U jezgri operacijskog sustava otkriveno je nekoliko sigurnosnih propusta koje zlonamjerni korisnici mogu iskoristiti za izvođenje napada uskraćivanjem usluga (DoS napad).
Paket:
Linux kernel 3.x
Operacijski sustavi:
Fedora 16
Kritičnost:
5
Problem:
pogreška u programskoj funkciji, pogreška u programskoj komponenti
Iskorištavanje:
udaljeno
Posljedica:
uskraćivanje usluga (DoS)
Rješenje:
programska zakrpa proizvođača
CVE:
CVE-2011-4131, CVE-2011-4132, CVE-2011-4110
Izvorni ID preporuke:
FEDORA-2011-16237
Izvor:
Fedora
Problem:
Neki propusti su otkriveni u "nfs4_getfacl" i "Journaling Block Device (JBD)" komponenti.
Posljedica:
Propusti se mogu iskoristiti za izvođenje DoS (eng. Denial of Service) napada.
Rješenje:
Svim korisnicima se savjetuje korištenje nadogradnje.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-16237
2011-11-23 00:21:05
--------------------------------------------------------------------------------
Name : kernel
Product : Fedora 16
Version : 3.1.2
Release : 1.fc16
URL : http://www.kernel.org/
Summary : The Linux kernel
Description :
The kernel package contains the Linux kernel (vmlinuz), the core of any
Linux operating system. The kernel handles the basic functions
of the operating system: memory allocation, process allocation, device
input and output, etc.
--------------------------------------------------------------------------------
Update Information:
Update to kernel 3.1.2:
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.1.2
Additional changes:
- Partially fix reported stalls during heavy I/O
- Fix problems with udev probing Wacom bluetooth tablets
--------------------------------------------------------------------------------
ChangeLog:
* Tue Nov 22 2011 Chuck Ebbert <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 3.1.2-1
- Linux 3.1.2
* Sat Nov 19 2011 Chuck Ebbert <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 3.1.2-0.rc1.1
- Linux 3.1.2-rc1
* Wed Nov 16 2011 John W. Linville <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.>
- Add compat-wireless as an option for kernel build
* Tue Nov 15 2011 Dave Jones <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.>
- mm: Do not stall in synchronous compaction for THP allocations
* Tue Nov 15 2011 Dave Jones <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.>
- Backport asus-laptop changes from 3.2 (rhbz 754214)
* Mon Nov 14 2011 Josh Boyer <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.>
- Patch from Joshua Roys to add rtl8192* to modules.networking (rhbz 753645)
- Add patch for wacom tablets for Bastien Nocera (upstream 3797ef6b6)
- Add patch to fix ip6_tunnel naming (rhbz 751165)
- Quite warning in apm_cpu_idle (rhbz 753776)
* Mon Nov 14 2011 Josh Boyer <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 3.1.1-2
- CVE-2011-4131: nfs4_getfacl decoding kernel oops (rhbz 753236)
- CVE-2011-4132: jbd/jbd2: invalid value of first log block leads to oops (rhbz
753346)
* Fri Nov 11 2011 Chuck Ebbert <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.>
- Use the same naming scheme as rawhide for -stable RC kernels
(e.g. 3.1.1-0.rc1.1 instead of 3.1.1-1.rc1)
* Fri Nov 11 2011 Josh Boyer <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 3.1.1-1
- Linux 3.1.1
* Fri Nov 11 2011 John W. Linville <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.>
- Remove overlap between bcma/b43 and brcmsmac and reenable bcm4331
* Thu Nov 10 2011 Chuck Ebbert <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.>
- Sync samsung-laptop driver with what's in 3.2 (rhbz 747560)
* Wed Nov 9 2011 Chuck Ebbert <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 3.1.1-1.rc1
- Linux 3.1.1-rc1
- Comment out merged patches, will drop when release is final:
ums-realtek-driver-uses-stack-memory-for-DMA.patch
epoll-fix-spurious-lockdep-warnings.patch
crypto-register-cryptd-first.patch
add-macbookair41-keyboard.patch
powerpc-Fix-deadlock-in-icswx-code.patch
iwlagn-fix-ht_params-NULL-pointer-dereference.patch
mmc-Always-check-for-lower-base-frequency-quirk-for-.patch
media-DiBcom-protect-the-I2C-bufer-access.patch
media-dib0700-protect-the-dib0700-buffer-access.patch
WMI-properly-cleanup-devices-to-avoid-crashes.patch
mac80211-fix-remain_off_channel-regression.patch
mac80211-config-hw-when-going-back-on-channel.patch
* Wed Nov 9 2011 John W. Linville <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.>
- Backport brcm80211 from 3.2-rc1
* Tue Nov 8 2011 Neil Horman <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.>
- Add msi irq ennumeration per device in sysfs (rhbz 752176)
* Mon Nov 7 2011 Josh Boyer <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.>
- Add two patches to fix mac80211 issues (rhbz 731365)
* Thu Nov 3 2011 Josh Boyer <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.>
- Add commits queued for 3.2 for elantech driver (rhbz 728607)
- Fix crash when setting brightness via Fn keys on ideapads (rhbz 748210)
* Wed Nov 2 2011 Josh Boyer <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.>
- Add patch to fix oops when removing wmi module (rhbz 706574)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #754214 - Backport Pegatron Lucid support for asus-laptop to Fedora
16 kernel (ExoPC, WeTab)
https://bugzilla.redhat.com/show_bug.cgi?id=754214
[ 2 ] Bug #753645 - Missing realtek drivers in modules.networking
https://bugzilla.redhat.com/show_bug.cgi?id=753645
[ 3 ] Bug #751165 - Tunnel Add problem in Fedora 15 since 2.6.40
https://bugzilla.redhat.com/show_bug.cgi?id=751165
[ 4 ] Bug #753776 - [abrt] kernel: WARNING: at arch/x86/kernel/apm_32.c:908
apm_cpu_idle+0x42/0x251()
https://bugzilla.redhat.com/show_bug.cgi?id=753776
[ 5 ] Bug #756169 - CVE-2011-4110 kernel: keys: NULL pointer deref in the
user-defined key type [f-16]
https://bugzilla.redhat.com/show_bug.cgi?id=756169
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update kernel' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke