kernel-2.6.18-53.21AXS3

エラータID: AXSA:2009-22:03

Release date: 
Monday, March 16, 2009 - 13:45
Subject: 
kernel-2.6.18-53.21AXS3
Affected Channels: 
Asianux Server 3 for x86_64
Asianux Server 3 for x86
Severity: 
High
Description: 

The kernel package contains the Linux kernel (vmlinuz), the core of any Linux operating system. The kernel handles the basic functions of the operating system: memory allocation, process allocation, device input and output, etc.
Bugs fixed:
CVE-2008-5029
The __scm_destroy function in net/core/scm.c in the Linux kernel 2.6.27.4, 2.6.26, and earlier makes indirect recursive calls to itself through calls to the fput function, which allows local users to cause a denial of service (panic) via vectors related to sending an SCM_RIGHTS message through a UNIX domain socket and closing file descriptors.
CVE-2008-5079
net/atm/svc.c in the ATM subsystem in the Linux kernel 2.6.27.8 and earlier allows local users to cause a denial of service (kernel infinite loop) by making two calls to svc_listen for the same socket, and then reading a /proc/net/atm/*vc file, related to corruption of the vcc table.
CVE-2008-5182
The inotify functionality in Linux kernel 2.6 before 2.6.28-rc5 might allow local users to gain privileges via unknown vectors related to race conditions in inotify watch removal and umount.
CVE-2008-4933
Buffer overflow in the hfsplus_find_cat function in fs/hfsplus/catalog.c in the Linux kernel before 2.6.28-rc1 allows attackers to cause a denial of service (memory corruption or system crash) via an hfsplus filesystem image with an invalid catalog namelength field, related to the hfsplus_cat_build_key_uni function.
CVE-2008-4934
The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the read_mapping_page function before calling kmap, which allows attackers to cause a denial of service (system crash) via a crafted hfsplus filesystem image.
CVE-2008-5025
Stack-based buffer overflow in the hfs_cat_find_brec function in fs/hfs/catalog.c in the Linux kernel before 2.6.28-rc1 allows attackers to cause a denial of service (memory corruption or system crash) via an hfs filesystem image with an invalid catalog namelength field, a related issue to CVE-2008-4933.
CVE-2008-5713
The __qdisc_run function in net/sched/sch_generic.c in the Linux kernel before 2.6.25 on SMP machines allows local users to cause a denial of service (soft lockup) by sending a large amount of network traffic, as demonstrated by multiple simultaneous invocations of the Netperf benchmark application in UDP_STREAM mode.
CVE-2009-0031
Memory leak in the keyctl_join_session_keyring function (security/keys/keyctl.c) in Linux kernel 2.6.29-rc2 and earlier allows local users to cause a denial of service (kernel memory consumption) via unknown vectors related to a missing kfree.
CVE-2009-0065
Buffer overflow in net/sctp/sm_statefuns.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.28-git8 allows remote attackers to have an unknown impact via an FWD-TSN (aka FORWARD-TSN) chunk with a large stream ID.
Other bugs:
[IPv6] Fix source address/interface selection.
When bonding two e1000 NIC(eth0, eth1) into one bonding device (bond0) and using the command ping6 -I specifying bond0 global address, the ping6 packet is sent as from eth0 and bond0 does not receive the reply packet.
VLAN devices 'features' were not set adequately, resulting in possible performance loss (seen on NIC e1000 with TSO capability)
Support for Nehalem-EP C6 state (power saving feature).

