[LU-9978] kernel update [RHEL7.4 3.10.0-693.2.2.el7] Created: 12/Sep/17  Updated: 19/Oct/17  Resolved: 09/Oct/17

Status: Resolved
Project: Lustre
Component/s: None
Affects Version/s: None
Fix Version/s: Lustre 2.11.0, Lustre 2.10.2

Type: Bug Priority: Minor
Reporter: Bob Glossman (Inactive) Assignee: Bob Glossman (Inactive)
Resolution: Fixed Votes: 0
Labels: None

Issue Links:
Related
is related to LU-9944 kernel update [RHEL7.4 3.10.0-693.2.1... Resolved
is related to LU-10142 kernel update [RHEL7.4 3.10.0-693.5.2... Resolved
Severity: 3
Rank (Obsolete): 9223372036854775807

 Description   

Security Fix(es):

A stack buffer overflow flaw was found in the way the Bluetooth subsystem of the Linux kernel processed pending L2CAP configuration responses from a client. On systems with the stack protection feature enabled in the kernel (CONFIG_CC_STACKPROTECTOR=y, which is enabled on all architectures other than s390x and ppc64[le]), an unauthenticated attacker able to initiate a connection to a system via Bluetooth could use this flaw to crash the system. Due to the nature of the stack protection feature, code execution cannot be fully ruled out, although we believe it is unlikely. On systems without the stack protection feature (ppc64[le]; the Bluetooth modules are not built on s390x), an unauthenticated attacker able to initiate a connection to a system via Bluetooth could use this flaw to remotely execute arbitrary code on the system with ring 0 (kernel) privileges. (CVE-2017-1000251, Important)

Bugs fixed (https://bugzilla.redhat.com/):

BZ - 1489716 - CVE-2017-1000251 kernel: stack buffer overflow in the native Bluetooth stack



 Comments   
Comment by Gerrit Updater [ 14/Sep/17 ]

Bob Glossman (bob.glossman@intel.com) uploaded a new patch: https://review.whamcloud.com/28999
Subject: LU-9978 kernel: kernel update RHEL7.4 [3.10.0-693.2.2.el7]
Project: fs/lustre-release
Branch: master
Current Patch Set: 1
Commit: 82cfad836304b53a0829651617509412ab179a95

Comment by Gerrit Updater [ 14/Sep/17 ]

Bob Glossman (bob.glossman@intel.com) uploaded a new patch: https://review.whamcloud.com/29002
Subject: LU-9978 kernel: kernel update RHEL7.4 [3.10.0-693.2.2.el7]
Project: fs/lustre-release
Branch: b2_10
Current Patch Set: 1
Commit: d66026886b8b78dc778e465bf44214b256f3bfff

Comment by Gerrit Updater [ 15/Sep/17 ]

John L. Hammond (john.hammond@intel.com) merged in patch https://review.whamcloud.com/29002/
Subject: LU-9978 kernel: kernel update RHEL7.4 [3.10.0-693.2.2.el7]
Project: fs/lustre-release
Branch: b2_10
Current Patch Set:
Commit: 1052a25616ba0e1e42869c63b309f6d9107f3966

Comment by Gerrit Updater [ 09/Oct/17 ]

Oleg Drokin (oleg.drokin@intel.com) merged in patch https://review.whamcloud.com/28999/
Subject: LU-9978 kernel: kernel update RHEL7.4 [3.10.0-693.2.2.el7]
Project: fs/lustre-release
Branch: master
Current Patch Set:
Commit: 8191f052ac5b3b2f54628bfc87c5f8897604b3a9

Comment by Peter Jones [ 09/Oct/17 ]

Landed for 2.11

Generated at Sat Feb 10 02:30:58 UTC 2024 using Jira 9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c.