Executive Summary

Summary
Titlekernel-rt security and bug fix update
Informations
NameRHSA-2017:1297First vendor Publication2017-05-25
VendorRedHatLast vendor Modification2017-05-25
Severity (Vendor) N/ARevision01

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Cvss Base Score9.3Attack RangeNetwork
Cvss Impact Score10Attack ComplexityMedium
Cvss Expoit Score8.6AuthenticationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

Problem Description:

An update for kernel-rt is now available for Red Hat Enterprise MRG 2.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

2. Relevant releases/architectures:

MRG Realtime for RHEL 6 Server v.2 - noarch, x86_64

3. Description:

The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.

Security Fix(es):

* It was found that the packet_set_ring() function of the Linux kernel's networking implementation did not properly validate certain block-size data. A local attacker with CAP_NET_RAW capability could use this flaw to trigger a buffer overflow, resulting in the crash of the system. Due to the nature of the flaw, privilege escalation cannot be fully ruled out. (CVE-2017-7308, Important)

* Mounting a crafted EXT4 image read-only leads to an attacker controlled memory corruption and SLAB-Out-of-Bounds reads. (CVE-2016-10208, Moderate)

* A flaw was found in the Linux kernel's implementation of seq_file where a local attacker could manipulate memory in the put() function pointer. This could lead to memory corruption and possible privileged escalation. (CVE-2016-7910, Moderate)

* A vulnerability was found in the Linux kernel. An unprivileged local user could trigger oops in shash_async_export() by attempting to force the in-kernel hashing algorithms into decrypting an empty data set. (CVE-2016-8646, Moderate)

Red Hat would like to thank Igor Redko (Virtuozzo kernel team) for reporting CVE-2016-8646.

Bug Fix(es):

* The kernel-rt packages have been upgraded to the 3.10.0-514 source tree, which provides a number of bug fixes over the previous version. (BZ#1440807)

4. Solution:

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

The system must be rebooted for this update to take effect.

5. Bugs fixed (https://bugzilla.redhat.com/):

1388821 - CVE-2016-8646 kernel: Oops in shash_async_export() 1395190 - CVE-2016-10208 kernel: EXT4 memory corruption / SLAB out-of-bounds read 1399727 - CVE-2016-7910 kernel: Use after free in seq file 1437404 - CVE-2017-7308 kernel: net/packet: overflow in check for priv area size 1440807 - update the MRG 2.5.z 3.10 kernel-rt sources

Original Source

Url : https://rhn.redhat.com/errata/RHSA-2017-1297.html

CWE : Common Weakness Enumeration

%idName
25 %CWE-476NULL Pointer Dereference
25 %CWE-416Use After Free
25 %CWE-125Out-of-bounds Read
25 %CWE-119Failure to Constrain Operations within the Bounds of a Memory Buffer

