Skip to content

Security Advisory Moderate: kernel security and bug fix update

アップデートID:

RHSA-2008:0167-8

タイプ:Security Advisory
重大性:Moderate
発行日:2008年3月14日
最終更新日:2008年3月14日
影響のある製品: Red Hat Desktop (v. 4)
Red Hat Enterprise Linux AS (v. 4)
Red Hat Enterprise Linux ES (v. 4)
Red Hat Enterprise Linux WS (v. 4)
OVAL: https://rhn.redhat.com/errata/RHSA-2008-0167.html
CVEs (cve.mitre.org): CVE-2007-5904


詳細

Updated kernel packages that fix various security issues and several bugs
are now available for Red Hat Enterprise Linux 4.

This update has been rated as having moderate security impact by the Red
Hat Security Response Team.

The kernel packages contain the Linux kernel, the core of any Linux
operating system.

A buffer overflow flaw was found in the CIFS virtual file system. A
remote authenticated user could issue a request that could lead to
a denial of service. (CVE-2007-5904, Moderate)

As well, these updated packages fix the following bugs:

* a bug was found in the Linux kernel audit subsystem. When the audit
daemon was setup to log the execve system call with a large number
of arguments, the kernel could run out out memory while attempting to
create audit log messages. This could cause a kernel panic. In these
updated packages, large audit messages are split into acceptable sizes,
which resolves this issue.

* on certain Intel chipsets, it was not possible to load the acpiphp
module using the "modprobe acpiphp" command. Because the acpiphp module
did not recurse across PCI bridges, hardware detection for PCI hot plug
slots failed. In these updated packages, hardware detection works
correctly.

* on IBM System z architectures that run the IBM z/VM hypervisor, the IBM
eServer zSeries HiperSockets network interface (layer 3) allowed ARP
packets to be sent and received, even when the "NOARP" flag was set. These
ARP packets caused problems for virtual machines.

* it was possible for the iounmap function to sleep while holding a lock.
This may have caused a deadlock for drivers and other code that uses the
iounmap function. In these updated packages, the lock is dropped before
the sleep code is called, which resolves this issue.

Red Hat Enterprise Linux 4 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.


解決法


このアップデートを適用する前に、ご使用のシステムに関係するリリース済みのエラータ/Errataがすべて適用されていることを確認してください。

このアップデートは、Red Hat Networkを通じて入手できます。


アップデートパッケージ

Red Hat Desktop (v. 4)

SRPMS:
kernel-2.6.9-67.0.7.EL.src.rpm     b109f8ecc113fd041cf6e76438347754
 
IA-32:
kernel-2.6.9-67.0.7.EL.i686.rpm     a982f8024376a157ac8e9a6e77e5bff7
kernel-devel-2.6.9-67.0.7.EL.i686.rpm     ec31f2844c5e511c7ed9268b51ae6c7f
kernel-doc-2.6.9-67.0.7.EL.noarch.rpm     8842b9ab5a860f0d9e088f78d659aff4
kernel-hugemem-2.6.9-67.0.7.EL.i686.rpm     f13b9b3d0a95d3f6cab4653396115369
kernel-hugemem-devel-2.6.9-67.0.7.EL.i686.rpm     07676769223a62e6fe3c7f2ed2a7e64f
kernel-smp-2.6.9-67.0.7.EL.i686.rpm     727acc31385d330e42887f4c0b752439
kernel-smp-devel-2.6.9-67.0.7.EL.i686.rpm     f9bc18136e44f8208a14c3c5262a0a8e
kernel-xenU-2.6.9-67.0.7.EL.i686.rpm     15b93afb6fa1a95966f2638186f92d96
kernel-xenU-devel-2.6.9-67.0.7.EL.i686.rpm     7084e16776d693b9fe468ac05143bcf8
 
x86_64:
kernel-2.6.9-67.0.7.EL.x86_64.rpm     6fcf89df6ad98bb00a7a89148f46a14e
kernel-devel-2.6.9-67.0.7.EL.x86_64.rpm     a6e0b6176e8f135a305a34761bebdf38
kernel-doc-2.6.9-67.0.7.EL.noarch.rpm     8842b9ab5a860f0d9e088f78d659aff4
kernel-largesmp-2.6.9-67.0.7.EL.x86_64.rpm     3f034687e075f8e84bb9443abfdbafff
kernel-largesmp-devel-2.6.9-67.0.7.EL.x86_64.rpm     e86f4625bd2675d603a91133e033a517
kernel-smp-2.6.9-67.0.7.EL.x86_64.rpm     1bd60a80abbf7c73384b099c2749c98c
kernel-smp-devel-2.6.9-67.0.7.EL.x86_64.rpm     0c16db6e964cffb5673ac02ba5dcfa37
kernel-xenU-2.6.9-67.0.7.EL.x86_64.rpm     ac61a5f8026150f31a73b4c6a49f4c17
kernel-xenU-devel-2.6.9-67.0.7.EL.x86_64.rpm     4c82f254493026b17164d68bfd559edf
 
