Security Advisory Important: kernel security and bug fix update

Advisory: RHSA-2009:1077-1
Type: Security Advisory
Severity: Important
Issued on: 2009-06-02
Last updated on: 2009-06-02
Affected Products: Red Hat Enterprise Linux AS (v. 4.7.z)
Red Hat Enterprise Linux ES (v. 4.7.z)
OVAL: N/A
CVEs (cve.mitre.org): CVE-2009-1336
CVE-2009-1337

Details

Updated kernel packages that fix two security issues and two bugs are now
available for Red Hat Enterprise Linux 4.7 Extended Update Support.

This update has been rated as having important security impact by the Red
Hat Security Response Team.

The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update includes backported fixes for two approved security issues.
These issues only affected users of Red Hat Enterprise Linux 4.7 Extended
Update Support, as they have already been addressed for users of Red Hat
Enterprise Linux 4 in the 4.8 update, RHSA-2009:1024.

* the exit_notify() function in the Linux kernel did not properly reset the
exit signal if a process executed a set user ID (setuid) application before
exiting. This could allow a local, unprivileged user to elevate their
privileges. (CVE-2009-1337, Important)

* the Linux kernel implementation of the Network File System (NFS) version
4 did not properly initialize the file name limit in the nfs_server data
structure. This flaw could possibly lead to a denial of service on a client
mounting an NFSv4 share. (CVE-2009-1336, Moderate)

This update fixes the following bugs:

* on IBM System z systems, if the cio driver was used for DASD devices, and
the last path to a DASD device was varied off, it was still possible to
attempt read and write operations to that device, resulting in errors. In
this update, path verification is used in this situation, which resolves
this issue. Also, a bug may have caused errors when subchannels were
unregistered. (BZ#437486)

* a bug prevented the Broadcom NetXtreme II 57710 network device from
working correctly on some Dell PowerEdge R805 systems. This device was
correctly shown in "lspci" output, but "ifup" failed and an IP address was
not assigned. In this update, the device works correctly on Dell PowerEdge
R805 systems. (BZ#491752)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. For this update to take effect, the system
must be rebooted.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259

Updated packages

Red Hat Enterprise Linux AS (v. 4.7.z)

SRPMS:
kernel-2.6.9-78.0.24.EL.src.rpm
File outdated by:  RHSA-2009:1588
    742108ec7710c66a7bf3add1df32a132
 
IA-32:
kernel-2.6.9-78.0.24.EL.i686.rpm
File outdated by:  RHSA-2009:1588
    a6bafea34ce3da8ef1a79f9e1391e336
kernel-devel-2.6.9-78.0.24.EL.i686.rpm
File outdated by:  RHSA-2009:1588
    9af2abf2561a79169e4b3ef86db09ae8
kernel-doc-2.6.9-78.0.24.EL.noarch.rpm
File outdated by:  RHSA-2009:1588
    9cb07db9a978f28c33a626f792b930c0
kernel-hugemem-2.6.9-78.0.24.EL.i686.rpm
File outdated by:  RHSA-2009:1588
    d29a1936f9ea46e6ee2c8dd018021363
kernel-hugemem-devel-2.6.9-78.0.24.EL.i686.rpm
File outdated by:  RHSA-2009:1588
    a4fe83577eb68dda087cae027d5a5db7
kernel-smp-2.6.9-78.0.24.EL.i686.rpm
File outdated by:  RHSA-2009:1588
    f3b927d567207293ad942b269fb322ad
kernel-smp-devel-2.6.9-78.0.24.EL.i686.rpm
File outdated by:  RHSA-2009:1588
    39585a68638c8374a8c8e4720c8d8d8b
kernel-xenU-2.6.9-78.0.24.EL.i686.rpm
File outdated by:  RHSA-2009:1588
    3699e20798e4269aa9b7a0e37808c81d
kernel-xenU-devel-2.6.9-78.0.24.EL.i686.rpm
File outdated by:  RHSA-2009:1588
    e11ed8dcf7f137765dfad908f15a8b94
 
IA-64:
kernel-2.6.9-78.0.24.EL.ia64.rpm
File outdated by:  RHSA-2009:1588
    e222cfd019e094daf72698fb4362274f
kernel-devel-2.6.9-78.0.24.EL.ia64.rpm
File outdated by:  RHSA-2009:1588
    fd29dbc2837e09b9913f8135d6e303a8
kernel-doc-2.6.9-78.0.24.EL.noarch.rpm
File outdated by:  RHSA-2009:1588
    9cb07db9a978f28c33a626f792b930c0
kernel-largesmp-2.6.9-78.0.24.EL.ia64.rpm
File outdated by:  RHSA-2009:1588
    72462e4441565be92c16aa8f1f5e847a
kernel-largesmp-devel-2.6.9-78.0.24.EL.ia64.rpm
File outdated by:  RHSA-2009:1588
    b29e124b98e6c74c6035f69d2bc69005
 
