<!-- 
RSS generated by JIRA (9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c) at Sat Feb 10 01:44:23 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>Whamcloud Community JIRA</title>
    <link>https://jira.whamcloud.com</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>9.4.14</version>
        <build-number>940014</build-number>
        <build-date>05-12-2023</build-date>
    </build-info>


<item>
            <title>[LU-4620] Kernel update [RHEL6.5 2.6.32-431.5.1.el6]</title>
                <link>https://jira.whamcloud.com/browse/LU-4620</link>
                <project id="10000" key="LU">Lustre</project>
                    <description>&lt;p&gt;This update fixes the following security issues:&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;A buffer overflow flaw was found in the way the qeth_snmp_command()&lt;br/&gt;
function in the Linux kernel&apos;s QETH network device driver implementation&lt;br/&gt;
handled SNMP IOCTL requests with an out-of-bounds length. A local,&lt;br/&gt;
unprivileged user could use this flaw to crash the system or, potentially,&lt;br/&gt;
escalate their privileges on the system. (CVE-2013-6381, Important)&lt;/li&gt;
&lt;/ul&gt;


&lt;ul&gt;
	&lt;li&gt;A flaw was found in the way the get_dumpable() function return value was&lt;br/&gt;
interpreted in the ptrace subsystem of the Linux kernel. When&lt;br/&gt;
&apos;fs.suid_dumpable&apos; was set to 2, a local, unprivileged local user could&lt;br/&gt;
use this flaw to bypass intended ptrace restrictions and obtain&lt;br/&gt;
potentially sensitive information. (CVE-2013-2929, Low)&lt;/li&gt;
&lt;/ul&gt;


&lt;ul&gt;
	&lt;li&gt;It was found that certain protocol handlers in the Linux kernel&apos;s&lt;br/&gt;
networking implementation could set the addr_len value without initializing&lt;br/&gt;
the associated data structure. A local, unprivileged user could use this&lt;br/&gt;
flaw to leak kernel stack memory to user space using the recvmsg, recvfrom,&lt;br/&gt;
and recvmmsg system calls (CVE-2013-7263, CVE-2013-7265, Low).&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;This update also fixes several bugs.&lt;/p&gt;

&lt;p&gt;Bugs fixed (&lt;a href=&quot;https://bugzilla.redhat.com/):&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://bugzilla.redhat.com/):&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;1028148 - CVE-2013-2929 kernel: exec/ptrace: get_dumpable() incorrect tests&lt;br/&gt;
1033600 - CVE-2013-6381 Kernel: qeth: buffer overflow in snmp ioctl&lt;br/&gt;
1035875 - CVE-2013-7263 CVE-2013-7265 Kernel: net: leakage of uninitialized memory to user-space via recv syscalls&lt;/p&gt;</description>
                <environment></environment>
        <key id="23128">LU-4620</key>
            <summary>Kernel update [RHEL6.5 2.6.32-431.5.1.el6]</summary>
                <type id="4" iconUrl="https://jira.whamcloud.com/secure/viewavatar?size=xsmall&amp;avatarId=11310&amp;avatarType=issuetype">Improvement</type>
                                            <priority id="1" iconUrl="https://jira.whamcloud.com/images/icons/priorities/blocker.svg">Blocker</priority>
                        <status id="5" iconUrl="https://jira.whamcloud.com/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="success"/>
                                    <resolution id="1">Fixed</resolution>
                                        <assignee username="bogl">Bob Glossman</assignee>
                                    <reporter username="bogl">Bob Glossman</reporter>
                        <labels>
                            <label>MB</label>
                    </labels>
                <created>Wed, 12 Feb 2014 21:54:48 +0000</created>
                <updated>Mon, 24 Mar 2014 18:19:45 +0000</updated>
                            <resolved>Thu, 20 Feb 2014 19:57:08 +0000</resolved>
                                                    <fixVersion>Lustre 2.6.0</fixVersion>
                    <fixVersion>Lustre 2.5.1</fixVersion>
                                        <due></due>
                            <votes>0</votes>
                                    <watches>5</watches>
                                                                            <comments>
                            <comment id="76978" author="bogl" created="Thu, 13 Feb 2014 16:27:09 +0000"  >&lt;p&gt;&lt;a href=&quot;http://review.whamcloud.com/9253&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;http://review.whamcloud.com/9253&lt;/a&gt;&lt;/p&gt;</comment>
                            <comment id="77025" author="bogl" created="Thu, 13 Feb 2014 22:05:59 +0000"  >&lt;p&gt;client builds failing.  apparently need some TEI work for the new version. example errors:&lt;/p&gt;
&lt;div class=&quot;preformatted panel&quot; style=&quot;border-width: 1px;&quot;&gt;&lt;div class=&quot;preformattedContent panelContent&quot;&gt;
&lt;pre&gt;+++ yumdownloader --destdir /var/lib/jenkins/lbuild-data/kernelrpm/2.6.32/rhel6/i686/yum61HYOn kernel-devel-2.6.32-431.5.1.el6
+++ fatal 1 &apos;failed to fetch kernel-devel-2.6.32-431.5.1.el6 with yumdownloader.&apos;
+++ cleanup
+++ true
+++ error &apos;failed to fetch kernel-devel-2.6.32-431.5.1.el6 with yumdownloader.&apos;
+++ local &apos;msg=failed to fetch kernel-devel-2.6.32-431.5.1.el6 with yumdownloader.&apos;
+++ &apos;[&apos; -n &apos;failed to fetch kernel-devel-2.6.32-431.5.1.el6 with yumdownloader.&apos; &apos;]&apos;
+++ echo -e &apos;\nlbuild: failed to fetch kernel-devel-2.6.32-431.5.1.el6 with yumdownloader.&apos;

lbuild: failed to fetch kernel-devel-2.6.32-431.5.1.el6 with yumdownloader.
&lt;/pre&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;p&gt;will enter a new TEI ticket&lt;/p&gt;</comment>
                            <comment id="77419" author="bogl" created="Wed, 19 Feb 2014 21:06:27 +0000"  >&lt;p&gt;in b2_5:&lt;br/&gt;
&lt;a href=&quot;http://review.whamcloud.com/9318&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;http://review.whamcloud.com/9318&lt;/a&gt;&lt;/p&gt;</comment>
                            <comment id="77507" author="pjones" created="Thu, 20 Feb 2014 19:57:08 +0000"  >&lt;p&gt;Landed for 2.5.1 and 2.6&lt;/p&gt;</comment>
                            <comment id="80094" author="jaylan" created="Mon, 24 Mar 2014 18:19:45 +0000"  >&lt;p&gt;Plan to land this one for 2.4.x also?&lt;/p&gt;</comment>
                    </comments>
                <issuelinks>
                            <issuelinktype id="10120">
                    <name>Blocker</name>
                                                                <inwardlinks description="is blocked by">
                                                        </inwardlinks>
                                    </issuelinktype>
                            <issuelinktype id="10011">
                    <name>Related</name>
                                                                <inwardlinks description="is related to">
                                        <issuelink>
            <issuekey id="23143">LU-4628</issuekey>
        </issuelink>
                            </inwardlinks>
                                    </issuelinktype>
                    </issuelinks>
                <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                                                                                                                                            <customfield id="customfield_10890" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10390" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|hzwez3:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10090" key="com.pyxis.greenhopper.jira:gh-global-rank">
                        <customfieldname>Rank (Obsolete)</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>12645</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                </customfields>
    </item>
</channel>
</rss>