CPE : Common Platform Enumeration

TypeDescriptionCount
Os2743

Nessus® Vulnerability Scanner

DateDescription
2018-08-17Name : The remote PhotonOS host is missing multiple security updates.
File : PhotonOS_PHSA-2017-0011.nasl - Type : ACT_GATHER_INFO
2018-06-22Name : The remote CentOS host is missing one or more security updates.
File : centos_RHSA-2018-1854.nasl - Type : ACT_GATHER_INFO
2017-12-11Name : The remote Debian host is missing a security update.
File : debian_DLA-1200.nasl - Type : ACT_GATHER_INFO
2017-12-11Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2017-3658.nasl - Type : ACT_GATHER_INFO
2017-11-03Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2017-3637.nasl - Type : ACT_GATHER_INFO
2017-09-20Name : The remote SUSE host is missing one or more security updates.
File : suse_SU-2017-2525-1.nasl - Type : ACT_GATHER_INFO
2017-08-25Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2017-3609.nasl - Type : ACT_GATHER_INFO
2017-08-25Name : The remote OracleVM host is missing one or more security updates.
File : oraclevm_OVMSA-2017-0145.nasl - Type : ACT_GATHER_INFO
2017-08-16Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2017-1842-1.nasl - Type : ACT_GATHER_INFO
2017-07-31Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2017-3595.nasl - Type : ACT_GATHER_INFO
2017-07-31Name : The remote OracleVM host is missing one or more security updates.
File : oraclevm_OVMSA-2017-0126.nasl - Type : ACT_GATHER_INFO
2017-07-24Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-3361-1.nasl - Type : ACT_GATHER_INFO
2017-07-21Name : The remote EulerOS host is missing multiple security updates.
File : EulerOS_SA-2017-1122.nasl - Type : ACT_GATHER_INFO
2017-07-21Name : The remote EulerOS host is missing multiple security updates.
File : EulerOS_SA-2017-1123.nasl - Type : ACT_GATHER_INFO
2017-07-13Name : The remote Virtuozzo host is missing a security update.
File : Virtuozzo_VZLSA-2017-0892.nasl - Type : ACT_GATHER_INFO
2017-07-13Name : The remote Virtuozzo host is missing a security update.
File : Virtuozzo_VZLSA-2017-1308.nasl - Type : ACT_GATHER_INFO
2017-06-05Name : The remote Virtuozzo host is missing a security update.
File : Virtuozzo_VZA-2017-042.nasl - Type : ACT_GATHER_INFO
2017-06-05Name : The remote Virtuozzo host is missing a security update.
File : Virtuozzo_VZA-2017-043.nasl - Type : ACT_GATHER_INFO
2017-06-02Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2017-3579.nasl - Type : ACT_GATHER_INFO
2017-06-02Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2017-3580.nasl - Type : ACT_GATHER_INFO
2017-06-02Name : The remote OracleVM host is missing one or more security updates.
File : oraclevm_OVMSA-2017-0111.nasl - Type : ACT_GATHER_INFO
2017-06-02Name : The remote OracleVM host is missing one or more security updates.
File : oraclevm_OVMSA-2017-0112.nasl - Type : ACT_GATHER_INFO
2017-05-30Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2017-1308-1.nasl - Type : ACT_GATHER_INFO
2017-05-30Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2017-1308.nasl - Type : ACT_GATHER_INFO
2017-05-26Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2017-1297.nasl - Type : ACT_GATHER_INFO
2017-05-26Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2017-1298.nasl - Type : ACT_GATHER_INFO
2017-05-26Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2017-1308.nasl - Type : ACT_GATHER_INFO
2017-05-26Name : The remote Scientific Linux host is missing one or more security updates.
File : sl_20170525_kernel_on_SL7_x.nasl - Type : ACT_GATHER_INFO
2017-05-26Name : The remote CentOS host is missing one or more security updates.
File : centos_RHSA-2017-1308.nasl - Type : ACT_GATHER_INFO
2017-05-22Name : The remote SUSE host is missing one or more security updates.
File : suse_SU-2017-1360-1.nasl - Type : ACT_GATHER_INFO
2017-05-17Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2017-3566.nasl - Type : ACT_GATHER_INFO
2017-05-17Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2017-3567.nasl - Type : ACT_GATHER_INFO
2017-05-17Name : The remote OracleVM host is missing one or more security updates.
File : oraclevm_OVMSA-2017-0105.nasl - Type : ACT_GATHER_INFO
2017-05-17Name : The remote OracleVM host is missing one or more security updates.
File : oraclevm_OVMSA-2017-0106.nasl - Type : ACT_GATHER_INFO
2017-05-16Name : The remote SUSE host is missing one or more security updates.
File : suse_SU-2017-1278-1.nasl - Type : ACT_GATHER_INFO
2017-05-16Name : The remote SUSE host is missing one or more security updates.
File : suse_SU-2017-1281-1.nasl - Type : ACT_GATHER_INFO
2017-05-16Name : The remote SUSE host is missing one or more security updates.
File : suse_SU-2017-1285-1.nasl - Type : ACT_GATHER_INFO
2017-05-16Name : The remote SUSE host is missing one or more security updates.
File : suse_SU-2017-1287-1.nasl - Type : ACT_GATHER_INFO
2017-05-16Name : The remote SUSE host is missing one or more security updates.
File : suse_SU-2017-1291-1.nasl - Type : ACT_GATHER_INFO
2017-05-16Name : The remote SUSE host is missing one or more security updates.
File : suse_SU-2017-1299-1.nasl - Type : ACT_GATHER_INFO
2017-05-16Name : The remote SUSE host is missing one or more security updates.
File : suse_SU-2017-1300-1.nasl - Type : ACT_GATHER_INFO
2017-05-16Name : The remote SUSE host is missing one or more security updates.
File : suse_SU-2017-1301-1.nasl - Type : ACT_GATHER_INFO
2017-05-16Name : The remote SUSE host is missing one or more security updates.
