[Rdo-list] [package announce] Moderate: kernel security and enhancement update
pbrady at redhat.com
Wed Oct 23 20:21:21 UTC 2013
RDO includes a custom Enterprise Linux 6.4 kernel.
These custom kernel packages include extra networking functionality
required to facilitate advanced OpenStack Networking deployments.
This update fixes 2 moderate security issues:
* A flaw was found in the way the Linux kernel's TCP/IP protocol suite
implementation handled IPv6 sockets that used the UDP_CORK option. A local,
unprivileged user could use this flaw to cause a denial of service.
* An information leak flaw was found in the way Linux kernel's device
mapper subsystem, under certain conditions, interpreted data written to
snapshot block devices. An attacker could use this flaw to read data from
disk blocks in free space, which are normally inaccessible.
Red Hat would like to thank Hannes Frederic Sowa for reporting
CVE-2013-4162; and Fujitsu for reporting CVE-2013-4299.
This update also adds the following enhancements:
* Support for Distributed Overlay Virtual Ethernet (DOVE).
* Support for Virtual Extensible LAN (VXLAN) as an OpenvSwitch (OVS) tunneling type.
All RDO Enterprise Linux users deploying the OpenStack Networking
service are advised to install these updated packages.
The packages containing the fixes are:
More information about the dev