kernel-2.6.32-504.3.3.el6
エラータID: AXSA:2015-004:01
Description :
The kernel package contains the Linux kernel (vmlinuz), the core of any
Linux operating system. The kernel handles the basic functions
of the operating system: memory allocation, process allocation, device
input and output, etc.
Security issues fixed with this release:
CVE-2012-6657
The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system crash) by leveraging the ability to create a raw socket.
CVE-2014-3673
The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF chunk, related to net/sctp/sm_make_chunk.c and net/sctp/sm_statefuns.c.
CVE-2014-3687
The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (panic) via duplicate ASCONF chunks that trigger an incorrect uncork within the side-effect interpreter.
CVE-2014-3688
The SCTP implementation in the Linux kernel before 3.17.4 allows remote attackers to cause a denial of service (memory consumption) by triggering a large number of chunks in an association's output queue, as demonstrated by ASCONF probes, related to net/sctp/inqueue.c and net/sctp/sm_statefuns.c.
CVE-2014-5471
Stack consumption vulnerability in the parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (uncontrolled recursion, and system crash or reboot) via a crafted iso9660 image with a CL entry referring to a directory entry that has a CL entry.
CVE-2014-5472
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (unkillable mount process) via a crafted iso9660 image with a self-referential CL entry.
CVE-2014-6410
The __udf_read_inode function in fs/udf/inode.c in the Linux kernel through 3.16.3 does not restrict the amount of ICB indirection, which allows physically proximate attackers to cause a denial of service (infinite loop or stack consumption) via a UDF filesystem with a crafted inode.
CVE-2014-9322
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to a GS Base address from the wrong space.
Fixed bugs:
* This update fixes a race condition issue between the sock_queue_err_skb function and sk_forward_alloc handling in the socket error queue (MSG_ERRQUEUE), which could occasionally cause the kernel, for example when using PTP, to incorrectly track allocated memory for the error queue, in which case a traceback would occur in the system log.
* The zcrypt device driver did not detect certain crypto cards and the related domains for crypto adapters on System z and s390x architectures. So, it was not possible to run the system on new crypto hardware. With this update, fixed it.
* After mounting and unmounting an XFS file system several times consecutively, the umount command occasionally became unresponsive. This was caused by the xlog_cil_force_lsn() function that was not waiting for completion as expected. With this update, xlog_cil_force_lsn() has been modified to correctly wait for completion, With this update, fixed it.
* When using the ixgbe adapter with disabled LRO and the tx-usec or rs-usec variables set to 0, transmit interrupts could not be set lower than the default of 8 buffered tx frames. So, a delay of TCP transfer occurred. The restriction of a minimum of 8 buffered frames has been removed, and the TCP delay no longer occurs.
* The offb driver has been updated for the QEMU standard VGA adapter, fixing an incorrect displaying of colors issue.
* Under certain circumstances, when a discovered MTU expired, the IPv6 connection became unavailable for a short period of time. With this update, fixed it.
* A low throughput occurred when using the dm-thin driver to write to unprovisioned or shared chunks for a thin pool with the chunk size bigger than the max_sectors_kb variable.
* Large write workloads on thin LVs could cause the iozone and smallfile utilities to terminate unexpectedly.
Update package.
