Red Hat Customer Portal

Skip to main content

Main Navigation

  • Products & Services
    • Back
    • View All Products
    • Infrastructure and Management
      • Back
      • Red Hat Enterprise Linux
      • Red Hat Virtualization
      • Red Hat Identity Management
      • Red Hat Directory Server
      • Red Hat Certificate System
      • Red Hat Satellite
      • Red Hat Subscription Management
      • Red Hat Update Infrastructure
      • Red Hat Insights
      • Red Hat Ansible Tower
      • Red Hat Ansible Engine
    • Cloud Computing
      • Back
      • Red Hat CloudForms
      • Red Hat OpenStack Platform
      • Red Hat Cloud Infrastructure
      • Red Hat Cloud Suite
      • Red Hat OpenShift Container Platform
      • Red Hat OpenShift Online
      • Red Hat OpenShift Dedicated
      • Red Hat OpenShift Application Runtimes
    • Storage
      • Back
      • Red Hat Gluster Storage
      • Red Hat Hyperconverged Infrastructure
      • Red Hat Ceph Storage
      • Red Hat Openshift Container Storage
    • JBoss Development and Management
      • Back
      • Red Hat JBoss Enterprise Application Platform
      • Red Hat JBoss Data Grid
      • Red Hat JBoss Web Server
      • Red Hat JBoss Operations Network
      • Red Hat Developer Studio
    • JBoss Integration and Automation
      • Back
      • Red Hat JBoss Data Virtualization
      • Red Hat Fuse
      • Red Hat AMQ
      • Red Hat Process Automation Manager
      • Red Hat Decision Manager
      • Red Hat 3scale API Management
    • Mobile
      • Back
      • Red Hat Mobile Application Platform
    • Support
    • Production Support
    • Development Support
    • Product Life Cycle & Update Policies
    • Documentation
    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    • Services
    • Consulting
    • Technical Account Management
    • Training & Certifications
    • Ecosystem
    • Browse Certified Solutions
    • Partner Resources
  • Tools
    • Back
    • Red Hat Insights
    • Tools
    • Solution Engine
    • Packages
    • Errata
    • Customer Portal Labs
    • Explore Labs
    • Configuration
    • Deployment
    • Security
    • Troubleshooting
  • Security
    • Back
    • Product Security Center
    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Security Labs
    • Resources
    • Overview
    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community
    • Back
    • Customer Portal Community
    • Discussions
    • Blogs
    • Private Groups
    • Community Activity
    • Customer Events
    • Red Hat Convergence
    • Red Hat Summit
    • Stories
    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Account
    • Back
    • Log In
    • Register
    • Red Hat Account Number:
    • Account Details
    • User Management
    • Account Maintenance
    • My Profile
    • Notifications
    • Help
    • Log Out
  • Language
    • Back
    • English
    • Español
    • Deutsch
    • Italiano
    • 한국어
    • Français
    • 日本語
    • Português
    • 中文 (中国)
    • русский
Red Hat Logo Customer Portal
  • Products & Services
    • Back
    • View All Products
    • Infrastructure and Management
      • Back
      • Red Hat Enterprise Linux
      • Red Hat Virtualization
      • Red Hat Identity Management
      • Red Hat Directory Server
      • Red Hat Certificate System
      • Red Hat Satellite
      • Red Hat Subscription Management
      • Red Hat Update Infrastructure
      • Red Hat Insights
      • Red Hat Ansible Tower
      • Red Hat Ansible Engine
    • Cloud Computing
      • Back
      • Red Hat CloudForms
      • Red Hat OpenStack Platform
      • Red Hat Cloud Infrastructure
      • Red Hat Cloud Suite
      • Red Hat OpenShift Container Platform
      • Red Hat OpenShift Online
      • Red Hat OpenShift Dedicated
      • Red Hat OpenShift Application Runtimes
    • Storage
      • Back
      • Red Hat Gluster Storage
      • Red Hat Hyperconverged Infrastructure
      • Red Hat Ceph Storage
      • Red Hat Openshift Container Storage
    • JBoss Development and Management
      • Back
      • Red Hat JBoss Enterprise Application Platform
      • Red Hat JBoss Data Grid
      • Red Hat JBoss Web Server
      • Red Hat JBoss Operations Network
      • Red Hat Developer Studio
    • JBoss Integration and Automation
      • Back
      • Red Hat JBoss Data Virtualization
      • Red Hat Fuse
      • Red Hat AMQ
      • Red Hat Process Automation Manager
      • Red Hat Decision Manager
      • Red Hat 3scale API Management
    • Mobile
      • Back
      • Red Hat Mobile Application Platform
    • Support
    • Production Support
    • Development Support
    • Product Life Cycle & Update Policies
    • Documentation
    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    • Services
    • Consulting
    • Technical Account Management
    • Training & Certifications
    • Ecosystem
    • Browse Certified Solutions
    • Partner Resources
  • Tools
    • Back
    • Red Hat Insights
    • Tools
    • Solution Engine
    • Packages
    • Errata
    • Customer Portal Labs
    • Explore Labs
    • Configuration
    • Deployment
    • Security
    • Troubleshooting
  • Security
    • Back
    • Product Security Center
    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Security Labs
    • Resources
    • Overview
    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community
    • Back
    • Customer Portal Community
    • Discussions
    • Blogs
    • Private Groups
    • Community Activity
    • Customer Events
    • Red Hat Convergence
    • Red Hat Summit
    • Stories
    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Account
    • Back
    • Log In
    • Register
    • Red Hat Account Number:
    • Account Details
    • User Management
    • Account Maintenance
    • My Profile
    • Notifications
    • Help
    • Log Out
  • Language
    • Back
    • English
    • Español
    • Deutsch
    • Italiano
    • 한국어
    • Français
    • 日本語
    • Português
    • 中文 (中国)
    • русский
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Search
  • Log In
  • Language
Troubleshooting an issue? Try Solution Engine—our new support tool.

