--------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: New kernel fixes local security issues Advisory ID: RHSA-2002:205-15 Issue date: 2002-09-20 Updated on: 2002-10-15 Product: Red Hat Linux Keywords: Cross references: Obsoletes: RHEA-2002:082 --------------------------------------------------------------------- 1. Topic: A new errata kernel based on the 2.4.18 kernel is available for Red Hat Linux 7.1 and Red Hat Linux 7.2 users. This is a major version change compared to the previous errata kernel for these releases (2.4.9-34). 2. Relevant releases/architectures: Red Hat Linux 7.1 - alpha, athlon, i386, i586, i686, ia64 Red Hat Linux 7.2 - athlon, i386, i586, i686, ia64 3. Problem description: The Linux kernel handles the basic functions of the operating system. A security code audit of the 2.4 kernel found a number of possible local security vulnerabilities. These vulnerabilities may allow a local user to obtain elevated (root) privileges, however no exploits are known to exist at the time of this errata release. Changes in the errata 2.4.18 kernel include the addition of the intermezzo file system, the ComX serial port driver, the PC bit ISDN driver, and the generic ISDN layer. Also, several USB drivers and firewire drivers have been added and many other device drivers have been updated. Other features of the 2.4.18 errata kernel include a much-improved VM subsystem, better interactive performance, and support for new hardware, such as USB2 devices and large IDE disks. A full description of the updated kernel can be found in the kernel changelogs at http://www.kernelnewbies.org/changelogs. IMPORTANT: For alpha and ia64 architectures, kernel version 2.4.9-40 is provided instead of 2.4.18. This errata kernel contains important backported security fixes. NOTE: As with the 8.0 release, IDE DMA on CD-ROM drives is disabled by default. If you are sure that your CD-ROM drive is capable of IDE DMA, place the following line in the /etc/modules.conf file: options ide-cd dma=1 All users of Red Hat Linux 7.1 and 7.2 should update to these errata packages. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. The procedure for upgrading the kernel manually is documented at: http://www.redhat.com/support/docs/howto/kernel-upgrade/ Please read the directions for your architecture carefully before proceeding with the kernel upgrade. Please note that this update is also available via Red Hat Network. Many people find this to be an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. Note