-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2010-16826 2010-10-28 05:05:01 --------------------------------------------------------------------------------
Name : kernel Product : Fedora 14 Version : 2.6.35.6 Release : 48.fc14 URL : http://www.kernel.org/ Summary : The Linux kernel Description : The kernel package contains the Linux kernel (vmlinuz), the core of any Linux operating system. The kernel handles the basic functions of the operating system: memory allocation, process allocation, device input and output, etc. -------------------------------------------------------------------------------- Update Information: Fix several important security issues. Also fixes suspend on some systems with TPM chips, enables additional Ricoh SDHC adapters, and fixes a problem with the error message printed when an Intel IOMMU gets disabled. -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 22 2010 Chuck Ebbert <[email protected]> 2.6.35.6-48 - drm-i915-sanity-check-pread-pwrite.patch; fix CVE-2010-2962, arbitrary kernel memory write via i915 GEM ioctl - kvm-fix-fs-gs-reload-oops-with-invalid-ldt.patch; fix CVE-2010-3698, kvm: invalid selector in fs/gs causes kernel panic - v4l1-fix-32-bit-compat-microcode-loading-translation.patch; fixes CVE-2010-2963, v4l: VIDIOCSMICROCODE arbitrary write * Fri Oct 22 2010 Kyle McMartin <[email protected]> 2.6.35.6-47 - tpm-autodetect-itpm-devices.patch: Auto-fix TPM issues on various laptops which prevented suspend/resume. - depessimize-rds_copy_page_user.patch: Fix CVE-2010-3904, local privilege escalation via RDS protocol. -------------------------------------------------------------------------------- References: [ 1 ] Bug #637688 - CVE-2010-2962 kernel: arbitrary kernel memory write via i915 GEM ioctl https://bugzilla.redhat.com/show_bug.cgi?id=637688 [ 2 ] Bug #642465 - CVE-2010-2963 kernel: v4l: VIDIOCSMICROCODE arbitrary write https://bugzilla.redhat.com/show_bug.cgi?id=642465 [ 3 ] Bug #639879 - CVE-2010-3698 kvm: invalid selector in fs/gs causes kernel panic https://bugzilla.redhat.com/show_bug.cgi?id=639879 [ 4 ] Bug #642896 - CVE-2010-3904 RDS sockets local privilege escalation https://bugzilla.redhat.com/show_bug.cgi?id=642896 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update kernel' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list [email protected] https://admin.fedoraproject.org/mailman/listinfo/package-announce