Log in to Your Red Hat Account

Log In

Your Red Hat account gives you access to your profile, preferences, and services, depending on your status.

Register

If you are a new customer, register now for access to product evaluations and purchasing capabilities.

Need access to an account?

If your company has an existing Red Hat account, your organization administrator can grant you access.

If you have any questions, please contact customer service.

Red Hat Account Number:

Red Hat Account

  • Account Details
  • User Management
  • Account Maintenance

Customer Portal

  • My Profile
  • Notifications
  • Help

For your security, if you’re on a public computer and have finished using your Red Hat services, please be sure to log out.

Log Out

Select Your Language

  • English
  • Español
  • Deutsch
  • Italiano
  • 한국어
  • Français
  • 日本語
  • Português
  • 中文 (中国)
  • русский
Red Hat Customer Portal
  • Products & Services
  • Tools
  • Security
  • Community
  • Infrastructure and Management

  • Cloud Computing

  • Storage

  • JBoss Development and Management

  • JBoss Integration and Automation

  • Mobile

  • Red Hat Enterprise Linux
  • Red Hat Virtualization
  • Red Hat Identity Management
  • Red Hat Directory Server
  • Red Hat Certificate System
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Update Infrastructure
  • Red Hat Insights
  • Red Hat Ansible Tower
  • Red Hat Ansible Engine
  • Red Hat CloudForms
  • Red Hat OpenStack Platform
  • Red Hat Cloud Infrastructure
  • Red Hat Cloud Suite
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Online
  • Red Hat OpenShift Dedicated
  • Red Hat OpenShift Application Runtimes
  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat Openshift Container Storage
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat JBoss Data Grid
  • Red Hat JBoss Web Server
  • Red Hat JBoss Operations Network
  • Red Hat Developer Studio
  • Red Hat JBoss Data Virtualization
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat Process Automation Manager
  • Red Hat Decision Manager
  • Red Hat 3scale API Management
  • Red Hat Mobile Application Platform
View All Products
  • Support
  • Production Support
  • Development Support
  • Product Life Cycle & Update Policies

Services

  • Consulting
  • Technical Account Management
  • Training & Certifications
  • Documentation
  • Red Hat Enterprise Linux
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Ecosystem
  • Browse Certified Solutions
  • Partner Resources

Tools

  • Solution Engine
  • Packages
  • Errata
  • Customer Portal Labs
  • Configuration
  • Deployment
  • Security
  • Troubleshooting
  • Red Hat Insights

Increase visibility into IT operations to detect and resolve technical issues before they impact your business.

Red Hat Product Security Center

Engage with our Red Hat Product Security team, access security updates, and ensure your environments are not exposed to any known security vulnerabilities.

Product Security Center

Security Updates

  • Security Advisories
  • Red Hat CVE Database
  • Security Labs

Keep your systems secure with Red Hat's specialized responses for high-priority security vulnerabilities.