N/A
SRPMS
- kernel-2.6.32-504.3.3.el6.src.rpm
MD5: abdab4238d5a2f033a119d97eb88edb9
SHA-256: a002e3fc7a627e65c58cfc6c91b3273f086f76bbaabb1af313f40792172b77e6
Size: 94.77 MB
Asianux Server 4 for x86
- kernel-2.6.32-504.3.3.el6.i686.rpm
MD5: 6393d66151b25e40c7317beeda139e6d
SHA-256: ad9ef00058b7846b1e13a7ee6e6c1f2fde8d507ce71d10dc7d64b30b6d8ed18b
Size: 26.91 MB - kernel-abi-whitelists-2.6.32-504.3.3.el6.noarch.rpm
MD5: d54ea9d04e918d96b81d824f365288eb
SHA-256: e18f7b56927cd6e7827f2beba8b0179cd4b1ec3a74ce8d4a54869668519eade4
Size: 2.64 MB - kernel-debug-2.6.32-504.3.3.el6.i686.rpm
MD5: f9d04154beac48b60d81caaba39bb0f0
SHA-256: 0676567e35291b83bb30548b9f416c77d47a71f47cdcd8d1486a642d077b55f4
Size: 27.51 MB - kernel-debug-devel-2.6.32-504.3.3.el6.i686.rpm
MD5: fef009f4a1e8da30e0cc635aa6f0b40e
SHA-256: 1dc8752810c19c36d421eeb3fe0096936d72f8ca52301083e750a1bc2d7a406b
Size: 9.35 MB - kernel-devel-2.6.32-504.3.3.el6.i686.rpm
MD5: 505bdced78f1a8463b6d02ab589dd791
SHA-256: 412a96a2631cc29bede9727c0d36ce208873342a13b88066001fea79fbc8187c
Size: 9.31 MB - kernel-doc-2.6.32-504.3.3.el6.noarch.rpm
MD5: 651194fcfdaa2bdd2e0a5003a23b9342
SHA-256: fcc2ed1b526499696ca43d64de2129f303b2ecb0624851a66abe128a0d324fd1
Size: 11.13 MB - kernel-firmware-2.6.32-504.3.3.el6.noarch.rpm
MD5: be11deda698dcd832ad7283bbb1d1818
SHA-256: 1ab7e16358286f2729338ac111c7dd74b349b5fa155933d0cd9d2702b1df2962
Size: 14.43 MB - kernel-headers-2.6.32-504.3.3.el6.i686.rpm
MD5: f0ecc13b00d38a7c065026069d577497
SHA-256: aa293c9ba1e959bc8924ac94c90a3e6a9a9c904bb1e3a27f6a911bae25183a3c
Size: 3.34 MB - perf-2.6.32-504.3.3.el6.i686.rpm
MD5: 8ff4036cec72442a1eee7e0a626039c0
SHA-256: 8236030dfdfe7135f7a969ef2dcf399b89f1c561ae440cc77ef1b75ea4eb4d12
Size: 3.45 MB
Asianux Server 4 for x86_64
- kernel-2.6.32-504.3.3.el6.x86_64.rpm
MD5: 06746866f1b53b9e9d4e484bfeeed17c
SHA-256: b3226eed5e05c662a362835d5ed9e017fd3445d5257e6b711721068fe245dada
Size: 29.09 MB - kernel-abi-whitelists-2.6.32-504.3.3.el6.noarch.rpm
MD5: 76503bd766ba4dd8d5c3b54d4c112210
SHA-256: 102ee9239105f011381f980b3cbee401cf8887e0b5d1376161ffc4946dac07df
Size: 2.64 MB - kernel-debug-2.6.32-504.3.3.el6.x86_64.rpm
MD5: 2f33cdd3787d7ee77a5746a7d6f13073
SHA-256: 35e0d83f0539e7246d20cfc36951c19f270022fc09afddbc217e64c1a2be56d1
Size: 29.78 MB - kernel-debug-devel-2.6.32-504.3.3.el6.x86_64.rpm
MD5: cec15e0d56532f29e5ca8372528330cb
SHA-256: 6142d842b9558ba1ce6979b90f1aa836c2ba53ab17ed3b940b1712e6e7bed5cb
Size: 9.40 MB - kernel-devel-2.6.32-504.3.3.el6.x86_64.rpm
MD5: 0af50c2a168eef605f3fe1e859241a56
SHA-256: aa0229169f387ccb25fb2f9837266bb14d5b2aaa800bdb6e2d3b744305bd8a9f
Size: 9.36 MB - kernel-doc-2.6.32-504.3.3.el6.noarch.rpm
MD5: a08bd4c10c4a34ab710ed148360ce0e2
SHA-256: 704993cec681fd38e32e73e0e68cc532967bae1d0a37df8e39eae1c0cf160424
Size: 11.13 MB - kernel-firmware-2.6.32-504.3.3.el6.noarch.rpm
MD5: 66529476c17e35dbcb069b186f4f9f26
SHA-256: 778545ce125faa89c703d07ced3eb1d28943c87639d5a26da27193901c427ab8
Size: 14.43 MB - kernel-headers-2.6.32-504.3.3.el6.x86_64.rpm
MD5: e91b6cbf9904af4d6213d36daf31c151
SHA-256: c03a1c06f32169c88618076951a1855bd118aed106ac1144f41ce36b5b0b743e
Size: 3.34 MB - perf-2.6.32-504.3.3.el6.x86_64.rpm
MD5: 84149f8ddb2d50eae894931de33ee5db
SHA-256: 50e1f774657b0e7b8260557badea7896db7ecf04b70a0a33e3b6ceb6abf910a4
Size: 3.42 MB