Oval Definition:oval:com.redhat.rhsa:def:20131282
Revision Date:2013-09-24Version:636
Title:RHSA-2013:1282: rtkit security update (Important)
Description:RealtimeKit is a D-Bus system service that changes the scheduling policy of user processes/threads to SCHED_RR (that is, realtime scheduling mode) on request. It is intended to be used as a secure mechanism to allow real-time scheduling to be used by normal user processes.

  • It was found that RealtimeKit communicated with PolicyKit for authorization using a D-Bus API that is vulnerable to a race condition. This could have led to intended PolicyKit authorizations being bypassed. This update modifies RealtimeKit to communicate with PolicyKit via a different API that is not vulnerable to the race condition. (CVE-2013-4326)

    All rtkit users are advised to upgrade to this updated package, which contains a backported patch to correct this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2013-4326
    CVE-2013-4326
    RHSA-2013:1282
    RHSA-2013:1282-00
    RHSA-2013:1282-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND rtkit is earlier than 0:0.5-2.el6_4
  • AND rtkit is signed with Red Hat redhatrelease2 key
  • BACK