RHEL 7 : kernel (RHSA-2017:0217)

This script is Copyright (C) 2017 Tenable Network Security, Inc.


Synopsis :

The remote Red Hat host is missing one or more security updates.

Description :

An update for kernel is now available for Red Hat Enterprise Linux 7.2
Extended Update Support.

Red Hat Product Security has rated this update as having a security
impact of Important. A Common Vulnerability Scoring System (CVSS) base
score, which gives a detailed severity rating, is available for each
vulnerability from the CVE link(s) in the References section.

The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security Fix(es) :

* A use-after-free vulnerability was found in the kernel's socket
recvmmsg subsystem. This may allow remote attackers to corrupt memory
and may allow execution of arbitrary code. This corruption takes place
during the error handling routines within __sys_recvmmsg() function.
(CVE-2016-7117, Important)

* It is possible for a single process to cause an OOM condition by
filling large pipes with data that are never read. A typical process
filling 4096 pipes with 1 MB of data will use 4 GB of memory and there
can be multiple such processes, up to a per-user-limit.
(CVE-2016-2847, Moderate)

Red Hat would like to thank Tetsuo Handa for reporting CVE-2016-2847.

Bug Fix(es) :

* Previously, an XFS corruption in some cases occurred on Seagate 8TB
drive based volumes after a planned system shutdown or reboot, when a
disk write back cache was used. With this update, the megaraid_sas
driver has been fixed and the XFS corruption no longer occurs in the
described scenario. (BZ#1398178)

* This update applies a set of patches for the resizable hash table
(rhashtable). This set contains backported bug fixes and enhancements
from upstream. (BZ#1382630)

* Previously, a kernel panic in some cases occurred during the boot
with the Nonvolatile Memory Express (NVMe) kernel module, because the
NVMe driver did not receive legacy PCI interrupts. This update fixes
the NVMe driver to always use the Message Signaled Interrupts
(MSI/MSI-X) interrupts. As a result, the operating system now boots
without panic under the described circumstances. (BZ#1396558)

* Previously, the Advanced Error Reporting (AER) correct error in some
cases caused a kernel panic. This update fixes the
_scsih_pci_mmio_enabled() function in the mpt3sas driver to not
incorrectly return PCI_ERS_RESULT_NEED_RESET return value in the
situation when PCI_ERS_RESULT_RECOVERED return value is expected. As a
result, the kernel no longer panics due to _scsih_pci_mmio_enabled().
(BZ#1395220)

* When resizing the Transmit (TX) and Receive (RX) rings in the sfc
driver with the 'ethtool -G' command, a kernel protection fault in the
napi_hash_add() function occurred on systems with a large number of
queues. With this update, the efx_copy_channel()function in the sfc
driver has been fixed to correctly clear the napi_hash state. As a
result, the sfc kernel module now unloads successfully without the
mentioned kernel protection fault. (BZ#1401460)

* When a virtual machine (VM) with 2 PCI-Passthrough Ethernet
interfaces attached was created, deleted and recreated, the operating
system terminated unexpectedly and rebooted during the recreation.
This update fixes the race condition between the eventfd and virqfd
signaling mechanisms in the vfio driver. As a result, the operating
system now boots without crashing in the described situation.
(BZ#1391610)

* Previously, when two NFS shares with different security settings
were mounted, the I/O operations to the kerberos-authenticated mount
caused the RPC_CRED_KEY_EXPIRE_SOON parameter to be set, but the
parameter was not unset when performing the I/O operations on the
sec=sys mount. Consequently, writes to both NFS shares had the same
parameters, regardless of their security settings. This update fixes
this problem by moving the NO_CRKEY_TIMEOUT parameter to the
auth->au_flags field. As a result, NFS shares with different security
settings are now handled as expected. (BZ#1388603)

* Previously, memory corruption by copying data into the wrong memory
locations sometimes occurred, because the __copy_tofrom_user()
function was returning incorrect values. This update fixes the
__copy_tofrom_user() function so that it no longer returns larger
values than the number of bytes it was asked to copy. As a result,
memory corruption no longer occurs in he described scenario.
(BZ#1398588)

See also :

https://www.redhat.com/security/data/cve/CVE-2016-2847.html
https://www.redhat.com/security/data/cve/CVE-2016-7117.html
https://access.redhat.com/security/vulnerabilities/2706661
http://rhn.redhat.com/errata/RHSA-2017-0217.html

Solution :

Update the affected packages.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 7.4
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: Red Hat Local Security Checks

Nessus Plugin ID: 96922 ()

Bugtraq ID:

CVE ID: CVE-2016-2847
CVE-2016-7117

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now