PPC:
kernel-2.6.9-78.0.24.EL.ppc64.rpm
File outdated by:  RHSA-2009:1588
    114c5dac66113359986ddf36d61696d0
kernel-2.6.9-78.0.24.EL.ppc64iseries.rpm
File outdated by:  RHSA-2009:1588
    ba93a82460d126d712fa086f76d125f2
kernel-devel-2.6.9-78.0.24.EL.ppc64.rpm
File outdated by:  RHSA-2009:1588
    71928e813cdcc3dc51a4dea7665adbac
kernel-devel-2.6.9-78.0.24.EL.ppc64iseries.rpm
File outdated by:  RHSA-2009:1588
    90213fd1d93fb4458a3a45026f3b3bb2
kernel-doc-2.6.9-78.0.24.EL.noarch.rpm
File outdated by:  RHSA-2009:1588
    9cb07db9a978f28c33a626f792b930c0
kernel-largesmp-2.6.9-78.0.24.EL.ppc64.rpm
File outdated by:  RHSA-2009:1588
    5d539245a1a612e995f0613484daf23d
kernel-largesmp-devel-2.6.9-78.0.24.EL.ppc64.rpm
File outdated by:  RHSA-2009:1588
    c2994df27fa8c464a46db7118b81b999
 
s390:
kernel-2.6.9-78.0.24.EL.s390.rpm
File outdated by:  RHSA-2009:1588
    d6ed708435f8a13f300700a81f63d8ad
kernel-devel-2.6.9-78.0.24.EL.s390.rpm
File outdated by:  RHSA-2009:1588
    5ef52ff5e3c8f20acf1775917d8d481b
kernel-doc-2.6.9-78.0.24.EL.noarch.rpm
File outdated by:  RHSA-2009:1588
    9cb07db9a978f28c33a626f792b930c0
 
s390x:
kernel-2.6.9-78.0.24.EL.s390x.rpm
File outdated by:  RHSA-2009:1588
    dd5c0549573ac2ea0b0fc2d18dd11ad5
kernel-devel-2.6.9-78.0.24.EL.s390x.rpm
File outdated by:  RHSA-2009:1588
    c78a176b05b2324eacd9fd95c80dab26
kernel-doc-2.6.9-78.0.24.EL.noarch.rpm
File outdated by:  RHSA-2009:1588
    9cb07db9a978f28c33a626f792b930c0
 
x86_64:
kernel-2.6.9-78.0.24.EL.x86_64.rpm
File outdated by:  RHSA-2009:1588
    a87945193a72538ae4f802f939379c7d
kernel-devel-2.6.9-78.0.24.EL.x86_64.rpm
File outdated by:  RHSA-2009:1588
    73fa6d23833cf997dc9efd0a51d654db
kernel-doc-2.6.9-78.0.24.EL.noarch.rpm
File outdated by:  RHSA-2009:1588
    9cb07db9a978f28c33a626f792b930c0
kernel-largesmp-2.6.9-78.0.24.EL.x86_64.rpm
File outdated by:  RHSA-2009:1588
    ee40727704b97f9445332a37bc40d707
kernel-largesmp-devel-2.6.9-78.0.24.EL.x86_64.rpm
File outdated by:  RHSA-2009:1588
    23fe6a34ab9cc234052df4c8382e858c
kernel-smp-2.6.9-78.0.24.EL.x86_64.rpm
File outdated by:  RHSA-2009:1588
    397565ca73609b93bcaf9b05016834ed
kernel-smp-devel-2.6.9-78.0.24.EL.x86_64.rpm
File outdated by:  RHSA-2009:1588
    b4de58c0c0c69cd5ae4d5fce4dfd9cbd
kernel-xenU-2.6.9-78.0.24.EL.x86_64.rpm
File outdated by:  RHSA-2009:1588
    d42dfc86eb9afe01687f248d51d16fb7
kernel-xenU-devel-2.6.9-78.0.24.EL.x86_64.rpm
File outdated by:  RHSA-2009:1588
    55fcfb449d7d62bfa1b18845cd986b4a
 
Red Hat Enterprise Linux ES (v. 4.7.z)

SRPMS:
kernel-2.6.9-78.0.24.EL.src.rpm
File outdated by:  RHSA-2009:1588
    742108ec7710c66a7bf3add1df32a132
 