that you need to select the kernel explicitly on default configurations of up2date. 5. RPMs required: Red Hat Linux 7.1: SRPMS: ftp://updates.redhat.com/7.1/en/os/SRPMS/kernel-2.4.18-17.7.x.src.rpm ftp://updates.redhat.com/7.1/en/os/SRPMS/iptables-1.2.5-3.src.rpm ftp://updates.redhat.com/7.1/en/os/SRPMS/MAKEDEV-3.3-4.src.rpm ftp://updates.redhat.com/7.1/en/os/SRPMS/hwcrypto-1.0-3.src.rpm ftp://updates.redhat.com/7.1/en/os/SRPMS/modutils-2.4.18-3.7x.src.rpm ftp://updates.redhat.com/7.1/en/os/SRPMS/kernel-utils-2.4-8.13.7.2.src.rpm ftp://updates.redhat.com/7.1/en/os/SRPMS/kernel-2.4.9-40.src.rpm alpha: ftp://updates.redhat.com/7.1/en/os/alpha/iptables-1.2.5-3.alpha.rpm ftp://updates.redhat.com/7.1/en/os/alpha/iptables-ipv6-1.2.5-3.alpha.rpm ftp://updates.redhat.com/7.1/en/os/alpha/MAKEDEV-3.3-4.alpha.rpm ftp://updates.redhat.com/7.1/en/os/alpha/dev-3.3-4.alpha.rpm ftp://updates.redhat.com/7.1/en/os/alpha/modutils-2.4.18-3.7x.alpha.rpm ftp://updates.redhat.com/7.1/en/os/alpha/modutils-devel-2.4.18-3.7x.alpha.rpm ftp://updates.redhat.com/7.1/en/os/alpha/kernel-utils-2.4-8.13.7.2.alpha.rpm ftp://updates.redhat.com/7.1/en/os/alpha/kernel-2.4.9-40.alpha.rpm ftp://updates.redhat.com/7.1/en/os/alpha/kernel-smp-2.4.9-40.alpha.rpm ftp://updates.redhat.com/7.1/en/os/alpha/kernel-source-2.4.9-40.alpha.rpm ftp://updates.redhat.com/7.1/en/os/alpha/kernel-doc-2.4.9-40.alpha.rpm ftp://updates.redhat.com/7.1/en/os/alpha/kernel-BOOT-2.4.9-40.alpha.rpm athlon: ftp://updates.redhat.com/7.1/en/os/athlon/kernel-2.4.18-17.7.x.athlon.rpm ftp://updates.redhat.com/7.1/en/os/athlon/kernel-smp-2.4.18-17.7.x.athlon.rpm i386: ftp://updates.redhat.com/7.1/en/os/i386/kernel-2.4.18-17.7.x.i386.rpm ftp://updates.redhat.com/7.1/en/os/i386/kernel-source-2.4.18-17.7.x.i386.rpm ftp://updates.redhat.com/7.1/en/os/i386/kernel-doc-2.4.18-17.7.x.i386.rpm ftp://updates.redhat.com/7.1/en/os/i386/kernel-BOOT-2.4.18-17.7.x.i386.rpm ftp://updates.redhat.com/7.1/en/os/i386/iptables-1.2.5-3.i386.rpm ftp://updates.redhat.com/7.1/en/os/i386/iptables-ipv6-1.2.5-3.i386.rpm ftp://updates.redhat.com/7.1/en/os/i386/MAKEDEV-3.3-4.i386.rpm ftp://updates.redhat.com/7.1/en/os/i386/hwcrypto-1.0-3.i386.rpm ftp://updates.redhat.com/7.1/en/os/i386/dev-3.3-4.i386.rpm ftp://updates.redhat.com/7.1/en/os/i386/modutils-2.4.18-3.7x.i386.rpm ftp://updates.redhat.com/7.1/en/os/i386/modutils-devel-2.4.18-3.7x.i386.rpm ftp://updates.redhat.com/7.1/en/os/i386/kernel-utils-2.4-8.13.7.2.i386.rpm i586: