Amazon Linux AMI : kernel (ALAS-2014-339)
Medium Nessus Plugin ID 78282
SynopsisThe remote Amazon Linux AMI host is missing a security update.
DescriptionThe n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the 'LECHO & !OPOST' case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.
SolutionRun 'yum update kernel' to update your system. You will need to reboot your system in order for the new kernel to be running.