IA-32:
kernel-2.6.9-78.0.24.EL.i686.rpm
File outdated by:  RHSA-2009:1588
    a6bafea34ce3da8ef1a79f9e1391e336
kernel-devel-2.6.9-78.0.24.EL.i686.rpm
File outdated by:  RHSA-2009:1588
    9af2abf2561a79169e4b3ef86db09ae8
kernel-doc-2.6.9-78.0.24.EL.noarch.rpm
File outdated by:  RHSA-2009:1588
    9cb07db9a978f28c33a626f792b930c0
kernel-hugemem-2.6.9-78.0.24.EL.i686.rpm
File outdated by:  RHSA-2009:1588
    d29a1936f9ea46e6ee2c8dd018021363
kernel-hugemem-devel-2.6.9-78.0.24.EL.i686.rpm
File outdated by:  RHSA-2009:1588
    a4fe83577eb68dda087cae027d5a5db7
kernel-smp-2.6.9-78.0.24.EL.i686.rpm
File outdated by:  RHSA-2009:1588
    f3b927d567207293ad942b269fb322ad
kernel-smp-devel-2.6.9-78.0.24.EL.i686.rpm
File outdated by:  RHSA-2009:1588
    39585a68638c8374a8c8e4720c8d8d8b
kernel-xenU-2.6.9-78.0.24.EL.i686.rpm
File outdated by:  RHSA-2009:1588
    3699e20798e4269aa9b7a0e37808c81d
kernel-xenU-devel-2.6.9-78.0.24.EL.i686.rpm
File outdated by:  RHSA-2009:1588
    e11ed8dcf7f137765dfad908f15a8b94
 
IA-64:
kernel-2.6.9-78.0.24.EL.ia64.rpm
File outdated by:  RHSA-2009:1588
    e222cfd019e094daf72698fb4362274f
kernel-devel-2.6.9-78.0.24.EL.ia64.rpm
File outdated by:  RHSA-2009:1588
    fd29dbc2837e09b9913f8135d6e303a8
kernel-doc-2.6.9-78.0.24.EL.noarch.rpm
File outdated by:  RHSA-2009:1588
    9cb07db9a978f28c33a626f792b930c0
kernel-largesmp-2.6.9-78.0.24.EL.ia64.rpm
File outdated by:  RHSA-2009:1588
    72462e4441565be92c16aa8f1f5e847a
kernel-largesmp-devel-2.6.9-78.0.24.EL.ia64.rpm
File outdated by:  RHSA-2009:1588
    b29e124b98e6c74c6035f69d2bc69005
 
x86_64:
kernel-2.6.9-78.0.24.EL.x86_64.rpm
File outdated by:  RHSA-2009:1588
    a87945193a72538ae4f802f939379c7d
kernel-devel-2.6.9-78.0.24.EL.x86_64.rpm
File outdated by:  RHSA-2009:1588
    73fa6d23833cf997dc9efd0a51d654db
kernel-doc-2.6.9-78.0.24.EL.noarch.rpm
File outdated by:  RHSA-2009:1588
    9cb07db9a978f28c33a626f792b930c0
kernel-largesmp-2.6.9-78.0.24.EL.x86_64.rpm
File outdated by:  RHSA-2009:1588
    ee40727704b97f9445332a37bc40d707
kernel-largesmp-devel-2.6.9-78.0.24.EL.x86_64.rpm
File outdated by:  RHSA-2009:1588
    23fe6a34ab9cc234052df4c8382e858c
kernel-smp-2.6.9-78.0.24.EL.x86_64.rpm
File outdated by:  RHSA-2009:1588
    397565ca73609b93bcaf9b05016834ed
kernel-smp-devel-2.6.9-78.0.24.EL.x86_64.rpm
File outdated by:  RHSA-2009:1588
    b4de58c0c0c69cd5ae4d5fce4dfd9cbd
kernel-xenU-2.6.9-78.0.24.EL.x86_64.rpm
File outdated by:  RHSA-2009:1588
    d42dfc86eb9afe01687f248d51d16fb7
kernel-xenU-devel-2.6.9-78.0.24.EL.x86_64.rpm
File outdated by:  RHSA-2009:1588
    55fcfb449d7d62bfa1b18845cd986b4a
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

491752 - For Broadcom(r) BMC57710, modprobe bnx2* fails citing memory allocation failures
493771 - CVE-2009-1337 kernel: exit_notify: kill the wrong capable(CAP_KILL) check
494074 - CVE-2009-1336 kernel: nfsv4 client can be crashed by stating a long filename


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/