ftp://updates.redhat.com/7.1/en/os/i586/kernel-2.4.18-17.7.x.i586.rpm ftp://updates.redhat.com/7.1/en/os/i586/kernel-smp-2.4.18-17.7.x.i586.rpm i686: ftp://updates.redhat.com/7.1/en/os/i686/kernel-2.4.18-17.7.x.i686.rpm ftp://updates.redhat.com/7.1/en/os/i686/kernel-smp-2.4.18-17.7.x.i686.rpm ftp://updates.redhat.com/7.1/en/os/i686/kernel-bigmem-2.4.18-17.7.x.i686.rpm ftp://updates.redhat.com/7.1/en/os/i686/kernel-debug-2.4.18-17.7.x.i686.rpm ia64: ftp://updates.redhat.com/7.1/en/os/ia64/iptables-1.2.5-3.ia64.rpm ftp://updates.redhat.com/7.1/en/os/ia64/iptables-ipv6-1.2.5-3.ia64.rpm ftp://updates.redhat.com/7.1/en/os/ia64/MAKEDEV-3.3-4.ia64.rpm ftp://updates.redhat.com/7.1/en/os/ia64/dev-3.3-4.ia64.rpm ftp://updates.redhat.com/7.1/en/os/ia64/modutils-2.4.18-3.7x.ia64.rpm ftp://updates.redhat.com/7.1/en/os/ia64/modutils-devel-2.4.18-3.7x.ia64.rpm ftp://updates.redhat.com/7.1/en/os/ia64/kernel-2.4.9-40.ia64.rpm ftp://updates.redhat.com/7.1/en/os/ia64/kernel-smp-2.4.9-40.ia64.rpm ftp://updates.redhat.com/7.1/en/os/ia64/kernel-source-2.4.9-40.ia64.rpm ftp://updates.redhat.com/7.1/en/os/ia64/kernel-doc-2.4.9-40.ia64.rpm Red Hat Linux 7.2: SRPMS: ftp://updates.redhat.com/7.2/en/os/SRPMS/kernel-2.4.18-17.7.x.src.rpm ftp://updates.redhat.com/7.2/en/os/SRPMS/iptables-1.2.5-3.src.rpm ftp://updates.redhat.com/7.2/en/os/SRPMS/MAKEDEV-3.3-4.src.rpm ftp://updates.redhat.com/7.2/en/os/SRPMS/hwcrypto-1.0-3.src.rpm ftp://updates.redhat.com/7.2/en/os/SRPMS/modutils-2.4.18-3.7x.src.rpm ftp://updates.redhat.com/7.2/en/os/SRPMS/kernel-utils-2.4-8.13.7.2.src.rpm ftp://updates.redhat.com/7.2/en/os/SRPMS/kernel-2.4.9-40.src.rpm athlon: ftp://updates.redhat.com/7.2/en/os/athlon/kernel-2.4.18-17.7.x.athlon.rpm ftp://updates.redhat.com/7.2/en/os/athlon/kernel-smp-2.4.18-17.7.x.athlon.rpm i386: ftp://updates.redhat.com/7.2/en/os/i386/kernel-2.4.18-17.7.x.i386.rpm ftp://updates.redhat.com/7.2/en/os/i386/kernel-source-2.4.18-17.7.x.i386.rpm ftp://updates.redhat.com/7.2/en/os/i386/kernel-doc-2.4.18-17.7.x.i386.rpm ftp://updates.redhat.com/7.2/en/os/i386/kernel-BOOT-2.4.18-17.7.x.i386.rpm ftp://updates.redhat.com/7.2/en/os/i386/iptables-1.2.5-3.i386.rpm ftp://updates.redhat.com/7.2/en/os/i386/iptables-ipv6-1.2.5-3.i386.rpm ftp://updates.redhat.com/7.2/en/os/i386/MAKEDEV-3.3-4.i386.rpm ftp://updates.redhat.com/7.2/en/os/i386/hwcrypto-1.0-3.i386.rpm ftp://updates.redhat.com/7.2/en/os/i386/dev-3.3-4.i386.rpm ftp://updates.redhat.com/7.2/en/os/i386/modutils-2.4.18-3.7x.i386.rpm ftp://updates.redhat.com/7.2/en/os/i386/modutils-devel-2.4.18-3.7x.i386.rpm