHSA-2013:0847
    MD5: 4e6e568df7dcacdee7e13210a20b536f
kernel-headers-2.6.18-92.1.18.el5.i386.rpm
File outdated by:  RHSA-2013:0847
    MD5: 87e8304c34e6b2010326b81f5c138920
kernel-xen-2.6.18-92.1.18.el5.i686.rpm
File outdated by:  RHSA-2013:0847
    MD5: 218274a1f0820e10d7afc2601d8d59ca
kernel-xen-devel-2.6.18-92.1.18.el5.i686.rpm
File outdated by:  RHSA-2013:0847
    MD5: efdaeeab1ed69aa66493ce9d4c62fcfc
 
x86_64:
kernel-2.6.18-92.1.18.el5.x86_64.rpm
File outdated by:  RHSA-2013:0847
    MD5: ac69be76d5f159067862c3ab95441ea5
kernel-debug-2.6.18-92.1.18.el5.x86_64.rpm
File outdated by:  RHSA-2013:0847
    MD5: 49efc15079be6de8011ffc22e9454ccc
kernel-debug-devel-2.6.18-92.1.18.el5.x86_64.rpm
File outdated by:  RHSA-2013:0847
    MD5: 175264b18f93758cb29fd3541ac1da61
kernel-devel-2.6.18-92.1.18.el5.x86_64.rpm
File outdated by:  RHSA-2013:0847
    MD5: d3bc9843fab91986ffd68a8e2ce08f78
kernel-doc-2.6.18-92.1.18.el5.noarch.rpm
File outdated by:  RHSA-2013:0847
    MD5: 4e6e568df7dcacdee7e13210a20b536f
kernel-headers-2.6.18-92.1.18.el5.x86_64.rpm
File outdated by:  RHSA-2013:0847
    MD5: 6bd435661a86de8291acde1fb2528900
kernel-xen-2.6.18-92.1.18.el5.x86_64.rpm
File outdated by:  RHSA-2013:0847
    MD5: 5c23e99ff2994ad1eca9a02fe0bcf4ee
kernel-xen-devel-2.6.18-92.1.18.el5.x86_64.rpm
File outdated by:  RHSA-2013:0847
    MD5: f813e17b326faea3e88ad947e353301d
 
Red Hat Enterprise Linux EUS (v. 5.2.z server)

SRPMS:
kernel-2.6.18-92.1.18.el5.src.rpm
File outdated by:  RHSA-2010:0148
    MD5: 91c29973610e75bd6a5bebd5e01c9562
 
IA-32:
kernel-2.6.18-92.1.18.el5.i686.rpm
File outdated by:  RHSA-2010:0148
    MD5: 0dddb2645fe53b1f4d80ac0089ad78de
kernel-PAE-2.6.18-92.1.18.el5.i686.rpm
File outdated by:  RHSA-2010:0148
    MD5: 57280634ccda872018d5edf89e960739
kernel-PAE-devel-2.6.18-92.1.18.el5.i686.rpm
File outdated by:  RHSA-2010:0148
    MD5: 30eb862a42f95ee540002e2413720cb6
kernel-debug-2.6.18-92.1.18.el5.i686.rpm
File outdated by:  RHSA-2010:0148
    MD5: 2cb753886f61644631071a2d30910ab7
kernel-debug-devel-2.6.18-92.1.18.el5.i686.rpm
File outdated by:  RHSA-2010:0148
    MD5: 5de6456536d3f75e1a3f835ef875fdf5
kernel-devel-2.6.18-92.1.18.el5.i686.rpm
File outdated by:  RHSA-2010:0148
    MD5: 6bdac525b394cb82e5db4108ee26290a
kernel-doc-2.6.18-92.1.18.el5.noarch.rpm
File outdated by:  RHSA-2010:0148
    MD5: 4e6e568df7dcacdee7e13210a20b536f
kernel-headers-2.6.18-92.1.18.el5.i386.rpm
File outdated by:  RHSA-2010:0148
    MD5: 87e8304c34e6b2010326b81f5c138920
kernel-xen-2.6.18-92.1.18.el5.i686.rpm
File outdated by:  RHSA-2010:0148
    MD5: 218274a1f0820e10d7afc2601d8d59ca
kernel-xen-devel-2.6.18-92.1.18.el5.i686.rpm
File outdated by:  RHSA-2010:0148
    MD5: efdaeeab1ed69aa66493ce9d4c62fcfc
 
