<!-- 
RSS generated by JIRA (9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c) at Sat Feb 10 01:49:43 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>Whamcloud Community JIRA</title>
    <link>https://jira.whamcloud.com</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>9.4.14</version>
        <build-number>940014</build-number>
        <build-date>05-12-2023</build-date>
    </build-info>


<item>
            <title>[LU-5238] Kernel update [RHEL6.5 2.6.32-431.20.3.el6]</title>
                <link>https://jira.whamcloud.com/browse/LU-5238</link>
                <project id="10000" key="LU">Lustre</project>
                    <description>&lt;ul&gt;
	&lt;li&gt;A flaw was found in the way the Linux kernel&apos;s futex subsystem handled&lt;br/&gt;
the requeuing of certain Priority Inheritance (PI) futexes. A local,&lt;br/&gt;
unprivileged user could use this flaw to escalate their privileges on the&lt;br/&gt;
system. (CVE-2014-3153, Important)&lt;/li&gt;
&lt;/ul&gt;


&lt;ul&gt;
	&lt;li&gt;A flaw was found in the way the Linux kernel&apos;s floppy driver handled user&lt;br/&gt;
space provided data in certain error code paths while processing FDRAWCMD&lt;br/&gt;
IOCTL commands. A local user with write access to /dev/fdX could use this&lt;br/&gt;
flaw to free (using the kfree() function) arbitrary kernel memory.&lt;br/&gt;
(CVE-2014-1737, Important)&lt;/li&gt;
&lt;/ul&gt;


&lt;ul&gt;
	&lt;li&gt;It was found that the Linux kernel&apos;s floppy driver leaked internal kernel&lt;br/&gt;
memory addresses to user space during the processing of the FDRAWCMD IOCTL&lt;br/&gt;
command. A local user with write access to /dev/fdX could use this flaw to&lt;br/&gt;
obtain information about the kernel heap arrangement. (CVE-2014-1738, Low)&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;Note: A local user with write access to /dev/fdX could use these two flaws&lt;br/&gt;
(CVE-2014-1737 in combination with CVE-2014-1738) to escalate their&lt;br/&gt;
privileges on the system.&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;It was discovered that the proc_ns_follow_link() function did not&lt;br/&gt;
properly return the LAST_BIND value in the last pathname component as is&lt;br/&gt;
expected for procfs symbolic links, which could lead to excessive freeing&lt;br/&gt;
of memory and consequent slab corruption. A local, unprivileged user could&lt;br/&gt;
use this flaw to crash the system. (CVE-2014-0203, Moderate)&lt;/li&gt;
&lt;/ul&gt;


&lt;ul&gt;
	&lt;li&gt;A flaw was found in the way the Linux kernel handled exceptions when&lt;br/&gt;
user-space applications attempted to use the linkage stack. On IBM S/390&lt;br/&gt;
systems, a local, unprivileged user could use this flaw to crash the&lt;br/&gt;
system. (CVE-2014-2039, Moderate)&lt;/li&gt;
&lt;/ul&gt;


&lt;ul&gt;
	&lt;li&gt;An invalid pointer dereference flaw was found in the Marvell 8xxx&lt;br/&gt;
Libertas WLAN (libertas) driver in the Linux kernel. A local user able to&lt;br/&gt;
write to a file that is provided by the libertas driver and located on the&lt;br/&gt;
debug file system (debugfs) could use this flaw to crash the system. Note:&lt;br/&gt;
The debugfs file system must be mounted locally to exploit this issue.&lt;br/&gt;
It is not mounted by default. (CVE-2013-6378, Low)&lt;/li&gt;
&lt;/ul&gt;


&lt;ul&gt;
	&lt;li&gt;A denial of service flaw was discovered in the way the Linux kernel&apos;s&lt;br/&gt;
SELinux implementation handled files with an empty SELinux security&lt;br/&gt;
context. A local user who has the CAP_MAC_ADMIN capability could use this&lt;br/&gt;
flaw to crash the system. (CVE-2014-1874, Low)&lt;/li&gt;
&lt;/ul&gt;
</description>
                <environment></environment>
        <key id="25248">LU-5238</key>
            <summary>Kernel update [RHEL6.5 2.6.32-431.20.3.el6]</summary>
                <type id="1" iconUrl="https://jira.whamcloud.com/secure/viewavatar?size=xsmall&amp;avatarId=11303&amp;avatarType=issuetype">Bug</type>
                                            <priority id="3" iconUrl="https://jira.whamcloud.com/images/icons/priorities/major.svg">Major</priority>
                        <status id="5" iconUrl="https://jira.whamcloud.com/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="success"/>
                                    <resolution id="1">Fixed</resolution>
                                        <assignee username="bogl">Bob Glossman</assignee>
                                    <reporter username="bogl">Bob Glossman</reporter>
                        <labels>
                    </labels>
                <created>Fri, 20 Jun 2014 15:51:08 +0000</created>
                <updated>Wed, 13 Aug 2014 22:21:57 +0000</updated>
                            <resolved>Wed, 16 Jul 2014 15:15:03 +0000</resolved>
                                    <version>Lustre 2.6.0</version>
                                    <fixVersion>Lustre 2.6.0</fixVersion>
                                        <due></due>
                            <votes>0</votes>
                                    <watches>2</watches>
                                                                            <comments>
                            <comment id="87706" author="bogl" created="Fri, 27 Jun 2014 16:40:24 +0000"  >&lt;p&gt;in master&lt;br/&gt;
&lt;a href=&quot;http://review.whamcloud.com/10875&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;http://review.whamcloud.com/10875&lt;/a&gt;&lt;br/&gt;
in b2_5&lt;br/&gt;
&lt;a href=&quot;http://review.whamcloud.com/10876&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;http://review.whamcloud.com/10876&lt;/a&gt;&lt;/p&gt;</comment>
                            <comment id="89231" author="jlevi" created="Wed, 16 Jul 2014 15:15:03 +0000"  >&lt;p&gt;Patch landed to Master. Backport to b2_5 is being tracked to land outside of this ticket.&lt;/p&gt;</comment>
                    </comments>
                <issuelinks>
                            <issuelinktype id="10120">
                    <name>Blocker</name>
                                                                <inwardlinks description="is blocked by">
                                                        </inwardlinks>
                                    </issuelinktype>
                    </issuelinks>
                <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                                                                                                                                            <customfield id="customfield_10890" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10390" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|hzwplj:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10090" key="com.pyxis.greenhopper.jira:gh-global-rank">
                        <customfieldname>Rank (Obsolete)</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>14604</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                            <customfield id="customfield_10060" key="com.atlassian.jira.plugin.system.customfieldtypes:select">
                        <customfieldname>Severity</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10022"><![CDATA[3]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        </customfields>
    </item>
</channel>
</rss>