ftp://updates.redhat.com/7.2/en/os/i386/kernel-utils-2.4-8.13.7.2.i386.rpm i586: ftp://updates.redhat.com/7.2/en/os/i586/kernel-2.4.18-17.7.x.i586.rpm ftp://updates.redhat.com/7.2/en/os/i586/kernel-smp-2.4.18-17.7.x.i586.rpm i686: ftp://updates.redhat.com/7.2/en/os/i686/kernel-2.4.18-17.7.x.i686.rpm ftp://updates.redhat.com/7.2/en/os/i686/kernel-smp-2.4.18-17.7.x.i686.rpm ftp://updates.redhat.com/7.2/en/os/i686/kernel-bigmem-2.4.18-17.7.x.i686.rpm ftp://updates.redhat.com/7.2/en/os/i686/kernel-debug-2.4.18-17.7.x.i686.rpm ia64: ftp://updates.redhat.com/7.2/en/os/ia64/iptables-1.2.5-3.ia64.rpm ftp://updates.redhat.com/7.2/en/os/ia64/iptables-ipv6-1.2.5-3.ia64.rpm ftp://updates.redhat.com/7.2/en/os/ia64/MAKEDEV-3.3-4.ia64.rpm ftp://updates.redhat.com/7.2/en/os/ia64/dev-3.3-4.ia64.rpm ftp://updates.redhat.com/7.2/en/os/ia64/modutils-2.4.18-3.7x.ia64.rpm ftp://updates.redhat.com/7.2/en/os/ia64/modutils-devel-2.4.18-3.7x.ia64.rpm ftp://updates.redhat.com/7.2/en/os/ia64/kernel-2.4.9-40.ia64.rpm ftp://updates.redhat.com/7.2/en/os/ia64/kernel-smp-2.4.9-40.ia64.rpm ftp://updates.redhat.com/7.2/en/os/ia64/kernel-source-2.4.9-40.ia64.rpm ftp://updates.redhat.com/7.2/en/os/ia64/kernel-doc-2.4.9-40.ia64.rpm 6. Verification: MD5 sum Package Name -------------------------------------------------------------------------- 7a3d80b481167ce07aeddb64e65bff3e 7.1/en/os/SRPMS/MAKEDEV-3.3-4.src.rpm 49189033d3aabafd23eba5439e3b0f97 7.1/en/os/SRPMS/hwcrypto-1.0-3.src.rpm 75f0a1cd65f95580239f88e03ab04623 7.1/en/os/SRPMS/iptables-1.2.5-3.src.rpm d0cf8ef64412c78c9d32da9d0cb9850d 7.1/en/os/SRPMS/kernel-2.4.18-17.7.x.src.rpm 7ae973d14afd4d1fa480cd5652651a8a 7.1/en/os/SRPMS/kernel-2.4.9-40.src.rpm 5390115158168e5e8e5d6fd90e3d1344 7.1/en/os/SRPMS/kernel-utils-2.4-8.13.7.2.src.rpm 0414620fa83d72ffd9f128be2e4bf430 7.1/en/os/SRPMS/modutils-2.4.18-3.7x.src.rpm 29d0771474e2ae9f877ed890b0e7c730 7.1/en/os/alpha/MAKEDEV-3.3-4.alpha.rpm 769b1f8cf0ec3e404ba8c055cb9e2e64 7.1/en/os/alpha/dev-3.3-4.alpha.rpm faa55a585ae9e84eb5b2407f91a5aefd 7.1/en/os/alpha/iptables-1.2.5-3.alpha.rpm 4e51115bc4dbab708c6084678423e634 7.1/en/os/alpha/iptables-ipv6-1.2.5-3.alpha.rpm 24265eb70cf408b132d787de7beb23bc 7.1/en/os/alpha/kernel-2.4.9-40.alpha.rpm bba867d5e20c1d39f6d4d8a1dcde427b 7.1/en/os/alpha/kernel-BOOT-2.4.9-40.alpha.rpm de2b64811e68e30bd99d5d6912131e1f 7.1/en/os/alpha/kernel-doc-2.4.9-40.alpha.rpm 324c1df33969fe4eef80e11ad2279258 7.1/en/os/alpha/kernel-smp-2.4.9-40.alpha.rpm acc0468afb4769887f300ead030b9653 