MGASA-2014-0455

Source
https://advisories.mageia.org/MGASA-2014-0455.html
Import Source
https://advisories.mageia.org/MGASA-2014-0455.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2014-0455
Related
Published
2014-11-15T18:31:46Z
Modified
2014-11-15T18:14:04Z
Summary
Updated kernel-vserver packages fix security vulnerabilities
Details

This kernel-vserver update provides an upgrade to the upstream 3.14 -longterm branch, currently based on 3.14.23 and fixes the following security issues:

The kvmiommumap_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of service (host OS memory corruption) or possibly have unspecified other impact by triggering a large gfn value or (2) cause a denial of service (host OS memory consumption) by triggering a small gfn value that leads to permanently pinned pages (CVE-2014-3601).

The assocarraygc function in the associative-array implementation in lib/assoc_array.c in the Linux kernel before 3.16.3 does not properly implement garbage collection, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via multiple "keyctl newring" operations followed by a "keyctl timeout" operation (CVE-2014-3631).

The xfsda3fixhashpath function in fs/xfs/xfsdabtree.c in the xfs implementation in the Linux kernel before 3.14.2 does not properly compare btree hash values, which allows local users to cause a denial of service (filesystem corruption, and OOPS or panic) via operations on directories that have hash collisions, as demonstrated by rmdir operations (CVE-2014-7283).

The netgetrandom_once implementation in net/core/utils.c in the Linux kernel 3.13.x and 3.14.x before 3.14.5 on certain Intel processors does not perform the intended slow-path operation to initialize random seeds, which makes it easier for remote attackers to spoof or disrupt IP communication by leveraging the predictability of TCP sequence numbers, TCP and UDP port numbers, and IP ID values (CVE-2014-7284)

The pivotroot implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of service (mount-tree loop) via . (dot) values in both arguments to the pivotroot system call (CVE-2014-7970).

The doumount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAPSYSADMIN capability for doremountsb calls that change the root filesystem to read-only, which allows local users to cause a denial of service (loss of writability) by making certain unshare system calls, clearing the / MNTLOCKED flag, and making an MNT_FORCE umount system call (CVE-2014-7975).

Other fixes: The X86_SYSFB config option has been disabled as it prevents proper KMS setup on some systems (mga#13098)

The vserver patch has been updated to vs2.3.6.13

The util-vserver userspace tools has been updated to 0.30.216-pre3062

For other fixes included in this update, read the referenced changelogs.

References
Credits

Affected packages

Mageia:4 / kernel-vserver

Package

Name
kernel-vserver
Purl
pkg:rpm/mageia/kernel-vserver?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.14.23-0.vs2.3.6.13.1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / util-vserver

Package

Name
util-vserver
Purl
pkg:rpm/mageia/util-vserver?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.30.216-0.pre3062.1.mga4

Ecosystem specific

{
    "section": "core"
}