[Ksplice][RHEL 5 Updates] New updates available via Ksplice (RHSA-2010:0178-02)
Nelson Elhage
nelhage at ksplice.com
Wed Mar 31 13:45:45 PDT 2010
Synopsis: RHSA-2010:0178-02 can now be patched using Ksplice
CVEs: CVE-2009-4307 CVE-2010-0727
Red Hat Security Advisory Severity: Important
Systems running Red Hat Enterprise Linux 5 and CentOS 5 can now use
Ksplice to patch against the latest Red Hat Security Advisory,
RHSA-2010:0178-02.
INSTALLING THE UPDATES
We recommend that all Ksplice Uptrack RHEL 5 and CentOS 5 users
install these updates. You can install these updates by running:
# uptrack-upgrade -y
DESCRIPTION
* CVE-2009-4307: Divide-by-zero mounting an ext4 filesystem.
A divide-by-zero flaw was found in the ext4 file system code. A local
attacker could use this flaw to cause a denial of service by mounting
a specially-crafted ext4 file system. (CVE-2009-4307, Low)
* CVE-2010-0727: Denial of Service in GFS2 locking.
A flaw was found in the gfs2_lock() implementation. The GFS2 locking
code could skip the lock operation for files that have the S_ISGID bit
(set-group-ID on execution) in their mode set. A local, unprivileged
user on a system that has a GFS2 file system mounted could use this
flaw to cause a kernel panic. (CVE-2010-0727, Moderate)
SUPPORT
Ksplice support is available at support at ksplice.com or +1 765-577-5423.
More information about the Ksplice-EL5-Updates
mailing list