cl_revoked list deletion causing softlock in nfsd [fs] ceph: multiple updates * (BZ#1322033) Security Fix(es): * A flaw was found in the way the Linux kernel's ASN.1 DER decoder processed certain certificate files with tags of indefinite length. A local, unprivileged user could use a specially crafted X.509 certificate DER file to crash the system or, potentially, escalate their privileges on the system. (CVE-2016-0758, Important) Red Hat would like to thank Philip Pettersson of Samsung for reporting this issue. Bug Fix(es): * The hotplug lock and the console semaphore could be acquired in an incorrect order, which could previously lead to a deadlock causing the system console to freeze. The underlying code has been adjusted to acquire the locks in the correct order, resolving the bug with the console. (BZ#1324767) "> OVAL Reference oval:com.redhat.rhsa:def:20161051 - CERT Civis.Net
Oval Definition:oval:com.redhat.rhsa:def:20161051
Revision Date:2016-05-12Version:641
Title:RHSA-2016:1051: kernel-rt security, bug fix, and enhancement update (Important)
Description:The kernel-rt packages contain the Linux kernel, the core of any Linux operating system.

The following packages have been upgraded to a newer upstream version: kernel-rt (3.10.0-327.18.2). This version provides a number of bug fixes and enhancements, including:

[scsi] bnx2fc: Fix FCP RSP residual parsing and remove explicit logouts

[scsi] mpt3sas: Fix for Asynchronous completion of timedout IO and task abort of timedout IO

[scsi] scsi_error: should not get sense for timeout IO in scsi error handler

[scsi] Revert libiscsi: Reduce locking contention in fast path

[mm] madvise: fix MADV_WILLNEED on shmem swapouts

[cpufreq] intel_pstate: decrease number of "HWP enabled" messages and enable HWP per CPU

[kernel] sched: Robustify topology setup

[kernel] sched/fair: Disable tg load_avg/runnable_avg update for root_task_group

[kernel] sched/fair: Move hot load_avg/runnable_avg into separate cacheline

[ib] mlx5: Fix RC transport send queue overhead computation

[fs] nfsd: fix clp->cl_revoked list deletion causing softlock in nfsd

[fs] ceph: multiple updates

  • (BZ#1322033)

    Security Fix(es):

  • A flaw was found in the way the Linux kernel's ASN.1 DER decoder processed certain certificate files with tags of indefinite length. A local, unprivileged user could use a specially crafted X.509 certificate DER file to crash the system or, potentially, escalate their privileges on the system. (CVE-2016-0758, Important)

    Red Hat would like to thank Philip Pettersson of Samsung for reporting this issue.

    Bug Fix(es):

  • The hotplug lock and the console semaphore could be acquired in an incorrect order, which could previously lead to a deadlock causing the system console to freeze. The underlying code has been adjusted to acquire the locks in the correct order, resolving the bug with the console. (BZ#1324767)
  • Family:unixClass:patch
    Status:Reference(s):CVE-2016-0758
    RHSA-2016:1051
    RHSA-2016:1051-00
    RHSA-2016:1051-01
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • kernel-rt earlier than 0:3.10.0-327.18.2.rt56.223.el7_2 is currently running
  • OR kernel-rt earlier than 0:3.10.0-327.18.2.rt56.223.el7_2 is set to boot up on next boot
  • AND
  • kernel-rt is earlier than 0:3.10.0-327.18.2.rt56.223.el7_2
  • AND kernel-rt is signed with Red Hat redhatrelease2 key
  • kernel-rt-debug is earlier than 0:3.10.0-327.18.2.rt56.223.el7_2
  • AND kernel-rt-debug is signed with Red Hat redhatrelease2 key
  • kernel-rt-debug-devel is earlier than 0:3.10.0-327.18.2.rt56.223.el7_2
  • AND kernel-rt-debug-devel is signed with Red Hat redhatrelease2 key
  • kernel-rt-debug-kvm is earlier than 0:3.10.0-327.18.2.rt56.223.el7_2
  • AND kernel-rt-debug-kvm is signed with Red Hat redhatrelease2 key
  • kernel-rt-devel is earlier than 0:3.10.0-327.18.2.rt56.223.el7_2
  • AND kernel-rt-devel is signed with Red Hat redhatrelease2 key
  • kernel-rt-doc is earlier than 0:3.10.0-327.18.2.rt56.223.el7_2
  • AND kernel-rt-doc is signed with Red Hat redhatrelease2 key
  • kernel-rt-kvm is earlier than 0:3.10.0-327.18.2.rt56.223.el7_2
  • AND kernel-rt-kvm is signed with Red Hat redhatrelease2 key
  • kernel-rt-trace is earlier than 0:3.10.0-327.18.2.rt56.223.el7_2
  • AND kernel-rt-trace is signed with Red Hat redhatrelease2 key
  • kernel-rt-trace-devel is earlier than 0:3.10.0-327.18.2.rt56.223.el7_2
  • AND kernel-rt-trace-devel is signed with Red Hat redhatrelease2 key
  • kernel-rt-trace-kvm is earlier than 0:3.10.0-327.18.2.rt56.223.el7_2
  • AND kernel-rt-trace-kvm is signed with Red Hat redhatrelease2 key
  • BACK