File : suse_SU-2017-1302-1.nasl - Type : ACT_GATHER_INFO
2017-05-12Name : The remote SUSE host is missing one or more security updates.
File : suse_SU-2017-1247-1.nasl - Type : ACT_GATHER_INFO
2017-05-11Name : The remote Amazon Linux AMI host is missing a security update.
File : ala_ALAS-2017-828.nasl - Type : ACT_GATHER_INFO
2017-05-09Name : The remote openSUSE host is missing a security update.
File : openSUSE-2017-562.nasl - Type : ACT_GATHER_INFO
2017-05-08Name : The remote device is missing a vendor-supplied security patch.
File : f5_bigip_SOL82224417.nasl - Type : ACT_GATHER_INFO
2017-05-08Name : The remote SUSE host is missing one or more security updates.
File : suse_SU-2017-1183-1.nasl - Type : ACT_GATHER_INFO
2017-05-02Name : The remote openSUSE host is missing a security update.
File : openSUSE-2017-532.nasl - Type : ACT_GATHER_INFO
2017-05-01Name : The remote EulerOS host is missing multiple security updates.
File : EulerOS_SA-2016-1089.nasl - Type : ACT_GATHER_INFO
2017-05-01Name : The remote Debian host is missing a security update.
File : debian_DLA-922.nasl - Type : ACT_GATHER_INFO
2017-04-18Name : The remote Fedora host is missing a security update.
File : fedora_2017-26c9ecd7a4.nasl - Type : ACT_GATHER_INFO
2017-04-18Name : The remote Fedora host is missing a security update.
File : fedora_2017-8e7549fb91.nasl - Type : ACT_GATHER_INFO
2017-04-14Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2017-3537.nasl - Type : ACT_GATHER_INFO
2017-04-14Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2017-3538.nasl - Type : ACT_GATHER_INFO
2017-04-14Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2017-3539.nasl - Type : ACT_GATHER_INFO
2017-04-14Name : The remote OracleVM host is missing one or more security updates.
File : oraclevm_OVMSA-2017-0060.nasl - Type : ACT_GATHER_INFO
2017-04-14Name : The remote OracleVM host is missing one or more security updates.
File : oraclevm_OVMSA-2017-0061.nasl - Type : ACT_GATHER_INFO
2017-04-14Name : The remote OracleVM host is missing one or more security updates.
File : oraclevm_OVMSA-2017-0062.nasl - Type : ACT_GATHER_INFO
2017-04-13Name : The remote CentOS host is missing one or more security updates.
File : centos_RHSA-2017-0892.nasl - Type : ACT_GATHER_INFO
2017-04-13Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2017-0892.nasl - Type : ACT_GATHER_INFO
2017-04-12Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2017-0892.nasl - Type : ACT_GATHER_INFO
2017-04-12Name : The remote Scientific Linux host is missing one or more security updates.
File : sl_20170411_kernel_on_SL6_x.nasl - Type : ACT_GATHER_INFO
2017-04-06Name : The remote Virtuozzo host is missing a security update.
File : Virtuozzo_VZA-2017-027.nasl - Type : ACT_GATHER_INFO
2017-04-05Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-3256-1.nasl - Type : ACT_GATHER_INFO
2017-04-05Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-3256-2.nasl - Type : ACT_GATHER_INFO
2017-04-03Name : The remote openSUSE host is missing a security update.
File : openSUSE-2017-419.nasl - Type : ACT_GATHER_INFO
2017-04-03Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2017-3534.nasl - Type : ACT_GATHER_INFO
2017-04-03Name : The remote OracleVM host is missing one or more security updates.
File : oraclevm_OVMSA-2017-0057.nasl - Type : ACT_GATHER_INFO
2017-03-16Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-3234-1.nasl - Type : ACT_GATHER_INFO
2017-03-16Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-3234-2.nasl - Type : ACT_GATHER_INFO
2017-02-22Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-3206-1.nasl - Type : ACT_GATHER_INFO
2017-02-22Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-3207-1.nasl - Type : ACT_GATHER_INFO
2017-02-22Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-3207-2.nasl - Type : ACT_GATHER_INFO
2017-02-21Name : The remote SUSE host is missing one or more security updates.
File : suse_SU-2017-0494-1.nasl - Type : ACT_GATHER_INFO
2017-02-16Name : The remote SUSE host is missing one or more security updates.
File : suse_SU-2017-0471-1.nasl - Type : ACT_GATHER_INFO
2017-02-15Name : The remote SUSE host is missing one or more security updates.
File : suse_SU-2017-0464-1.nasl - Type : ACT_GATHER_INFO
2017-02-13Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2017-3515.nasl - Type : ACT_GATHER_INFO
2017-02-13Name : The remote OracleVM host is missing one or more security updates.
File : oraclevm_OVMSA-2017-0040.nasl - Type : ACT_GATHER_INFO
2017-02-10Name : The remote SUSE host is missing one or more security updates.
File : suse_SU-2017-0437-1.nasl - Type : ACT_GATHER_INFO
2017-02-09Name : The remote OracleVM host is missing one or more security updates.
File : oraclevm_OVMSA-2017-0039.nasl - Type : ACT_GATHER_INFO
2017-02-08Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2017-3514.nasl - Type : ACT_GATHER_INFO
2017-01-31Name : The remote SUSE host is missing one or more security updates.
File : suse_SU-2017-0333-1.nasl - Type : ACT_GATHER_INFO
2017-01-03Name : The remote Debian host is missing a security update.
File : debian_DLA-772.nasl - Type : ACT_GATHER_INFO
2016-12-12Name : The remote openSUSE host is missing a security update.
File : openSUSE-2016-1428.nasl - Type : ACT_GATHER_INFO
2016-12-12Name : The remote openSUSE host is missing a security update.
File : openSUSE-2016-1431.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
DateInformations
2017-05-27 13:25:58
  • Multiple Updates
2017-05-25 21:23:12
  • First insertion