[LU-4818] Kernel update [RHEL6.5 2.6.32-431.11.2.el6] Created: 26/Mar/14  Updated: 08/Apr/14  Resolved: 08/Apr/14

Status: Resolved
Project: Lustre
Component/s: None
Affects Version/s: None
Fix Version/s: Lustre 2.6.0

Type: Bug Priority: Critical
Reporter: Yang Sheng Assignee: Yang Sheng
Resolution: Fixed Votes: 0
Labels: None

Issue Links:
Related
Severity: 3
Rank (Obsolete): 13254

 Description   
  • A flaw was found in the way the get_rx_bufs() function in the vhost_net
    implementation in the Linux kernel handled error conditions reported by the
    vhost_get_vq_desc() function. A privileged guest user could use this flaw
    to crash the host. (CVE-2014-0055, Important)
  • A flaw was found in the way the Linux kernel processed an authenticated
    COOKIE_ECHO chunk during the initialization of an SCTP connection. A remote
    attacker could use this flaw to crash the system by initiating a specially
    crafted SCTP handshake in order to trigger a NULL pointer dereference on
    the system. (CVE-2014-0101, Important)
  • A flaw was found in the way the Linux kernel's CIFS implementation
    handled uncached write operations with specially crafted iovec structures.
    An unprivileged local user with access to a CIFS share could use this flaw
    to crash the system, leak kernel memory, or, potentially, escalate their
    privileges on the system. Note: the default cache settings for CIFS mounts
    on Red Hat Enterprise Linux 6 prohibit a successful exploitation of this
    issue. (CVE-2014-0069, Moderate)
  • A heap-based buffer overflow flaw was found in the Linux kernel's cdc-wdm
    driver, used for USB CDC WCM device management. An attacker with physical
    access to a system could use this flaw to cause a denial of service or,
    potentially, escalate their privileges. (CVE-2013-1860, Low)

Bugs fixed (https://bugzilla.redhat.com/):

921970 - CVE-2013-1860 kernel: usb: cdc-wdm buffer overflow triggered by device
1062577 - CVE-2014-0055 kernel: vhost-net: insufficient handling of error conditions in get_rx_bufs()
1064253 - CVE-2014-0069 kernel: cifs: incorrect handling of bogus user pointers during uncached writes
1070705 - CVE-2014-0101 kernel: net: sctp: null pointer dereference when processing authenticated cookie_echo chunk



 Comments   
Comment by Bob Glossman (Inactive) [ 26/Mar/14 ]

http://review.whamcloud.com/9797

Comment by Yang Sheng [ 08/Apr/14 ]

Patch was landed for 2.6.0.

Generated at Sat Feb 10 01:46:06 UTC 2024 using Jira 9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c.