Red Hat Enterprise Linux AS (v. 4)

SRPMS:
kernel-2.6.9-67.0.7.EL.src.rpm     b109f8ecc113fd041cf6e76438347754
 
IA-32:
kernel-2.6.9-67.0.7.EL.i686.rpm     a982f8024376a157ac8e9a6e77e5bff7
kernel-devel-2.6.9-67.0.7.EL.i686.rpm     ec31f2844c5e511c7ed9268b51ae6c7f
kernel-doc-2.6.9-67.0.7.EL.noarch.rpm     8842b9ab5a860f0d9e088f78d659aff4
kernel-hugemem-2.6.9-67.0.7.EL.i686.rpm     f13b9b3d0a95d3f6cab4653396115369
kernel-hugemem-devel-2.6.9-67.0.7.EL.i686.rpm     07676769223a62e6fe3c7f2ed2a7e64f
kernel-smp-2.6.9-67.0.7.EL.i686.rpm     727acc31385d330e42887f4c0b752439
kernel-smp-devel-2.6.9-67.0.7.EL.i686.rpm     f9bc18136e44f8208a14c3c5262a0a8e
kernel-xenU-2.6.9-67.0.7.EL.i686.rpm     15b93afb6fa1a95966f2638186f92d96
kernel-xenU-devel-2.6.9-67.0.7.EL.i686.rpm     7084e16776d693b9fe468ac05143bcf8
 
IA-64:
kernel-2.6.9-67.0.7.EL.ia64.rpm     74b2eea2490ac03788bd181a774dfc36
kernel-devel-2.6.9-67.0.7.EL.ia64.rpm     d739569eeab5cff10c13bb72180a5f60
kernel-doc-2.6.9-67.0.7.EL.noarch.rpm     8842b9ab5a860f0d9e088f78d659aff4
kernel-largesmp-2.6.9-67.0.7.EL.ia64.rpm     c64a4f9a0ad31babf2beb441eab50cce
kernel-largesmp-devel-2.6.9-67.0.7.EL.ia64.rpm     168ee1ca528bca2d43e58d641b78d887
 
PPC:
kernel-2.6.9-67.0.7.EL.ppc64.rpm     acae38ccf70d67c282efcc9b4521cdea
kernel-2.6.9-67.0.7.EL.ppc64iseries.rpm     22b1f35394d791c3114185b508b87d68
kernel-devel-2.6.9-67.0.7.EL.ppc64.rpm     26e3a7f5e78e3cf0221ff48b7bac188b
kernel-devel-2.6.9-67.0.7.EL.ppc64iseries.rpm     efe3cbd1c262658472d4ca4b3b5f1e61
kernel-doc-2.6.9-67.0.7.EL.noarch.rpm     8842b9ab5a860f0d9e088f78d659aff4
kernel-largesmp-2.6.9-67.0.7.EL.ppc64.rpm     2e3f3307b083ca5e645673473e992ffc
kernel-largesmp-devel-2.6.9-67.0.7.EL.ppc64.rpm     94e070123e3355b79594466f8a94a468
 
s390:
kernel-2.6.9-67.0.7.EL.s390.rpm     d394903caff335fe641aff57d8d3b9cd
kernel-devel-2.6.9-67.0.7.EL.s390.rpm     ce0625875e4e3db74b8a38a8be752b7c
kernel-doc-2.6.9-67.0.7.EL.noarch.rpm     8842b9ab5a860f0d9e088f78d659aff4
 
s390x:
kernel-2.6.9-67.0.7.EL.s390x.rpm     f0922cda6b48d57df510098ec5fc131c
kernel-devel-2.6.9-67.0.7.EL.s390x.rpm     3292417c9d478a8dd54c8760ded68aad
kernel-doc-2.6.9-67.0.7.EL.noarch.rpm     8842b9ab5a860f0d9e088f78d659aff4
 