7.1/en/os/alpha/kernel-source-2.4.9-40.alpha.rpm 1bdd50916955e8215758db837c4138b0 7.1/en/os/alpha/kernel-utils-2.4-8.13.7.2.alpha.rpm db71f242273729a201e01aa1d7c55e6b 7.1/en/os/alpha/modutils-2.4.18-3.7x.alpha.rpm 6f477cc811f9930b1b418621401a0e7d 7.1/en/os/alpha/modutils-devel-2.4.18-3.7x.alpha.rpm 082114a540f7bd692476584e38c6cd5c 7.1/en/os/athlon/kernel-2.4.18-17.7.x.athlon.rpm bd2fa5b6b721caf12dcea357304c008b 7.1/en/os/athlon/kernel-smp-2.4.18-17.7.x.athlon.rpm b5bdf89f6810239c8074f135339c372b 7.1/en/os/i386/MAKEDEV-3.3-4.i386.rpm e1c9bf91a11b6eddb9df51edf5af63cb 7.1/en/os/i386/dev-3.3-4.i386.rpm 92f18477c6b3dd5da4e3babe19a57c13 7.1/en/os/i386/hwcrypto-1.0-3.i386.rpm 11df2613702a118e43564d2ff077621a 7.1/en/os/i386/iptables-1.2.5-3.i386.rpm e31d27e142c6fd23ea8508de07258f5e 7.1/en/os/i386/iptables-ipv6-1.2.5-3.i386.rpm cfdef58820f5d7701f4221c80a7c821b 7.1/en/os/i386/kernel-2.4.18-17.7.x.i386.rpm 145d063537e3a34723d50e611cbd37a8 7.1/en/os/i386/kernel-BOOT-2.4.18-17.7.x.i386.rpm 8d9a20e2f4d82cc262cab928910377fa 7.1/en/os/i386/kernel-doc-2.4.18-17.7.x.i386.rpm 0344cc1d42651916fb91ed7a700f3f90 7.1/en/os/i386/kernel-source-2.4.18-17.7.x.i386.rpm 9d8fcfd1dcb2a3efed1519c56498cd71 7.1/en/os/i386/kernel-utils-2.4-8.13.7.2.i386.rpm cddd8196a38dbff1a8e34429415670fb 7.1/en/os/i386/modutils-2.4.18-3.7x.i386.rpm 8c663b5015ba81b2ebef80307a37885f 7.1/en/os/i386/modutils-devel-2.4.18-3.7x.i386.rpm 576ceca80b035a10b942e6feb217c055 7.1/en/os/i586/kernel-2.4.18-17.7.x.i586.rpm d9d2b3fa23ee4733b35fd730e9553625 7.1/en/os/i586/kernel-smp-2.4.18-17.7.x.i586.rpm 3a3afd67620fc36de17876629398dceb 7.1/en/os/i686/kernel-2.4.18-17.7.x.i686.rpm fe9a658e1e22defc3cf5e2134646a6eb 7.1/en/os/i686/kernel-bigmem-2.4.18-17.7.x.i686.rpm 158c941a9b430581a7bcd23ec1398052 7.1/en/os/i686/kernel-debug-2.4.18-17.7.x.i686.rpm f9e11d26c2ca35ef403656be882fb592 7.1/en/os/i686/kernel-smp-2.4.18-17.7.x.i686.rpm 31d745681c9e53b81147f5fc968a11c4 7.1/en/os/ia64/MAKEDEV-3.3-4.ia64.rpm 647cae518850399228a68da079b0cb7a 7.1/en/os/ia64/dev-3.3-4.ia64.rpm 9c3d09166d9a854028ecf2fe120a0824 7.1/en/os/ia64/iptables-1.2.5-3.ia64.rpm 7a498fd5b5e803ceb6afc65f9da9bd78 7.1/en/os/ia64/iptables-ipv6-1.2.5-3.ia64.rpm 35c17902e921f84e07202bc36c77bcbd 7.1/en/os/ia64/kernel-2.4.9-40.ia64.rpm 71757ded05ea9ec37fc81ce7459df3f3 7.1/en/os/ia64/kernel-doc-2.4.9-40.ia64.rpm cb4a9c26a725e65169e5e82638a6f0be 7.1/en/os/ia64/kernel-smp-2.4.9-40.ia64.rpm 785bafa5b9b56338562f7a7b6f6db991 7.1/en/os/ia64/kernel-source-2.4.9-40.ia64.rpm