·ChinaUnix首页 ·论坛 ·博客 
Linux首页 | Linux新闻 | Linux文档 | Linux论坛 | Linux下载 | Linux博客 | Linux搜索
新手入门 | 安装启动 | 管理员指南 | 开发者手册 | 桌面应用 | 程序开发 | 数据库 | 网络技术| CentOS | Fedora | RHEL | Ubuntu | Apache | MySQL | PHP
  Linux时代 >> 新闻
 
重要升级:内核漏洞影响RHEL5所有版本
来源: Linux论坛  日期: 2008.05.21 15:22 (共有条评论) 我要评论
 
来源:linux时代

一个重要的内核安全漏洞被发现,现在RHEL5的内核补丁已经放出,这个漏洞可以使得非特权用户操作引起拒绝服务。
RHEL5的服务器版本和桌面版本都会受到影响,几乎所有的架构都受到影响,比如i386, x86_64, PPC和IBM s390x等。


A important kernel security and bug fix update was releasedfor Red Hat Enterprise Linux 5, repairing some issues that could allow an unprivileged user to cause a denial of service.

Red Hat Enterprise Linux 5 (both Desktop and Server editions) were affected by these issues. Almost all architectures could have had problems because of this security hole, including i386, x86_64, PPC, s390x and a few others.

The Linux kernel process-trace ability was tested on AMD64 architectures, discovering the possibility of a kernel crash that could allow a local unprivileged user to cause a denial of service.

Due to improper handling of fragmented ESP packets, a possibility of a kernel crash was discovered in the Linux kernel IPsec protocol implementation. If these packages were fragmented in very small chunks, a kernel crash might have occurred during the packet reassembly on the receiving node.

A denial of service could have been caused on 64-bit architectures if a local unprivileged user setup a large interval value for hrtimer, forcing the time expiry value to become negative.

Another problem that could cause a denial of service was found in the Linux kernel PWC USB video driver. The kernel USB subsystem could be brought into the busy-waiting mode by a normal user and cause a DoS.

The updated packages will resolve some other issues as well, like the continual "softlockup" messages that kept occurring on the guest's console after successfully saving and restoring a Red Hat Enterprise Linux 5 para-virtualized guest. Sometimes, a kernel hung and panic occurred when the cpufreq daemon was disabled. Because of this, some system reboots did not complete successfully.

If you intend to apply the updated packages - and this is the advisable thing to do -, first make sure that you've installed all the previously-released updates.

[ 本帖最后由 Send_linux 于 2008-5-22 10:43 编辑 ]
  发表评论 查看评论(共有条评论)
 
 


最新资讯更多>> 
· Symbian开源:救赎 反击与未来
· Google发布内部安全侦测工具Ra..
· RMS攻击盖茨、微软及其慈善基金会
· Richard Stallman对盖茨退休的..
· 发行版发布:Ubuntu 8.04.1
· Ubuntu Tweak 0.3.4正式发布
· 哪一个 Linux 发行版最流行?
· 开源运营引发中小网游厂商运营..
· Core 2 Duo E8400 Ubuntu性能全..
· Linux下Wine中文对话框乱码解决法
论坛热点更多>> 
· 70后和80后 的婚姻
· 系统时钟比硬件时钟快很多,..
· crontab内容无法启动
· [转贴]热词“俯卧撑”风靡网络
· 闲啊闲~闲啊闲
· 墙纸 1280x1024
· 好儿呢。。。
· 原来我也是一个小心眼得女人
· 信誉积分怎么得?
· @@
文档更新更多>> 
· [转]几种linux内核文件的区别
· Debian 在线播放
· epoll入门
· yum出现Existing lock /var/run/..
· RPM 的介绍和应用
· SSH客户端命令的使用
· Unix/Linux下文件基本操作
· vmstat命令列出的属性详解
· linux学习笔记分享 (Linux入门绝佳)
· squid 命令行选项分类
 
关于我们 | 联系方式 | 广告合作 | 诚聘英才 | 网站地图 | 友情链接 | 免费注册

Copyright © 2001-2008 ChinaUnix.net All Rights Reserved

感谢所有关心和支持过ChinaUnix的朋友们