x86_64:
kernel-2.6.9-67.0.7.EL.x86_64.rpm     6fcf89df6ad98bb00a7a89148f46a14e
kernel-devel-2.6.9-67.0.7.EL.x86_64.rpm     a6e0b6176e8f135a305a34761bebdf38
kernel-doc-2.6.9-67.0.7.EL.noarch.rpm     8842b9ab5a860f0d9e088f78d659aff4
kernel-largesmp-2.6.9-67.0.7.EL.x86_64.rpm     3f034687e075f8e84bb9443abfdbafff
kernel-largesmp-devel-2.6.9-67.0.7.EL.x86_64.rpm     e86f4625bd2675d603a91133e033a517
kernel-smp-2.6.9-67.0.7.EL.x86_64.rpm     1bd60a80abbf7c73384b099c2749c98c
kernel-smp-devel-2.6.9-67.0.7.EL.x86_64.rpm     0c16db6e964cffb5673ac02ba5dcfa37
kernel-xenU-2.6.9-67.0.7.EL.x86_64.rpm     ac61a5f8026150f31a73b4c6a49f4c17
kernel-xenU-devel-2.6.9-67.0.7.EL.x86_64.rpm     4c82f254493026b17164d68bfd559edf
 
Red Hat Enterprise Linux ES (v. 4)

SRPMS:
kernel-2.6.9-67.0.7.EL.src.rpm     b109f8ecc113fd041cf6e76438347754
 
IA-32:
kernel-2.6.9-67.0.7.EL.i686.rpm     a982f8024376a157ac8e9a6e77e5bff7
kernel-devel-2.6.9-67.0.7.EL.i686.rpm     ec31f2844c5e511c7ed9268b51ae6c7f
kernel-doc-2.6.9-67.0.7.EL.noarch.rpm     8842b9ab5a860f0d9e088f78d659aff4
kernel-hugemem-2.6.9-67.0.7.EL.i686.rpm     f13b9b3d0a95d3f6cab4653396115369
kernel-hugemem-devel-2.6.9-67.0.7.EL.i686.rpm     07676769223a62e6fe3c7f2ed2a7e64f
kernel-smp-2.6.9-67.0.7.EL.i686.rpm     727acc31385d330e42887f4c0b752439
kernel-smp-devel-2.6.9-67.0.7.EL.i686.rpm     f9bc18136e44f8208a14c3c5262a0a8e
kernel-xenU-2.6.9-67.0.7.EL.i686.rpm     15b93afb6fa1a95966f2638186f92d96
kernel-xenU-devel-2.6.9-67.0.7.EL.i686.rpm     7084e16776d693b9fe468ac05143bcf8
 
IA-64:
kernel-2.6.9-67.0.7.EL.ia64.rpm     74b2eea2490ac03788bd181a774dfc36
kernel-devel-2.6.9-67.0.7.EL.ia64.rpm     d739569eeab5cff10c13bb72180a5f60
kernel-doc-2.6.9-67.0.7.EL.noarch.rpm     8842b9ab5a860f0d9e088f78d659aff4
kernel-largesmp-2.6.9-67.0.7.EL.ia64.rpm     c64a4f9a0ad31babf2beb441eab50cce
kernel-largesmp-devel-2.6.9-67.0.7.EL.ia64.rpm     168ee1ca528bca2d43e58d641b78d887
 
x86_64:
kernel-2.6.9-67.0.7.EL.x86_64.rpm     6fcf89df6ad98bb00a7a89148f46a14e
kernel-devel-2.6.9-67.0.7.EL.x86_64.rpm     a6e0b6176e8f135a305a34761bebdf38
kernel-doc-2.6.9-67.0.7.EL.noarch.rpm     8842b9ab5a860f0d9e088f78d659aff4
kernel-largesmp-2.6.9-67.0.7.EL.x86_64.rpm     3f034687e075f8e84bb9443abfdbafff
kernel-largesmp-devel-2.6.9-67.0.7.EL.x86_64.rpm     e86f4625bd2675d603a91133e033a517
kernel-smp-2.6.9-67.0.7.EL.x86_64.rpm     1bd60a80abbf7c73384b099c2749c98c
kernel-smp-devel-2.6.9-67.0.7.EL.x86_64.rpm     0c16db6e964cffb5673ac02ba5dcfa37
kernel-xenU-2.6.9-67.0.7.EL.x86_64.rpm     ac61a5f8026150f31a73b4c6a49f4c17
kernel-xenU-devel-2.6.9-67.0.7.EL.x86_64.rpm     4c82f254493026b17164d68bfd559edf
 
