[LU-5025] Kernel update [RHEL6.5 2.6.32-431.17.1.el6] Created: 07/May/14  Updated: 14/May/14  Resolved: 12/May/14

Status: Resolved
Project: Lustre
Component/s: None
Affects Version/s: Lustre 2.6.0
Fix Version/s: Lustre 2.6.0, Lustre 2.5.2

Type: Bug Priority: Critical
Reporter: Bob Glossman (Inactive) Assignee: Bob Glossman (Inactive)
Resolution: Fixed Votes: 0
Labels: None

Issue Links:
Related
is related to LU-4638 racer test hung: /mnt/lustre is still... Resolved
Severity: 3
Rank (Obsolete): 13906

 Description   
  • A flaw was found in the way the Linux kernel's netfilter connection
    tracking implementation for Datagram Congestion Control Protocol (DCCP)
    packets used the skb_header_pointer() function. A remote attacker could use
    this flaw to send a specially crafted DCCP packet to crash the system or,
    potentially, escalate their privileges on the system. (CVE-2014-2523,
    Important)
  • A flaw was found in the way the Linux kernel's Adaptec RAID controller
    (aacraid) checked permissions of compat IOCTLs. A local attacker could use
    this flaw to bypass intended security restrictions. (CVE-2013-6383,
    Moderate)
  • A flaw was found in the way the handle_rx() function handled large
    network packets when mergeable buffers were disabled. A privileged guest
    user could use this flaw to crash the host or corrupt QEMU process memory
    on the host, which could potentially result in arbitrary code execution on
    the host with the privileges of the QEMU process. (CVE-2014-0077, Moderate)


 Comments   
Comment by Bob Glossman (Inactive) [ 07/May/14 ]

This kernel update includes the fix we've been waiting for to repair LU-4638.

Comment by Peter Jones [ 09/May/14 ]

I think Kelsey accidentally hit "assign to me"

Comment by James A Simmons [ 09/May/14 ]

Updating my images to this kernel. Will be testing it starting today.

Comment by Bob Glossman (Inactive) [ 09/May/14 ]

in master: http://review.whamcloud.com/10282
in b2_5: http://review.whamcloud.com/10283

Comment by Peter Jones [ 12/May/14 ]

Landed for 2.6. Will track landing for b2_5 separately

Generated at Sat Feb 10 01:47:53 UTC 2024 using Jira 9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c.