kernel (SL4)

Synopsis: Important: Red Hat Enterprise Linux 4.9 kernel security and bug fix update
Issue Date: 2011-02-16
CVE Numbers: CVE-2010-4527
CVE-2011-0521
CVE-2010-4655

The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* A buffer overflow flaw was found in the load_mixer_volumes() function in
the Linux kernel’s Open Sound System (OSS) sound driver. On 64-bit PowerPC
systems, a local, unprivileged user could use this flaw to cause a denial
of service or escalate their privileges. (CVE-2010-4527, Important)

* A missing boundary check was found in the dvb_ca_ioctl() function in the
Linux kernel’s av7110 module. On systems that use old DVB cards that
require the av7110 module, a local, unprivileged user could use this flaw
to cause a denial of service or escalate their privileges. (CVE-2011-0521,
Important)

* A missing initialization flaw was found in the ethtool_get_regs()
function in the Linux kernel’s ethtool IOCTL handler. A local user who has
the CAP_NET_ADMIN capability could use this flaw to cause an information
leak. (CVE-2010-4655, Low)

Red Hat would like to thank Dan Rosenberg for reporting CVE-2010-4527, and
Kees Cook for reporting CVE-2010-4655.

These updated kernel packages also fix hundreds of bugs and add numerous
enhancements. For details on individual bug fixes and enhancements included
in this update, refer to the Red Hat Enterprise Linux 4.9 Release Notes,
linked to in the References section.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues and add these enhancements. The system must
be rebooted for this update to take effect.

SL4
x86_64
kernel-2.6.9-100.EL.x86_64.rpm
kernel-devel-2.6.9-100.EL.x86_64.rpm
kernel-largesmp-2.6.9-100.EL.x86_64.rpm
kernel-largesmp-devel-2.6.9-100.EL.x86_64.rpm
kernel-smp-2.6.9-100.EL.x86_64.rpm
kernel-smp-devel-2.6.9-100.EL.x86_64.rpm
kernel-xenU-2.6.9-100.EL.x86_64.rpm
kernel-xenU-devel-2.6.9-100.EL.x86_64.rpm
i386
kernel-2.6.9-100.EL.i686.rpm
kernel-devel-2.6.9-100.EL.i686.rpm
kernel-hugemem-2.6.9-100.EL.i686.rpm
kernel-hugemem-devel-2.6.9-100.EL.i686.rpm
kernel-smp-2.6.9-100.EL.i686.rpm
kernel-smp-devel-2.6.9-100.EL.i686.rpm
kernel-xenU-2.6.9-100.EL.i686.rpm
kernel-xenU-devel-2.6.9-100.EL.i686.rpm
noarch
kernel-doc-2.6.9-100.EL.noarch.rpm

– Scientific Linux Development Team