openSUSE Security Update : kernel (kernel-1908)

This script is Copyright (C) 2010-2016 Tenable Network Security, Inc.


Synopsis :

The remote openSUSE host is missing a security update.

Description :

This kernel update for openSUSE 11.0 fixes some bugs and several
security problems.

The following security issues are fixed: CVE-2009-4536:
drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel
handles Ethernet frames that exceed the MTU by processing certain
trailing payload data as if it were a complete frame, which allows
remote attackers to bypass packet filters via a large packet with a
crafted payload.

CVE-2009-4538: drivers/net/e1000e/netdev.c in the e1000e driver in the
Linux kernel does not properly check the size of an Ethernet frame
that exceeds the MTU, which allows remote attackers to have an
unspecified impact via crafted packets.

CVE-2010-0007: Missing CAP_NET_ADMIN checks in the ebtables netfilter
code might have allowed local attackers to modify bridge firewall
settings.

CVE-2010-0003: An information leakage on fatal signals on x86_64
machines was fixed.

CVE-2009-4138: drivers/firewire/ohci.c in the Linux kernel, when
packet-per-buffer mode is used, allows local users to cause a denial
of service (NULL pointer dereference and system crash) or possibly
have unknown other impact via an unspecified ioctl associated with
receiving an ISO packet that contains zero in the payload-length
field.

CVE-2009-4308: The ext4_decode_error function in fs/ext4/super.c in
the ext4 filesystem in the Linux kernel before 2.6.32 allows
user-assisted remote attackers to cause a denial of service (NULL
pointer dereference), and possibly have unspecified other impact, via
a crafted read-only filesystem that lacks a journal.

CVE-2009-3939: The poll_mode_io file for the megaraid_sas driver in
the Linux kernel 2.6.31.6 and earlier has world-writable permissions,
which allows local users to change the I/O mode of the driver by
modifying this file.

CVE-2009-4021: The fuse_direct_io function in fs/fuse/file.c in the
fuse subsystem in the Linux kernel before 2.6.32-rc7 might allow
attackers to cause a denial of service (invalid pointer dereference
and OOPS) via vectors possibly related to a memory-consumption attack.

CVE-2009-3547: A race condition in the pipe(2) systemcall could be
used by local attackers to hang the machine. The kernel in Moblin 2.0
uses NULL ptr protection which avoids code execution possbilities.

CVE-2009-2903: Memory leak in the appletalk subsystem in the Linux
kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the
appletalk and ipddp modules are loaded but the ipddp'N' device is not
found, allows remote attackers to cause a denial of service (memory
consumption) via IP-DDP datagrams.

CVE-2009-3621: net/unix/af_unix.c in the Linux kernel 2.6.31.4 and
earlier allows local users to cause a denial of service (system hang)
by creating an abstract-namespace AF_UNIX listening socket, performing
a shutdown operation on this socket, and then performing a series of
connect operations to this socket.

CVE-2009-3612: The tcf_fill_node function in net/sched/cls_api.c in
the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and
2.4.37.6 and earlier, does not initialize a certain tcm__pad2
structure member, which might allow local users to obtain sensitive
information from kernel memory via unspecified vectors.

CVE-2009-3620: The ATI Rage 128 (aka r128) driver in the Linux kernel
before 2.6.31-git11 does not properly verify Concurrent Command Engine
(CCE) state initialization, which allows local users to cause a denial
of service (NULL pointer dereference and system crash) or possibly
gain privileges via unspecified ioctl calls.

CVE-2009-3726: The nfs4_proc_lock function in fs/nfs/nfs4proc.c in the
NFSv4 client in the Linux kernel before 2.6.31-rc4 allows remote NFS
servers to cause a denial of service (NULL pointer dereference and
panic) by sending a certain response containing incorrect file
attributes, which trigger attempted use of an open file that lacks
NFSv4 state.

CVE-2009-3286: NFSv4 in the Linux kernel 2.6.18, and possibly other
versions, does not properly clean up an inode when an O_EXCL create
fails, which causes files to be created with insecure settings such as
setuid bits, and possibly allows local users to gain privileges,
related to the execution of the do_open_permission function even when
a create fails.

