LWN.net Logo

kernel: multiple vulnerabilities

Package(s):kernel CVE #(s):CVE-2009-4067 CVE-2011-2942 CVE-2011-3209 CVE-2011-3347
Created:October 20, 2011 Updated:March 29, 2012
Description:

From the Red Hat advisory:

A flaw in the auerswald USB driver could allow a local, unprivileged user to cause a denial of service or escalate their privileges by inserting a specially-crafted USB device. (CVE-2009-4067, Low)

RHSA-2011:1065 introduced a regression in the Ethernet bridge implementation. If a system had an interface in a bridge, and an attacker on the local network could send packets to that interface, they could cause a denial of service on that system. Xen hypervisor and KVM (Kernel-based Virtual Machine) hosts often deploy bridge interfaces. (CVE-2011-2942, Moderate)

A flaw in the kernel's clock implementation could allow a local, unprivileged user to cause a denial of service. (CVE-2011-3209, Moderate)

Non-member VLAN (virtual LAN) packet handling for interfaces in promiscuous mode and also using the be2net driver could allow an attacker on the local network to cause a denial of service. (CVE-2011-3347, Moderate)

Alerts:
Scientific Linux SL-Kern-20111206 2011-12-06
Oracle ELSA-2011-2037 2011-12-15
Ubuntu USN-1294-1 2011-12-08
Red Hat RHSA-2011:1530-03 2011-12-06
Fedora FEDORA-2011-15856 2011-11-13
Ubuntu USN-1256-1 2011-11-09
Ubuntu USN-1268-1 2011-11-21
Red Hat RHSA-2011:1419-01 2011-11-01
Red Hat RHSA-2011:1418-01 2011-11-01
SUSE SUSE-SA:2011:042 2011-10-28
SUSE SUSE-SU-2011:1195-1 2011-10-28
Scientific Linux SL-kern-20111020 2011-10-20
Ubuntu USN-1236-1 2011-10-20
CentOS CESA-2011:1386 2011-10-21
Red Hat RHSA-2011:1386-01 2011-10-20
Red Hat RHSA-2012:0116-01 2012-02-15
Oracle ELSA-2012-0150 2012-03-07
Ubuntu USN-1409-1 2012-03-27
Ubuntu USN-1405-1 2012-03-27
Ubuntu USN-1404-1 2012-03-27
Ubuntu USN-1412-1 2012-03-29
openSUSE openSUSE-SU-2012:0781-1 2012-06-22
openSUSE openSUSE-SU-2012:0812-1 2012-07-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds