[LU-9979] kernel update [RHEL6.9 2.6.32-696.10.2.el6] Created: 12/Sep/17  Updated: 03/Oct/17  Resolved: 21/Sep/17

Status: Resolved
Project: Lustre
Component/s: None
Affects Version/s: None
Fix Version/s: Lustre 2.10.1, Lustre 2.11.0

Type: Improvement Priority: Minor
Reporter: Bob Glossman (Inactive) Assignee: Bob Glossman (Inactive)
Resolution: Fixed Votes: 0
Labels: None

Issue Links:
Related
is related to LU-9903 kernel update [RHEL6.9 2.6.32-696.10.... Resolved
is related to LU-10037 kernel update [RHEL6.9 2.6.32-696.10.... Resolved
Severity: 3
Rank (Obsolete): 9223372036854775807

 Description   

Security Fix(es):

A stack buffer overflow flaw was found in the way the Bluetooth subsystem of the Linux kernel processed pending L2CAP configuration responses from a client. On systems with the stack protection feature enabled in the kernel (CONFIG_CC_STACKPROTECTOR=y, which is enabled on all architectures other than s390x and ppc64[le]), an unauthenticated attacker able to initiate a connection to a system via Bluetooth could use this flaw to crash the system. Due to the nature of the stack protection feature, code execution cannot be fully ruled out, although we believe it is unlikely. On systems without the stack protection feature (ppc64[le]; the Bluetooth modules are not built on s390x), an unauthenticated attacker able to initiate a connection to a system via Bluetooth could use this flaw to remotely execute arbitrary code on the system with ring 0 (kernel) privileges. (CVE-2017-1000251, Important)

Bugs fixed (https://bugzilla.redhat.com/):

BZ - 1489716 - CVE-2017-1000251 kernel: stack buffer overflow in the native Bluetooth stack



 Comments   
Comment by Gerrit Updater [ 13/Sep/17 ]

Bob Glossman (bob.glossman@intel.com) uploaded a new patch: https://review.whamcloud.com/28967
Subject: LU-9979 kernel: kernel update RHEL6.9 [2.6.32-696.10.2.el6]
Project: fs/lustre-release
Branch: master
Current Patch Set: 1
Commit: 1726b14d44f38c62a92d36bd4f3203b43dad123c

Comment by Gerrit Updater [ 13/Sep/17 ]

Bob Glossman (bob.glossman@intel.com) uploaded a new patch: https://review.whamcloud.com/28969
Subject: LU-9979 kernel: kernel update RHEL6.9 [2.6.32-696.10.2.el6]
Project: fs/lustre-release
Branch: b2_10
Current Patch Set: 1
Commit: 0e3ca32136104868a90e5a87ba7987b790977e87

Comment by Gerrit Updater [ 14/Sep/17 ]

John L. Hammond (john.hammond@intel.com) merged in patch https://review.whamcloud.com/28969/
Subject: LU-9979 kernel: kernel update RHEL6.9 [2.6.32-696.10.2.el6]
Project: fs/lustre-release
Branch: b2_10
Current Patch Set:
Commit: 5e2805a597985cad93adf5efa487660291e9c23c

Comment by Gerrit Updater [ 21/Sep/17 ]

Oleg Drokin (oleg.drokin@intel.com) merged in patch https://review.whamcloud.com/28967/
Subject: LU-9979 kernel: kernel update RHEL6.9 [2.6.32-696.10.2.el6]
Project: fs/lustre-release
Branch: master
Current Patch Set:
Commit: 62640bf7796e15d953703b2842a70fbcfa5b399f

Comment by Peter Jones [ 21/Sep/17 ]

Landed for 2.11

Generated at Sat Feb 10 02:30:59 UTC 2024 using Jira 9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c.