  • View Responses

Resources

  • Overview
  • Security Blog
  • Security Measurement
  • Severity Ratings
  • Backporting Policies
  • Product Signing (GPG) Keys

Customer Portal Community

  • Discussions
  • Blogs
  • Private Groups
  • Community Activity

Customer Events

  • Red Hat Convergence
  • Red Hat Summit

Stories

  • Red Hat Subscription Value
  • You Asked. We Acted.
  • Open Source Communities
Red Hat Product Errata RHSA-2013:1080 - Security Advisory
Issued:
2013-07-16
Updated:
2013-07-16

RHSA-2013:1080 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: kernel security and bug fix update

Type/Severity

Security Advisory: Moderate

Topic

Updated kernel packages that fix multiple security issues and several bugs
are now available for Red Hat OpenStack 3.0.

The Red Hat Security Response Team has rated this update as having moderate
security impact. Common Vulnerability Scoring System (CVSS) base scores,
which give detailed severity ratings, are available for each vulnerability
from the CVE links in the References section.

Description

Red Hat OpenStack 3.0 includes a custom Red Hat Enterprise Linux 6.4
kernel. These custom kernel packages include support for network
namespaces, this support is required to facilitate advanced OpenStack
Networking deployments.

This update fixes the following security issues:

  • A flaw was found in the tcp_read_sock() function in the Linux kernel's
    IPv4 TCP/IP protocol suite implementation in the way socket buffers (skb)
    were handled. A local, unprivileged user could trigger this issue via a
    call to splice(), leading to a denial of service. (CVE-2013-2128,
    Moderate)
  • Information leak flaws in the Linux kernel could allow a local,
    unprivileged user to leak kernel memory to user-space. (CVE-2012-6548,
    CVE-2013-2634, CVE-2013-2635, CVE-2013-3222, CVE-2013-3224, CVE-2013-3225,
    Low)
  • An information leak was found in the Linux kernel's POSIX signals
    implementation. A local, unprivileged user could use this flaw to bypass
    the Address Space Layout Randomization (ASLR) security feature.
    (CVE-2013-0914, Low)
  • A format string flaw was found in the ext3_msg() function in the Linux
    kernel's ext3 file system implementation. A local user who is able to mount
    an ext3 file system could use this flaw to cause a denial of service or,
    potentially, escalate their privileges. (CVE-2013-1848, Low)
  • A format string flaw was found in the b43_do_request_fw() function in the
    Linux kernel's b43 driver implementation. A local user who is able to
    specify the "fwpostfix" b43 module parameter could use this flaw to cause a
    denial of service or, potentially, escalate their privileges.
    (CVE-2013-2852, Low)
  • A NULL pointer dereference flaw was found in the Linux kernel's ftrace
    and function tracer implementations. A local user who has the CAP_SYS_ADMIN
    capability could use this flaw to cause a denial of service.
    (CVE-2013-3301, Low)

Red Hat would like to thank Kees Cook for reporting CVE-2013-2852.

More information on the Red Hat Enterprise Linux 6.4 kernel packages upon
which these custom kernel packages are based is available in
RHSA-2013:1051:

https://rhn.redhat.com/errata/RHSA-2013-1051.html

All Red Hat OpenStack 3.0 users deploying the OpenStack Networking service
are advised to install these updated packages.

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

Details on how to use the Red Hat Network to apply this update are
available at https://access.redhat.com/site/articles/11258

This Red Hat OpenStack 3.0 kernel may be installed by running this command
while logged in as the root user on a system that has the required
entitlements and subscriptions attached:

# yum install "kernel-2.6.*.openstack.el6.x86_64"

Documentation for both stable and preview releases of Red Hat OpenStack is
available at:

https://access.redhat.com/site/documentation/en-US/Red_Hat_OpenStack/

In particular it is highly recommended that all users read the Release
Notes document for the relevant Red Hat OpenStack release prior to
installation.

Affected Products

  • Red Hat OpenStack grizzly x86_64

Fixes

  • BZ - 920499 - CVE-2013-0914 Kernel: sa_restorer information leak
  • BZ - 920783 - CVE-2013-1848 kernel: ext3: format string issues
  • BZ - 922353 - CVE-2012-6548 Kernel: udf: information leak on export
  • BZ - 924689 - CVE-2013-2634 kernel: Information leak in the Data Center Bridging (DCB) component
  • BZ - 924690 - CVE-2013-2635 kernel: Information leak in the RTNETLINK component
  • BZ - 952197 - CVE-2013-3301 Kernel: tracing: NULL pointer dereference
  • BZ - 955216 - CVE-2013-3222 Kernel: atm: update msg_namelen in vcc_recvmsg()
  • BZ - 955599 - CVE-2013-3224 Kernel: Bluetooth: possible info leak in bt_sock_recvmsg()
  • BZ - 955649 - CVE-2013-3225 Kernel: Bluetooth: RFCOMM - missing msg_namelen update in rfcomm_sock_recvmsg
  • BZ - 968484 - CVE-2013-2128 Kernel: net: oops from tcp_collapse() when using splice(2)
  • BZ - 969518 - CVE-2013-2852 kernel: b43: format string leaking into error msgs