IA-64:
kernel-2.6.18-92.1.18.el5.ia64.rpm
File outdated by:  RHSA-2010:0148
    MD5: 3e00939a3b0a39472e6e40b93f0df8d7
kernel-debug-2.6.18-92.1.18.el5.ia64.rpm
File outdated by:  RHSA-2010:0148
    MD5: 20e21e78f2e1c0fa987aa41461e5cf11
kernel-debug-devel-2.6.18-92.1.18.el5.ia64.rpm
File outdated by:  RHSA-2010:0148
    MD5: dc574fa0d8e9f5e76563a760957269ee
kernel-devel-2.6.18-92.1.18.el5.ia64.rpm
File outdated by:  RHSA-2010:0148
    MD5: a6ebec2e1ccfff691f919f1d61eab6c8
kernel-doc-2.6.18-92.1.18.el5.noarch.rpm
File outdated by:  RHSA-2010:0148
    MD5: 4e6e568df7dcacdee7e13210a20b536f
kernel-headers-2.6.18-92.1.18.el5.ia64.rpm
File outdated by:  RHSA-2010:0148
    MD5: dc315a85fa8ff2483556e96a4b368e20
kernel-xen-2.6.18-92.1.18.el5.ia64.rpm
File outdated by:  RHSA-2010:0148
    MD5: ab0c8ae884febfa09aedd7eb382b86a7
kernel-xen-devel-2.6.18-92.1.18.el5.ia64.rpm
File outdated by:  RHSA-2010:0148
    MD5: b72c1ef2d5709171489f1d13e1d2533b
 
PPC:
kernel-2.6.18-92.1.18.el5.ppc64.rpm
File outdated by:  RHSA-2010:0148
    MD5: f10476d060326bb81f78ca05905ea72b
kernel-debug-2.6.18-92.1.18.el5.ppc64.rpm
File outdated by:  RHSA-2010:0148
    MD5: 44e32a2ec9d8d0517117b6d664e77696
kernel-debug-devel-2.6.18-92.1.18.el5.ppc64.rpm
File outdated by:  RHSA-2010:0148
    MD5: 103db513e2c161fcde53c4b59a5644f4
kernel-devel-2.6.18-92.1.18.el5.ppc64.rpm
File outdated by:  RHSA-2010:0148
    MD5: 5eb9365251a47492af0ef04f8f624a8d
kernel-doc-2.6.18-92.1.18.el5.noarch.rpm
File outdated by:  RHSA-2010:0148
    MD5: 4e6e568df7dcacdee7e13210a20b536f
kernel-headers-2.6.18-92.1.18.el5.ppc.rpm
File outdated by:  RHSA-2010:0148
    MD5: 6d47f86d23d38f500d1e256248013a86
kernel-headers-2.6.18-92.1.18.el5.ppc64.rpm
File outdated by:  RHSA-2010:0148
    MD5: ef7bb51fce839219d52c2bd02a3fe6f6
kernel-kdump-2.6.18-92.1.18.el5.ppc64.rpm
File outdated by:  RHSA-2010:0148
    MD5: efb704d79df0b988784f5fa39cb9b04d
kernel-kdump-devel-2.6.18-92.1.18.el5.ppc64.rpm
File outdated by:  RHSA-2010:0148
    MD5: 517595f9f197f711e4a35d1bff1495f3
 
s390x:
kernel-2.6.18-92.1.18.el5.s390x.rpm
File outdated by:  RHSA-2010:0148
    MD5: f31b1f3f0a22ba5b4366e3555d38343a
kernel-debug-2.6.18-92.1.18.el5.s390x.rpm
File outdated by:  RHSA-2010:0148
    MD5: 2efeae115a71521b54d34325958db5b0
kernel-debug-devel-2.6.18-92.1.18.el5.s390x.rpm
File outdated by:  RHSA-2010:0148
    MD5: 5703756f6a04a5488f359b081bd91e22
kernel-devel-2.6.18-92.1.18.el5.s390x.rpm
File outdated by:  RHSA-2010:0148
    MD5: f921887e2b31599bdc155ffaa92ca848
kernel-doc-2.6.18-92.1.18.el5.noarch.rpm
File outdated by:  RHSA-2010:0148
    MD5: 4e6e568df7dcacdee7e13210a20b536f
kernel-headers-2.6.18-92.1.18.el5.s390x.rpm
File outdated by:  RHSA-2010:0148
    MD5: a3e4edf4fdef14be7125429ace672c1e
kernel-kdump-2.6.18-92.1.18.el5.s390x.rpm
File outdated by:  RHSA-2010:0148
    MD5: 0a99e9dcbfcd0a36d5bddd93ce8809a8
kernel-kdump-devel-2.6.18-92.1.18.el5.s390x.rpm
File outdated by:  RHSA-2010:0148
    MD5: 87eee30c4d9b0df38e67fbce0b93f525
 
