<!-- 
RSS generated by JIRA (9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c) at Sat Feb 10 01:46:06 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>Whamcloud Community JIRA</title>
    <link>https://jira.whamcloud.com</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>9.4.14</version>
        <build-number>940014</build-number>
        <build-date>05-12-2023</build-date>
    </build-info>


<item>
            <title>[LU-4818] Kernel update [RHEL6.5 2.6.32-431.11.2.el6]</title>
                <link>https://jira.whamcloud.com/browse/LU-4818</link>
                <project id="10000" key="LU">Lustre</project>
                    <description>&lt;ul&gt;
	&lt;li&gt;A flaw was found in the way the get_rx_bufs() function in the vhost_net&lt;br/&gt;
implementation in the Linux kernel handled error conditions reported by the&lt;br/&gt;
vhost_get_vq_desc() function. A privileged guest user could use this flaw&lt;br/&gt;
to crash the host. (CVE-2014-0055, Important)&lt;/li&gt;
&lt;/ul&gt;


&lt;ul&gt;
	&lt;li&gt;A flaw was found in the way the Linux kernel processed an authenticated&lt;br/&gt;
COOKIE_ECHO chunk during the initialization of an SCTP connection. A remote&lt;br/&gt;
attacker could use this flaw to crash the system by initiating a specially&lt;br/&gt;
crafted SCTP handshake in order to trigger a NULL pointer dereference on&lt;br/&gt;
the system. (CVE-2014-0101, Important)&lt;/li&gt;
&lt;/ul&gt;


&lt;ul&gt;
	&lt;li&gt;A flaw was found in the way the Linux kernel&apos;s CIFS implementation&lt;br/&gt;
handled uncached write operations with specially crafted iovec structures.&lt;br/&gt;
An unprivileged local user with access to a CIFS share could use this flaw&lt;br/&gt;
to crash the system, leak kernel memory, or, potentially, escalate their&lt;br/&gt;
privileges on the system. Note: the default cache settings for CIFS mounts&lt;br/&gt;
on Red Hat Enterprise Linux 6 prohibit a successful exploitation of this&lt;br/&gt;
issue. (CVE-2014-0069, Moderate)&lt;/li&gt;
&lt;/ul&gt;


&lt;ul&gt;
	&lt;li&gt;A heap-based buffer overflow flaw was found in the Linux kernel&apos;s cdc-wdm&lt;br/&gt;
driver, used for USB CDC WCM device management. An attacker with physical&lt;br/&gt;
access to a system could use this flaw to cause a denial of service or,&lt;br/&gt;
potentially, escalate their privileges. (CVE-2013-1860, Low)&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;Bugs fixed (&lt;a href=&quot;https://bugzilla.redhat.com/):&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://bugzilla.redhat.com/):&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;921970 - CVE-2013-1860 kernel: usb: cdc-wdm buffer overflow triggered by device&lt;br/&gt;
1062577 - CVE-2014-0055 kernel: vhost-net: insufficient handling of error conditions in get_rx_bufs()&lt;br/&gt;
1064253 - CVE-2014-0069 kernel: cifs: incorrect handling of bogus user pointers during uncached writes&lt;br/&gt;
1070705 - CVE-2014-0101 kernel: net: sctp: null pointer dereference when processing authenticated cookie_echo chunk&lt;/p&gt;</description>
                <environment></environment>
        <key id="23897">LU-4818</key>
            <summary>Kernel update [RHEL6.5 2.6.32-431.11.2.el6]</summary>
                <type id="1" iconUrl="https://jira.whamcloud.com/secure/viewavatar?size=xsmall&amp;avatarId=11303&amp;avatarType=issuetype">Bug</type>
                                            <priority id="2" iconUrl="https://jira.whamcloud.com/images/icons/priorities/critical.svg">Critical</priority>
                        <status id="5" iconUrl="https://jira.whamcloud.com/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="success"/>
                                    <resolution id="1">Fixed</resolution>
                                        <assignee username="ys">Yang Sheng</assignee>
                                    <reporter username="ys">Yang Sheng</reporter>
                        <labels>
                    </labels>
                <created>Wed, 26 Mar 2014 02:17:10 +0000</created>
                <updated>Tue, 8 Apr 2014 15:31:19 +0000</updated>
                            <resolved>Tue, 8 Apr 2014 15:31:19 +0000</resolved>
                                                    <fixVersion>Lustre 2.6.0</fixVersion>
                                        <due></due>
                            <votes>0</votes>
                                    <watches>2</watches>
                                                                            <comments>
                            <comment id="80335" author="bogl" created="Wed, 26 Mar 2014 20:07:14 +0000"  >&lt;p&gt;&lt;a href=&quot;http://review.whamcloud.com/9797&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;http://review.whamcloud.com/9797&lt;/a&gt;&lt;/p&gt;</comment>
                            <comment id="81180" author="ys" created="Tue, 8 Apr 2014 15:31:19 +0000"  >&lt;p&gt;Patch was landed for 2.6.0.&lt;/p&gt;</comment>
                    </comments>
                <issuelinks>
                            <issuelinktype id="10011">
                    <name>Related</name>
                                                                <inwardlinks description="is related to">
                                                        </inwardlinks>
                                    </issuelinktype>
                    </issuelinks>
                <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                                                                                                                                            <customfield id="customfield_10890" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10390" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|hzwief:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10090" key="com.pyxis.greenhopper.jira:gh-global-rank">
                        <customfieldname>Rank (Obsolete)</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>13254</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                            <customfield id="customfield_10060" key="com.atlassian.jira.plugin.system.customfieldtypes:select">
                        <customfieldname>Severity</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10022"><![CDATA[3]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        </customfields>
    </item>
</channel>
</rss>