Updated kernel packages that fix two security issues are now available forRed Hat Enterprise Linux 6.2 Advanced Update Support.Red Hat Product Security has rated this update as having Important securityimpact. Common Vulnerability Scoring System (CVSS) base scores, which givedetailed severity ratings, are available for each vulnerability from theCVE links in the References section.

The kernel packages contain the Linux kernel, the core of any Linuxoperating system.* A use-after-free flaw was found in the way the Linux kernel’s SCTPimplementation handled authentication key reference counting during INITcollisions. A remote attacker could use this flaw to crash the system or,potentially, escalate their privileges on the system. (CVE-2015-1421,Important)* It was found that the Linux kernel’s implementation of vectored pipe readand write functionality did not take into account the I/O vectors that werealready processed when retrying after a failed atomic access operation,potentially resulting in memory corruption due to an I/O vector arrayoverrun. A local, unprivileged user could use this flaw to crash the systemor, potentially, escalate their privileges on the system. (CVE-2015-1805,Important)The CVE-2015-1421 issue was discovered by Sun Baoliang of Red Hat, and thesecurity impact of the CVE-2015-1805 issue was discovered by Red Hat.All kernel users are advised to upgrade to these updated packages, whichcontain backported patches to correct these issues. The system must berebooted for this update to take effect.
Before applying this update, make sure all previously released erratarelevant to your system have been applied.For details on how to apply this update, refer to:https://access.redhat.com/articles/11258Red Hat Enterprise Linux Server AUS (v. 6.2)

SRPMS:
kernel-2.6.32-220.63.2.el6.src.rpm
    MD5: b6e1e0e1a8a675936bf082dc56b97933SHA-256: c0ab970b38d2e16dccc3739db3f4f1268e870314c129b2c067d1d879ef71e1b5
 
x86_64:
kernel-2.6.32-220.63.2.el6.x86_64.rpm
    MD5: 28392b3f87774e82e564dc4e532aa458SHA-256: 9ed98c31b104e4537e3f9112e5ed8536f6dffe1d55f47542a74fad682cf611eb
kernel-debug-2.6.32-220.63.2.el6.x86_64.rpm
    MD5: a7b790fad8842e93e25d5f25b3533e48SHA-256: 2604188d6dd48ba2bbc517124cf811005fcc047451b852ef32394eb047a91c96
kernel-debug-debuginfo-2.6.32-220.63.2.el6.x86_64.rpm
    MD5: 9b8e457bf305841909cefa8d5a4e9e01SHA-256: c8fbb779f301128192e8a66bfbe29d6dbcde2b420e3a864c76257c6d093efad0
kernel-debug-devel-2.6.32-220.63.2.el6.x86_64.rpm
    MD5: 423c9d89c6798352adb2b456b0bce3bdSHA-256: 42a05b1b3e0426f4e601e37b1b0ccc5d2fe31be6fb301eb7562d8e10c996669f
kernel-debuginfo-2.6.32-220.63.2.el6.x86_64.rpm
    MD5: f52366ee2f8a03b789d2cef2cbc05eebSHA-256: f122284cda36d8925370d18911397298204a4cdb2a07d8960e680994cd470e75
kernel-debuginfo-common-x86_64-2.6.32-220.63.2.el6.x86_64.rpm
    MD5: ba503216ca591bfd752b9dc4ad058194SHA-256: a0469f98fed9d07f2ec5c41b6ce1e183a1e346bc0c5c5590ad8d225341483dc6
kernel-devel-2.6.32-220.63.2.el6.x86_64.rpm
    MD5: 5c8da5384fbb964aeb77641d7e274731SHA-256: 77542d74e3890d018a6147056321322c69c62b36d8805107052a7896a109c478
kernel-doc-2.6.32-220.63.2.el6.noarch.rpm
    MD5: 7fc00ba494cf22632af79c3dbe31f9e5SHA-256: 1a6d750f494f7781c4b86cdc8d7100eba6bb85fc1f6b6d147d1640ec3fe992a0
kernel-firmware-2.6.32-220.63.2.el6.noarch.rpm
    MD5: cb610b283152b874e4c24dd88773d4fbSHA-256: 7304d59d3864acd1ef3a5c94098cea66db9119d2512416c4b21d6a8631c4d980
kernel-headers-2.6.32-220.63.2.el6.x86_64.rpm
    MD5: bb574b275304ba51df5be8cc3a77a623SHA-256: 00009981a2c4c33246b13a47b621eeb28e386c3a4cb566460fb5eb4add1bd8db
perf-2.6.32-220.63.2.el6.x86_64.rpm
    MD5: 5171aae827819db26fc71ce79f8d17a3SHA-256: eab797a5a8b7b14af0d92be2f2318c3088d3f16c9c3b173eb5f10252acd357c3
perf-debuginfo-2.6.32-220.63.2.el6.x86_64.rpm
    MD5: ca0ec3d4184d9275e88217ec5fb2079bSHA-256: bf322de9f07dbec502dd3faca7a90aa442ff9af995e6ff0f9e72ed943927c9cd
python-perf-2.6.32-220.63.2.el6.x86_64.rpm
    MD5: f20c78cbfd7b6dcbfc856febabb1ddc5SHA-256: a894df324f8b6bb4b117d2df070a636d5319f5af252c6b7a0a76d9c17b0ae911
python-perf-debuginfo-2.6.32-220.63.2.el6.x86_64.rpm
    MD5: 8de9e227810cb7c8f077b98dde3ba0c7SHA-256: 098a616f93a12694d36a6a0733328ad36713278d90fe560eb2fb53028605a678
 
(The unlinked packages above are only available from the Red Hat Network)
1196581 – CVE-2015-1421 kernel: net: slab corruption from use after free on INIT collisions1202855 – CVE-2015-1805 kernel: pipe: iovec overrun leading to memory corruption

These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from:

Leave a Reply