Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:
Category:Red Hat Local Security Checks
Title:RedHat Update for kernel RHSA-2012:1540-01
Summary:The remote host is missing an update for the 'kernel'; package(s) announced via the referenced advisory.
The remote host is missing an update for the 'kernel'
package(s) announced via the referenced advisory.

Vulnerability Insight:
These packages contain the Linux kernel.

Security fixes:

* A race condition in the way asynchronous I/O and fallocate() interacted
when using ext4 could allow a local, unprivileged user to obtain random
data from a deleted file. (CVE-2012-4508, Important)

* A flaw in the way the Xen hypervisor implementation range checked guest
provided addresses in the XENMEM_exchange hypercall could allow a
malicious, para-virtualized guest administrator to crash the hypervisor or,
potentially, escalate their privileges, allowing them to execute arbitrary
code at the hypervisor level. (CVE-2012-5513, Important)

* A flaw in the Reliable Datagram Sockets (RDS) protocol implementation
could allow a local, unprivileged user to cause a denial of service.
(CVE-2012-2372, Moderate)

* A race condition in the way access to inet->opt ip_options was
synchronized in the Linux kernel's TCP/IP protocol suite implementation.
Depending on the network facing applications running on the system, a
remote attacker could possibly trigger this flaw to cause a denial of
service. A local, unprivileged user could use this flaw to cause a denial
of service regardless of the applications the system runs. (CVE-2012-3552,

Bug fixes:

* Previously, the interrupt handlers of the qla2xxx driver could clear
pending interrupts right after the IRQ lines were attached during system
start-up. Consequently, the kernel could miss the interrupt that reported
completion of the link initialization, and the qla2xxx driver then failed
to detect all attached LUNs. With this update, the qla2xxx driver has been
modified to no longer clear interrupt bits after attaching the IRQ lines.

Description truncated, please see the referenced URL(s) for more information.

Affected Software/OS:
kernel on Red Hat Enterprise Linux (v. 5 server)

Please Install the Updated Packages.

CVSS Score:

CVSS Vector:

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-2372
BugTraq ID: 54062
HPdes Security Advisory: HPSBGN02970
RedHat Security Advisories: RHSA-2012:0743
RedHat Security Advisories: RHSA-2012:1540
SuSE Security Announcement: SUSE-SU-2012:1679 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2012-3552
Common Vulnerability Exposure (CVE) ID: CVE-2012-4508
RedHat Security Advisories: RHSA-2013:0496
RedHat Security Advisories: RHSA-2013:1519
RedHat Security Advisories: RHSA-2013:1783
Common Vulnerability Exposure (CVE) ID: CVE-2012-4535
BugTraq ID: 56498
Debian Security Information: DSA-2582 (Google Search)
SuSE Security Announcement: SUSE-SU-2012:1486 (Google Search)
SuSE Security Announcement: SUSE-SU-2012:1487 (Google Search)
SuSE Security Announcement: SUSE-SU-2012:1615 (Google Search)
SuSE Security Announcement: SUSE-SU-2014:0446 (Google Search)
SuSE Security Announcement: SUSE-SU-2014:0470 (Google Search)
SuSE Security Announcement: openSUSE-SU-2012:1572 (Google Search)
SuSE Security Announcement: openSUSE-SU-2012:1573 (Google Search)
XForce ISS Database: xen-vcpu-dos(80022)
Common Vulnerability Exposure (CVE) ID: CVE-2012-4537
XForce ISS Database: xen-setp2mentry-dos(80024)
Common Vulnerability Exposure (CVE) ID: CVE-2012-5513
BugTraq ID: 56797
SuSE Security Announcement: SUSE-SU-2012:1606 (Google Search)
SuSE Security Announcement: openSUSE-SU-2012:1685 (Google Search)
SuSE Security Announcement: openSUSE-SU-2012:1687 (Google Search)
SuSE Security Announcement: openSUSE-SU-2013:0133 (Google Search)
SuSE Security Announcement: openSUSE-SU-2013:0636 (Google Search)
SuSE Security Announcement: openSUSE-SU-2013:0637 (Google Search)
XForce ISS Database: xen-xenmemexchange-priv-esc(80482)
CopyrightCopyright (C) 2012 Greenbone Networks GmbH

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

© 1998-2021 E-Soft Inc. All rights reserved.