Description: | Description:
The remote host is missing an update to kernel announced via advisory FEDORA-2008-3873.
The kernel package contains the Linux kernel (vmlinuz), the core of any Linux operating system. The kernel handles the basic functions of the operating system: memory allocation, process allocation, device input and output, etc.
Update Information:
Update to Linux kernel verion 2.6.24.6, 2.6.24.7: http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.6 http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.7
Security fixes: CVE-2008-1375 (2.6.24.6) - dnotify/close race CVE-2008-1675 (2.6.24.6) - tehuti driver permissions and register size check issues CVE-2008-1669 (2.6.24.7) - SMP ordering hole in fcntl_setlk() Wireless driver bug fixes. Fix access permissions on /proc/kcore (#241362) Re-enable machine check exception handler.
ChangeLog:
* Wed May 7 2008 Neil Horman - Return kcore access policy to upstream behavior (bz 241362)
References:
[ 1 ] Bug #439754 - CVE-2008-1375 kernel: race condition in dnotify (local DoS, local roothole possible) https://bugzilla.redhat.com/show_bug.cgi?id=439754 [ 2 ] Bug #443433 - CVE-2008-1669 kernel: add rcu_read_lock() to fcheck() in both dnotify, locks.c and fix fcntl store/load race in locks.c https://bugzilla.redhat.com/show_bug.cgi?id=443433
Solution: Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update kernel' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2008-3873
Risk factor : High
CVSS Score: 7.2
|