CVEs

  • CVE-2013-2635
  • CVE-2013-3225
  • CVE-2013-3224
  • CVE-2013-2634
  • CVE-2013-3222
  • CVE-2013-0914
  • CVE-2013-1848
  • CVE-2012-6548
  • CVE-2013-3301
  • CVE-2013-2128
  • CVE-2013-2852

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://rhn.redhat.com/errata/RHSA-2013-1051.html
  • https://access.redhat.com/site/documentation/en-US/Red_Hat_OpenStack/
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat OpenStack grizzly

SRPM
kernel-2.6.32-358.114.1.openstack.el6.src.rpm SHA-256: 6535fc00b84e90eb0ec88c990b5af20309fc8a0e06340614635e2832f3b2484b
x86_64
kernel-2.6.32-358.114.1.openstack.el6.x86_64.rpm SHA-256: 3508c3af6ef9875658199215dcfd4fecab9bcb6eda4d4fa29e0e4ee9a8e7ea87
kernel-debug-2.6.32-358.114.1.openstack.el6.x86_64.rpm SHA-256: bc15052cb22308f1d3f0efd9f963da5a68610544c2ebbd67b6a94daee62aa3c9
kernel-debug-debuginfo-2.6.32-358.114.1.openstack.el6.x86_64.rpm SHA-256: 81597c0e838d77e597b03e7d1cd78ed341f2a77c6a0e744f5bca3507c9fe9218
kernel-debug-devel-2.6.32-358.114.1.openstack.el6.x86_64.rpm SHA-256: e37673b08db80cd6b565c699f434a4e1c80dd9ddd571ae21bf62862c06894bdb
kernel-debuginfo-2.6.32-358.114.1.openstack.el6.x86_64.rpm SHA-256: 3779fa7f9bd837917186c0ca242fa9f4d3c1d14b62a865cfcbd1920e8e78a68c
kernel-debuginfo-common-x86_64-2.6.32-358.114.1.openstack.el6.x86_64.rpm SHA-256: 04c4b49573ed626a5a7f03392f05fa0a88e3a68c1222c99db77ff3a816659b97
kernel-devel-2.6.32-358.114.1.openstack.el6.x86_64.rpm SHA-256: 026834dc8479bc937805ac75e63ce852f8c977b1da502a301af8ba1c435decaf
kernel-doc-2.6.32-358.114.1.openstack.el6.noarch.rpm SHA-256: e5e254f2520cfdfdb5595f80e7749afc7dcc2fca8c31f50595226b26ca5e1296
kernel-firmware-2.6.32-358.114.1.openstack.el6.noarch.rpm SHA-256: 158bc83e373f30065fde3332553883a674736b3a6e2bc73a0c88cd6a2d0d57c2
kernel-headers-2.6.32-358.114.1.openstack.el6.x86_64.rpm SHA-256: f6791daf6d34f6f9a60ca7953d774503287958ca58f16a03305d0514325e901c
perf-2.6.32-358.114.1.openstack.el6.x86_64.rpm SHA-256: c9d49a54f828b75ab1578566056132234c56fee3bd8f84127b14cf2207199c9b
perf-debuginfo-2.6.32-358.114.1.openstack.el6.x86_64.rpm SHA-256: 937e5a5fcda90319df31789f71fefe46da8297358f525adbecb019262543670e
python-perf-2.6.32-358.114.1.openstack.el6.x86_64.rpm SHA-256: 4e9be07ad7d0c1a430f0d63537f418675db13d16463d59e1d4571c0e6989855f
python-perf-debuginfo-2.6.32-358.114.1.openstack.el6.x86_64.rpm SHA-256: 868ee065068f2b9ef7e6c92f030eca7fe5de718ef0a72635e6ea1654965eead8

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • openshift.com
  • developers.redhat.com
  • connect.redhat.com

About

  • Red Hat Subscription Value
  • About Red Hat
  • Red Hat Jobs
Copyright © 2018 Red Hat, Inc.
  • Privacy Statement
  • Customer Portal Terms of Use
  • All Policies and Guidelines
Red Hat Summit
Twitter Facebook Google+