<!-- 
RSS generated by JIRA (9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c) at Sat Feb 10 01:51:11 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>Whamcloud Community JIRA</title>
    <link>https://jira.whamcloud.com</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>9.4.14</version>
        <build-number>940014</build-number>
        <build-date>05-12-2023</build-date>
    </build-info>


<item>
            <title>[LU-5403] Kernel update [RHEL6.5 2.6.32-431.23.3.el6]</title>
                <link>https://jira.whamcloud.com/browse/LU-5403</link>
                <project id="10000" key="LU">Lustre</project>
                    <description>&lt;ul&gt;
	&lt;li&gt;It was found that the Linux kernel&apos;s ptrace subsystem allowed a traced&lt;br/&gt;
process&apos; instruction pointer to be set to a non-canonical memory address&lt;br/&gt;
without forcing the non-sysret code path when returning to user space.&lt;br/&gt;
A local, unprivileged user could use this flaw to crash the system or,&lt;br/&gt;
potentially, escalate their privileges on the system. (CVE-2014-4699,&lt;br/&gt;
Important)&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;Note: The CVE-2014-4699 issue only affected systems using an Intel CPU.&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;A flaw was found in the way the pppol2tp_setsockopt() and&lt;br/&gt;
pppol2tp_getsockopt() functions in the Linux kernel&apos;s PPP over L2TP&lt;br/&gt;
implementation handled requests with a non-SOL_PPPOL2TP socket option&lt;br/&gt;
level. A local, unprivileged user could use this flaw to escalate their&lt;br/&gt;
privileges on the system. (CVE-2014-4943, Important)&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;Bugs fixed (&lt;a href=&quot;https://bugzilla.redhat.com/):&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://bugzilla.redhat.com/):&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;1115927 - CVE-2014-4699 kernel: x86_64: ptrace: sysret to non-canonical address&lt;br/&gt;
1119458 - CVE-2014-4943 kernel: net: pppol2tp: level handling in pppol2tp_&lt;span class=&quot;error&quot;&gt;&amp;#91;s,g&amp;#93;&lt;/span&gt;etsockopt()&lt;/p&gt;</description>
                <environment></environment>
        <key id="25718">LU-5403</key>
            <summary>Kernel update [RHEL6.5 2.6.32-431.23.3.el6]</summary>
                <type id="1" iconUrl="https://jira.whamcloud.com/secure/viewavatar?size=xsmall&amp;avatarId=11303&amp;avatarType=issuetype">Bug</type>
                                            <priority id="4" iconUrl="https://jira.whamcloud.com/images/icons/priorities/minor.svg">Minor</priority>
                        <status id="5" iconUrl="https://jira.whamcloud.com/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="success"/>
                                    <resolution id="1">Fixed</resolution>
                                        <assignee username="ys">Yang Sheng</assignee>
                                    <reporter username="ys">Yang Sheng</reporter>
                        <labels>
                    </labels>
                <created>Thu, 24 Jul 2014 02:39:22 +0000</created>
                <updated>Thu, 14 Aug 2014 16:43:50 +0000</updated>
                            <resolved>Thu, 14 Aug 2014 16:43:39 +0000</resolved>
                                                    <fixVersion>Lustre 2.7.0</fixVersion>
                    <fixVersion>Lustre 2.5.3</fixVersion>
                                        <due></due>
                            <votes>0</votes>
                                    <watches>3</watches>
                                                                            <comments>
                            <comment id="89924" author="ys" created="Thu, 24 Jul 2014 03:36:28 +0000"  >&lt;p&gt;Patch for master:  &lt;a href=&quot;http://review.whamcloud.com/11211&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;http://review.whamcloud.com/11211&lt;/a&gt;&lt;/p&gt;</comment>
                            <comment id="90449" author="bogl" created="Wed, 30 Jul 2014 16:12:15 +0000"  >&lt;p&gt;there&apos;s already an even newer kernel version update; 2.6.32-431.23.3.el6.  I think it makes most sense to wait for that to arrive in Centos then update our build to that version, skipping -431.20.5.  I plan to revise the mod in gerrit as soon as the update appears in Centos 6.&lt;/p&gt;</comment>
                            <comment id="91621" author="pjones" created="Thu, 14 Aug 2014 16:43:39 +0000"  >&lt;p&gt;Landed for 2.5.3 and 2.7&lt;/p&gt;</comment>
                    </comments>
                <issuelinks>
                            <issuelinktype id="10011">
                    <name>Related</name>
                                            <outwardlinks description="is related to ">
                                                        </outwardlinks>
                                                                <inwardlinks description="is related to">
                                                        </inwardlinks>
                                    </issuelinktype>
                    </issuelinks>
                <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                                                                                                                                            <customfield id="customfield_10890" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10390" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|hzws5r:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10090" key="com.pyxis.greenhopper.jira:gh-global-rank">
                        <customfieldname>Rank (Obsolete)</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>15037</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                            <customfield id="customfield_10060" key="com.atlassian.jira.plugin.system.customfieldtypes:select">
                        <customfieldname>Severity</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10022"><![CDATA[3]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        </customfields>
    </item>
</channel>
</rss>