Revision Date: | 2013-09-24 | Version: | 636 |
Title: | RHSA-2013:1282: rtkit security update (Important) |
Description: | RealtimeKit is a D-Bus system service that changes the scheduling policy of user processes/threads to SCHED_RR (that is, realtime scheduling mode) on request. It is intended to be used as a secure mechanism to allow real-time scheduling to be used by normal user processes.
It was found that RealtimeKit communicated with PolicyKit for authorization using a D-Bus API that is vulnerable to a race condition. This could have led to intended PolicyKit authorizations being bypassed. This update modifies RealtimeKit to communicate with PolicyKit via a different API that is not vulnerable to the race condition. (CVE-2013-4326)
All rtkit users are advised to upgrade to this updated package, which contains a backported patch to correct this issue.
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | CVE-2013-4326 CVE-2013-4326 RHSA-2013:1282 RHSA-2013:1282-00 RHSA-2013:1282-01
|
Platform(s): | Red Hat Enterprise Linux 6
| Product(s): | |
Definition Synopsis |
Red Hat Enterprise Linux must be installed OR Package Information
Red Hat Enterprise Linux 6 is installed
AND rtkit is earlier than 0:0.5-2.el6_4
AND rtkit is signed with Red Hat redhatrelease2 key
|