x86_64:
kernel-2.6.18-92.1.18.el5.x86_64.rpm
File outdated by:  RHSA-2010:0148
    MD5: ac69be76d5f159067862c3ab95441ea5
kernel-debug-2.6.18-92.1.18.el5.x86_64.rpm
File outdated by:  RHSA-2010:0148
    MD5: 49efc15079be6de8011ffc22e9454ccc
kernel-debug-devel-2.6.18-92.1.18.el5.x86_64.rpm
File outdated by:  RHSA-2010:0148
    MD5: 175264b18f93758cb29fd3541ac1da61
kernel-devel-2.6.18-92.1.18.el5.x86_64.rpm
File outdated by:  RHSA-2010:0148
    MD5: d3bc9843fab91986ffd68a8e2ce08f78
kernel-doc-2.6.18-92.1.18.el5.noarch.rpm
File outdated by:  RHSA-2010:0148
    MD5: 4e6e568df7dcacdee7e13210a20b536f
kernel-headers-2.6.18-92.1.18.el5.x86_64.rpm
File outdated by:  RHSA-2010:0148
    MD5: 6bd435661a86de8291acde1fb2528900
kernel-xen-2.6.18-92.1.18.el5.x86_64.rpm
File outdated by:  RHSA-2010:0148
    MD5: 5c23e99ff2994ad1eca9a02fe0bcf4ee
kernel-xen-devel-2.6.18-92.1.18.el5.x86_64.rpm
File outdated by:  RHSA-2010:0148
    MD5: f813e17b326faea3e88ad947e353301d
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

377561 - CVE-2007-5907 kernel-xen 3.1.1 does not prevent modification of the CR4 TSC from applications (DoS possible)
452666 - CVE-2008-2372 kernel: Reinstate ZERO_PAGE optimization in 'get_user_pages()' and fix XIP
457718 - CVE-2006-5755 kernel: local denial of service due to NT bit leakage
458021 - kernel: random32: seeding improvement [rhel-5.2.z]
458759 - kernel: dlm: dlm/user.c input validation fixes [rhel-5.2.z]
458781 - LTC44618-Race possibility between QP async handler and destroy_qp()
459226 - CVE-2008-3276 Linux kernel dccp_setsockopt_change() integer overflow
459461 - kernel: cpufreq: fix format string bug [rhel-5.2.z]
459464 - kernel: binfmt_misc.c: avoid potential kernel stack overflow [rhel-5.2.z]
460251 - CVE-2008-3527 kernel: missing boundary checks in syscall/syscall32_nopage()
460638 - [REG][5.3] The system crashed by the NULL pointer access with kmap_atomic() of ata_scsi_rbuf_get().
460858 - kernel: devmem: add range_is_allowed() check to mmap_mem() [rhel-5.2.z]
460868 - RHEL5.2 ACPI core bug
461099 - evtchn device lacks lock and barriers
461457 - Coordinate gratuitous ARP with backend network status
461894 - nVidia MCP55 MCP55 Ethernet (rev a3) not functional on kernel 2.6.18-53.1.4
462434 - CVE-2008-4302 kernel: splice: fix bad unlock_page() in error case
462591 - CIFS option forcedirectio fails to allow the appending of text to files.
462860 - RHEL5.3: Fix time of gettimeofday() going backward (EM64T) (*)
463661 - CVE-2008-4210 kernel: open() call allows setgid bit when user is not in new file's group
464450 - CVE-2008-3833 kernel: remove SUID when splicing into an inode
465741 - [QLogic 5.2.z bug] qla2xxx - Additional residual-count corrections during UNDERRUN handling.
466427 - Significant regression in time() performance
466885 - [aacraid 5.2.z] aac_srb: aac_fib_send failed with status 8195
467105 - xm trigger <domain> init causes kernel panic.


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/