Red Hat Enterprise Linux WS (v. 4)

SRPMS:
kernel-2.6.9-67.0.7.EL.src.rpm     b109f8ecc113fd041cf6e76438347754
 
IA-32:
kernel-2.6.9-67.0.7.EL.i686.rpm     a982f8024376a157ac8e9a6e77e5bff7
kernel-devel-2.6.9-67.0.7.EL.i686.rpm     ec31f2844c5e511c7ed9268b51ae6c7f
kernel-doc-2.6.9-67.0.7.EL.noarch.rpm     8842b9ab5a860f0d9e088f78d659aff4
kernel-hugemem-2.6.9-67.0.7.EL.i686.rpm     f13b9b3d0a95d3f6cab4653396115369
kernel-hugemem-devel-2.6.9-67.0.7.EL.i686.rpm     07676769223a62e6fe3c7f2ed2a7e64f
kernel-smp-2.6.9-67.0.7.EL.i686.rpm     727acc31385d330e42887f4c0b752439
kernel-smp-devel-2.6.9-67.0.7.EL.i686.rpm     f9bc18136e44f8208a14c3c5262a0a8e
kernel-xenU-2.6.9-67.0.7.EL.i686.rpm     15b93afb6fa1a95966f2638186f92d96
kernel-xenU-devel-2.6.9-67.0.7.EL.i686.rpm     7084e16776d693b9fe468ac05143bcf8
 
IA-64:
kernel-2.6.9-67.0.7.EL.ia64.rpm     74b2eea2490ac03788bd181a774dfc36
kernel-devel-2.6.9-67.0.7.EL.ia64.rpm     d739569eeab5cff10c13bb72180a5f60
kernel-doc-2.6.9-67.0.7.EL.noarch.rpm     8842b9ab5a860f0d9e088f78d659aff4
kernel-largesmp-2.6.9-67.0.7.EL.ia64.rpm     c64a4f9a0ad31babf2beb441eab50cce
kernel-largesmp-devel-2.6.9-67.0.7.EL.ia64.rpm     168ee1ca528bca2d43e58d641b78d887
 
x86_64:
kernel-2.6.9-67.0.7.EL.x86_64.rpm     6fcf89df6ad98bb00a7a89148f46a14e
kernel-devel-2.6.9-67.0.7.EL.x86_64.rpm     a6e0b6176e8f135a305a34761bebdf38
kernel-doc-2.6.9-67.0.7.EL.noarch.rpm     8842b9ab5a860f0d9e088f78d659aff4
kernel-largesmp-2.6.9-67.0.7.EL.x86_64.rpm     3f034687e075f8e84bb9443abfdbafff
kernel-largesmp-devel-2.6.9-67.0.7.EL.x86_64.rpm     e86f4625bd2675d603a91133e033a517
kernel-smp-2.6.9-67.0.7.EL.x86_64.rpm     1bd60a80abbf7c73384b099c2749c98c
kernel-smp-devel-2.6.9-67.0.7.EL.x86_64.rpm     0c16db6e964cffb5673ac02ba5dcfa37
kernel-xenU-2.6.9-67.0.7.EL.x86_64.rpm     ac61a5f8026150f31a73b4c6a49f4c17
kernel-xenU-devel-2.6.9-67.0.7.EL.x86_64.rpm     4c82f254493026b17164d68bfd559edf
 
(The unlinked packages above are only available from the Red Hat Network)


バグフィックス (詳細は、bugzilla/バグジラ[英語]を御覧ください。)

372701 - CVE-2007-5904 Buffer overflow in CIFS VFS
427393 - audit: Logging execve arguments, out of memory in audit_expand
428174 - ACPIPHP.ko will not load : RHEL4.x and RHEL5.0 on X8450 (Intel 4 socket Quad Core) but will load on RHEL5.1
430670 - LTC39262-qeth: HiperSockets layer-3 interface to drop non-IP packets
433267 - [Stratus 4.6.z bug] iounmap may sleep while holding vmlist_lock, causing a deadlock.


参照





ここに在るパッケージはセキュリティの為、Red Hat, Inc. によって、GPG認証されています。
認証キー及び詳細は以下を御覧下さい。
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/