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. kernel-2.6.18-53.21AXS3.src.rpm
    MD5: 269b8c0f872a1661aae9471839f4b451
    SHA-256: 5d1b4c5791dfdee282f16825569c12141e9ab67b19e4e1889ecfa1b87294947d
    Size: 54.86 MB

Asianux Server 3 for x86
  1. kernel-2.6.18-53.21AXS3.i686.rpm
    MD5: a2db75afbcfa8b8512994e4a922380dd
    SHA-256: 071603ee8079b60cb8b6d397943e12d442972563822e758e4ede18168df9f831
    Size: 13.66 MB
  2. kernel-devel-2.6.18-53.21AXS3.i686.rpm
    MD5: efdd0918910631e6316e46cd092dca69
    SHA-256: 1b3a15c760d79406bb6fce5f2d592d6f8ff8778ae3490962c24316941ff0fb3f
    Size: 4.87 MB
  3. kernel-PAE-2.6.18-53.21AXS3.i686.rpm
    MD5: 4a1b6328b76061564d91924361503807
    SHA-256: 54c95589ec525b0fdbfee15db55b15d0f6ff5583d5c65afd01d07b51517955c1
    Size: 13.67 MB
  4. kernel-PAE-devel-2.6.18-53.21AXS3.i686.rpm
    MD5: 1fb44354fd9e9aa3c73153c05296e2bd
    SHA-256: c00d30c3fde236d04adac811135a7308e0eda9ddee3de480cf4f31beae924916
    Size: 4.89 MB
  5. kernel-xen-2.6.18-53.21AXS3.i686.rpm
    MD5: 4e34fe30037d998efc4d688a38653cc8
    SHA-256: 2ad51449fe18000afce6b281d4f0fc01eb53e12a4a80702a3c2e17fe1dce57c5
    Size: 14.62 MB
  6. kernel-xen-devel-2.6.18-53.21AXS3.i686.rpm
    MD5: 3cd43d72e1ad2eeb3bd03d9f2bb00d41
    SHA-256: 58b161c351b4d23898dd0033a32a9d12e06a24bff9515a73b24e0b9de3854a16
    Size: 4.88 MB
  7. kernel-doc-2.6.18-53.21AXS3.noarch.rpm
    MD5: 224b09a522b4beb9412e81a5e9e90958
    SHA-256: ff2006949a0fa4931a7c7dd3f999c3456b164fcb2745195f4787c96889d0bc54
    Size: 2.82 MB
  8. kernel-headers-2.6.18-53.21AXS3.i386.rpm
    MD5: 44e182b5298343b7e7f3b008197b674b
    SHA-256: 73ef002918417a4e36735cc58548dd0923b639e0e456732d6a506f2946e4713c
    Size: 806.29 kB

Asianux Server 3 for x86_64
  1. kernel-2.6.18-53.21AXS3.x86_64.rpm
    MD5: 9478068e3a15fb0620cd753f048bd752
    SHA-256: 8021a59abbc13a8aaf40f0cc22301c1da2e92804e3d3888ba8611125d67a91d7
    Size: 15.84 MB
  2. kernel-devel-2.6.18-53.21AXS3.x86_64.rpm
    MD5: 2b1794ae96b0ca83a9327cba2224c69e
    SHA-256: ce9c5b8f7837a66ea32ebf4d737d386a129038033462c4a51b82ddc96804823e
    Size: 5.06 MB
  3. kernel-headers-2.6.18-53.21AXS3.x86_64.rpm
    MD5: 9b984adc5fe18a3f3e3cb7cc8979de50
    SHA-256: 1c48c5fffaa995b02ce162921e9d29bf859ca76933263bb7b998f9a1a6c25f91
    Size: 844.49 kB
  4. kernel-xen-2.6.18-53.21AXS3.x86_64.rpm
    MD5: 32706de6319e260b744c7341cb896884
    SHA-256: 923068ad437a08425346cec1a228dcb485ed8191b3eab261981535d17286aa98
    Size: 16.50 MB
  5. kernel-xen-devel-2.6.18-53.21AXS3.x86_64.rpm
    MD5: 258b1623465153e19885849b953417bb
    SHA-256: 590dc87deb4b0b29bd4d2d49305e98da21169833c37f1092481159f4ee7d45c9
    Size: 5.06 MB
  6. kernel-doc-2.6.18-53.21AXS3.noarch.rpm
    MD5: e31d7ba3c5bb3aa4d1f548e5044ea576
    SHA-256: 7346e7d76e4ad9fbc6842e266f0b5975a45e983cefd051a30d366a4fc3ccd0da
    Size: 2.82 MB