<!-- 
RSS generated by JIRA (9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c) at Sat Feb 10 01:52:53 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>Whamcloud Community JIRA</title>
    <link>https://jira.whamcloud.com</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>9.4.14</version>
        <build-number>940014</build-number>
        <build-date>05-12-2023</build-date>
    </build-info>


<item>
            <title>[LU-5600] Kernel update [RHEL6.5 2.6.32-431.29.2.el6]</title>
                <link>https://jira.whamcloud.com/browse/LU-5600</link>
                <project id="10000" key="LU">Lustre</project>
                    <description>&lt;ul&gt;
	&lt;li&gt;A flaw was found in the way the Linux kernel&apos;s futex subsystem handled&lt;br/&gt;
reference counting when requeuing futexes during futex_wait(). A local,&lt;br/&gt;
unprivileged user could use this flaw to zero out the reference counter of&lt;br/&gt;
an inode or an mm struct that backs up the memory area of the futex, which&lt;br/&gt;
could lead to a use-after-free flaw, resulting in a system crash or,&lt;br/&gt;
potentially, privilege escalation. (CVE-2014-0205, Important)&lt;/li&gt;
&lt;/ul&gt;


&lt;ul&gt;
	&lt;li&gt;A NULL pointer dereference flaw was found in the way the Linux kernel&apos;s&lt;br/&gt;
networking implementation handled logging while processing certain invalid&lt;br/&gt;
packets coming in via a VxLAN interface. A remote attacker could use this&lt;br/&gt;
flaw to crash the system by sending a specially crafted packet to such an&lt;br/&gt;
interface. (CVE-2014-3535, Important)&lt;/li&gt;
&lt;/ul&gt;


&lt;ul&gt;
	&lt;li&gt;An out-of-bounds memory access flaw was found in the Linux kernel&apos;s&lt;br/&gt;
system call auditing implementation. On a system with existing audit rules&lt;br/&gt;
defined, a local, unprivileged user could use this flaw to leak kernel&lt;br/&gt;
memory to user space or, potentially, crash the system. (CVE-2014-3917,&lt;br/&gt;
Moderate)&lt;/li&gt;
&lt;/ul&gt;


&lt;ul&gt;
	&lt;li&gt;An integer underflow flaw was found in the way the Linux kernel&apos;s Stream&lt;br/&gt;
Control Transmission Protocol (SCTP) implementation processed certain&lt;br/&gt;
COOKIE_ECHO packets. By sending a specially crafted SCTP packet, a remote&lt;br/&gt;
attacker could use this flaw to prevent legitimate connections to a&lt;br/&gt;
particular SCTP server socket to be made. (CVE-2014-4667, Moderate)&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;Bugs fixed (&lt;a href=&quot;https://bugzilla.redhat.com/):&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://bugzilla.redhat.com/):&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;1094455 - CVE-2014-0205 kernel: futex: refcount issue in case of requeue&lt;br/&gt;
1102571 - CVE-2014-3917 kernel: DoS with syscall auditing&lt;br/&gt;
1113967 - CVE-2014-4667 kernel: sctp: sk_ack_backlog wrap-around problem&lt;br/&gt;
1114540 - CVE-2014-3535 Kernel: netdevice.h: NULL pointer dereference over VxLAN&lt;/p&gt;</description>
                <environment></environment>
        <key id="26459">LU-5600</key>
            <summary>Kernel update [RHEL6.5 2.6.32-431.29.2.el6]</summary>
                <type id="1" iconUrl="https://jira.whamcloud.com/secure/viewavatar?size=xsmall&amp;avatarId=11303&amp;avatarType=issuetype">Bug</type>
                                            <priority id="4" iconUrl="https://jira.whamcloud.com/images/icons/priorities/minor.svg">Minor</priority>
                        <status id="5" iconUrl="https://jira.whamcloud.com/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="success"/>
                                    <resolution id="1">Fixed</resolution>
                                        <assignee username="bogl">Bob Glossman</assignee>
                                    <reporter username="bogl">Bob Glossman</reporter>
                        <labels>
                    </labels>
                <created>Tue, 9 Sep 2014 18:09:59 +0000</created>
                <updated>Thu, 18 Sep 2014 03:36:42 +0000</updated>
                            <resolved>Fri, 12 Sep 2014 17:14:55 +0000</resolved>
                                                    <fixVersion>Lustre 2.7.0</fixVersion>
                    <fixVersion>Lustre 2.5.4</fixVersion>
                                        <due></due>
                            <votes>0</votes>
                                    <watches>5</watches>
                                                                            <comments>
                            <comment id="93612" author="bogl" created="Tue, 9 Sep 2014 20:24:24 +0000"  >&lt;p&gt;master:&lt;br/&gt;
&lt;a href=&quot;http://review.whamcloud.com/11837&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;http://review.whamcloud.com/11837&lt;/a&gt;&lt;br/&gt;
b2_5:&lt;br/&gt;
&lt;a href=&quot;http://review.whamcloud.com/11838&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;http://review.whamcloud.com/11838&lt;/a&gt;&lt;/p&gt;</comment>
                            <comment id="93862" author="jlevi" created="Fri, 12 Sep 2014 17:14:55 +0000"  >&lt;p&gt;Patch landed to Master.&lt;/p&gt;</comment>
                    </comments>
                    <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                                                                                                                                            <customfield id="customfield_10890" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10390" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|hzwvuf:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10090" key="com.pyxis.greenhopper.jira:gh-global-rank">
                        <customfieldname>Rank (Obsolete)</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>15662</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                            <customfield id="customfield_10060" key="com.atlassian.jira.plugin.system.customfieldtypes:select">
                        <customfieldname>Severity</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10022"><![CDATA[3]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        </customfields>
    </item>
</channel>
</rss>