CVE-2009-2910: arch/x86/ia32/ia32entry.S in the Linux kernel before
2.6.31.4 on the x86_64 platform does not clear certain kernel
registers before a return to user mode, which allows local users to
read register values from an earlier process by switching an ia32
process to 64-bit mode.

CVE-2009-3238: The get_random_int function in drivers/char/random.c in
the Linux kernel before 2.6.30 produces insufficiently random numbers,
which allows attackers to predict the return value, and possibly
defeat protection mechanisms based on randomization, via vectors that
leverage the function's tendency to 'return the same value over and
over again for long stretches of time.'

CVE-2009-2848: The execve function in the Linux kernel, possibly
2.6.30-rc6 and earlier, does not properly clear the
current->clear_child_tid pointer, which allows local users to cause a
denial of service (memory corruption) or possibly gain privileges via
a clone system call with CLONE_CHILD_SETTID or CLONE_CHILD_CLEARTID
enabled, which is not properly handled during thread creation and
exit.

CVE-2009-3002: The Linux kernel before 2.6.31-rc7 does not initialize
certain data structures within getname functions, which allows local
users to read the contents of some kernel memory locations by calling
getsockname on (1) an AF_APPLETALK socket, related to the
atalk_getname function in net/appletalk/ddp.c; (2) an AF_IRDA socket,
related to the irda_getname function in net/irda/af_irda.c; (3) an
AF_ECONET socket, related to the econet_getname function in
net/econet/af_econet.c; (4) an AF_NETROM socket, related to the
nr_getname function in net/netrom/af_netrom.c; (5) an AF_ROSE socket,
related to the rose_getname function in net/rose/af_rose.c; or (6) a
raw CAN socket, related to the raw_getname function in net/can/raw.c.

CVE-2009-1633: Multiple buffer overflows in the cifs subsystem in the
Linux kernel before 2.6.29.4 allow remote CIFS servers to cause a
denial of service (memory corruption) and possibly have unspecified
other impact via (1) a malformed Unicode string, related to Unicode
string area alignment in fs/cifs/sess.c; or (2) long Unicode
characters, related to fs/cifs/cifssmb.c and the cifs_readdir function
in fs/cifs/readdir.c.

See also :

https://bugzilla.novell.com/show_bug.cgi?id=421732
https://bugzilla.novell.com/show_bug.cgi?id=441062
https://bugzilla.novell.com/show_bug.cgi?id=492282
https://bugzilla.novell.com/show_bug.cgi?id=526368
https://bugzilla.novell.com/show_bug.cgi?id=527865
https://bugzilla.novell.com/show_bug.cgi?id=534372
https://bugzilla.novell.com/show_bug.cgi?id=536467
https://bugzilla.novell.com/show_bug.cgi?id=539878
https://bugzilla.novell.com/show_bug.cgi?id=541648
https://bugzilla.novell.com/show_bug.cgi?id=541658
https://bugzilla.novell.com/show_bug.cgi?id=543740
https://bugzilla.novell.com/show_bug.cgi?id=547131
https://bugzilla.novell.com/show_bug.cgi?id=548070
https://bugzilla.novell.com/show_bug.cgi?id=548071
https://bugzilla.novell.com/show_bug.cgi?id=550001
https://bugzilla.novell.com/show_bug.cgi?id=552775
https://bugzilla.novell.com/show_bug.cgi?id=556864
https://bugzilla.novell.com/show_bug.cgi?id=557180
https://bugzilla.novell.com/show_bug.cgi?id=564382
https://bugzilla.novell.com/show_bug.cgi?id=564712
https://bugzilla.novell.com/show_bug.cgi?id=567376
https://bugzilla.novell.com/show_bug.cgi?id=569902
https://bugzilla.novell.com/show_bug.cgi?id=570606

Solution :

Update the affected kernel packages.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
Public Exploit Available : true

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now