<!-- 
RSS generated by JIRA (9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c) at Sat Feb 10 01:44:27 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>Whamcloud Community JIRA</title>
    <link>https://jira.whamcloud.com</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>9.4.14</version>
        <build-number>940014</build-number>
        <build-date>05-12-2023</build-date>
    </build-info>


<item>
            <title>[LU-4628] Kernel update [RHEL6.5 2.6.32-431.5.1.el6]</title>
                <link>https://jira.whamcloud.com/browse/LU-4628</link>
                <project id="10000" key="LU">Lustre</project>
                    <description>&lt;ul&gt;
	&lt;li&gt;A buffer overflow flaw was found in the way the qeth_snmp_command()&lt;br/&gt;
function in the Linux kernel&apos;s QETH network device driver implementation&lt;br/&gt;
handled SNMP IOCTL requests with an out-of-bounds length. A local,&lt;br/&gt;
unprivileged user could use this flaw to crash the system or, potentially,&lt;br/&gt;
escalate their privileges on the system. (CVE-2013-6381, Important)&lt;/li&gt;
&lt;/ul&gt;


&lt;ul&gt;
	&lt;li&gt;A flaw was found in the way the get_dumpable() function return value was&lt;br/&gt;
interpreted in the ptrace subsystem of the Linux kernel. When&lt;br/&gt;
&apos;fs.suid_dumpable&apos; was set to 2, a local, unprivileged local user could&lt;br/&gt;
use this flaw to bypass intended ptrace restrictions and obtain&lt;br/&gt;
potentially sensitive information. (CVE-2013-2929, Low)&lt;/li&gt;
&lt;/ul&gt;


&lt;ul&gt;
	&lt;li&gt;It was found that certain protocol handlers in the Linux kernel&apos;s&lt;br/&gt;
networking implementation could set the addr_len value without initializing&lt;br/&gt;
the associated data structure. A local, unprivileged user could use this&lt;br/&gt;
flaw to leak kernel stack memory to user space using the recvmsg, recvfrom,&lt;br/&gt;
and recvmmsg system calls (CVE-2013-7263, CVE-2013-7265, Low).&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;This update also fixes several bugs. &lt;/p&gt;

&lt;p&gt;Bugs fixed (&lt;a href=&quot;https://bugzilla.redhat.com/):&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://bugzilla.redhat.com/):&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;1028148 - CVE-2013-2929 kernel: exec/ptrace: get_dumpable() incorrect tests&lt;br/&gt;
1033600 - CVE-2013-6381 Kernel: qeth: buffer overflow in snmp ioctl&lt;br/&gt;
1035875 - CVE-2013-7263 CVE-2013-7265 Kernel: net: leakage of uninitialized memory to user-space via recv syscalls&lt;/p&gt;
</description>
                <environment></environment>
        <key id="23143">LU-4628</key>
            <summary>Kernel update [RHEL6.5 2.6.32-431.5.1.el6]</summary>
                <type id="1" iconUrl="https://jira.whamcloud.com/secure/viewavatar?size=xsmall&amp;avatarId=11303&amp;avatarType=issuetype">Bug</type>
                                            <priority id="4" iconUrl="https://jira.whamcloud.com/images/icons/priorities/minor.svg">Minor</priority>
                        <status id="5" iconUrl="https://jira.whamcloud.com/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="success"/>
                                    <resolution id="3">Duplicate</resolution>
                                        <assignee username="ys">Yang Sheng</assignee>
                                    <reporter username="ys">Yang Sheng</reporter>
                        <labels>
                    </labels>
                <created>Thu, 13 Feb 2014 13:05:57 +0000</created>
                <updated>Thu, 13 Feb 2014 15:59:56 +0000</updated>
                            <resolved>Thu, 13 Feb 2014 13:17:22 +0000</resolved>
                                                                        <due></due>
                            <votes>0</votes>
                                    <watches>2</watches>
                                                                            <comments>
                            <comment id="76956" author="pjones" created="Thu, 13 Feb 2014 13:17:23 +0000"  >&lt;p&gt;I think that this is already being tracked under lu-4620&lt;/p&gt;</comment>
                            <comment id="76976" author="dmiter" created="Thu, 13 Feb 2014 15:59:56 +0000"  >&lt;p&gt;It looks the same.&lt;/p&gt;</comment>
                    </comments>
                <issuelinks>
                            <issuelinktype id="10011">
                    <name>Related</name>
                                            <outwardlinks description="is related to ">
                                        <issuelink>
            <issuekey id="23128">LU-4620</issuekey>
        </issuelink>
                            </outwardlinks>
                                                        </issuelinktype>
                    </issuelinks>
                <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                                                                                                                                            <customfield id="customfield_10890" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10390" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|hzwf1r:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10090" key="com.pyxis.greenhopper.jira:gh-global-rank">
                        <customfieldname>Rank (Obsolete)</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>12658</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                            <customfield id="customfield_10060" key="com.atlassian.jira.plugin.system.customfieldtypes:select">
                        <customfieldname>Severity</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10022"><![CDATA[3]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        </customfields>
    </item>
</channel>
</rss>