b2881ce4c011e08d32e817499c813974 7.1/en/os/ia64/modutils-2.4.18-3.7x.ia64.rpm d1fbc32d6d55dad80129e0bef7360168 7.1/en/os/ia64/modutils-devel-2.4.18-3.7x.ia64.rpm 7a3d80b481167ce07aeddb64e65bff3e 7.2/en/os/SRPMS/MAKEDEV-3.3-4.src.rpm 49189033d3aabafd23eba5439e3b0f97 7.2/en/os/SRPMS/hwcrypto-1.0-3.src.rpm 75f0a1cd65f95580239f88e03ab04623 7.2/en/os/SRPMS/iptables-1.2.5-3.src.rpm d0cf8ef64412c78c9d32da9d0cb9850d 7.2/en/os/SRPMS/kernel-2.4.18-17.7.x.src.rpm 7ae973d14afd4d1fa480cd5652651a8a 7.2/en/os/SRPMS/kernel-2.4.9-40.src.rpm 5390115158168e5e8e5d6fd90e3d1344 7.2/en/os/SRPMS/kernel-utils-2.4-8.13.7.2.src.rpm 0414620fa83d72ffd9f128be2e4bf430 7.2/en/os/SRPMS/modutils-2.4.18-3.7x.src.rpm 082114a540f7bd692476584e38c6cd5c 7.2/en/os/athlon/kernel-2.4.18-17.7.x.athlon.rpm bd2fa5b6b721caf12dcea357304c008b 7.2/en/os/athlon/kernel-smp-2.4.18-17.7.x.athlon.rpm b5bdf89f6810239c8074f135339c372b 7.2/en/os/i386/MAKEDEV-3.3-4.i386.rpm e1c9bf91a11b6eddb9df51edf5af63cb 7.2/en/os/i386/dev-3.3-4.i386.rpm 92f18477c6b3dd5da4e3babe19a57c13 7.2/en/os/i386/hwcrypto-1.0-3.i386.rpm 11df2613702a118e43564d2ff077621a 7.2/en/os/i386/iptables-1.2.5-3.i386.rpm e31d27e142c6fd23ea8508de07258f5e 7.2/en/os/i386/iptables-ipv6-1.2.5-3.i386.rpm cfdef58820f5d7701f4221c80a7c821b 7.2/en/os/i386/kernel-2.4.18-17.7.x.i386.rpm 145d063537e3a34723d50e611cbd37a8 7.2/en/os/i386/kernel-BOOT-2.4.18-17.7.x.i386.rpm 8d9a20e2f4d82cc262cab928910377fa 7.2/en/os/i386/kernel-doc-2.4.18-17.7.x.i386.rpm 0344cc1d42651916fb91ed7a700f3f90 7.2/en/os/i386/kernel-source-2.4.18-17.7.x.i386.rpm 9d8fcfd1dcb2a3efed1519c56498cd71 7.2/en/os/i386/kernel-utils-2.4-8.13.7.2.i386.rpm cddd8196a38dbff1a8e34429415670fb 7.2/en/os/i386/modutils-2.4.18-3.7x.i386.rpm 8c663b5015ba81b2ebef80307a37885f 7.2/en/os/i386/modutils-devel-2.4.18-3.7x.i386.rpm 576ceca80b035a10b942e6feb217c055 7.2/en/os/i586/kernel-2.4.18-17.7.x.i586.rpm d9d2b3fa23ee4733b35fd730e9553625 7.2/en/os/i586/kernel-smp-2.4.18-17.7.x.i586.rpm 3a3afd67620fc36de17876629398dceb 7.2/en/os/i686/kernel-2.4.18-17.7.x.i686.rpm fe9a658e1e22defc3cf5e2134646a6eb 7.2/en/os/i686/kernel-bigmem-2.4.18-17.7.x.i686.rpm 158c941a9b430581a7bcd23ec1398052 7.2/en/os/i686/kernel-debug-2.4.18-17.7.x.i686.rpm f9e11d26c2ca35ef403656be882fb592 7.2/en/os/i686/kernel-smp-2.4.18-17.7.x.i686.rpm 31d745681c9e53b81147f5fc968a11c4 7.2/en/os/ia64/MAKEDEV-3.3-4.ia64.rpm 647cae518850399228a68da079b0cb7a 7.2/en/os/ia64/dev-3.3-4.ia64.rpm 9c3d09166d9a854028ecf2fe120a0824 7.2/en/os/ia64/iptables-1.2.5-3.ia64.rpm 7a498fd5b5e803ceb6afc65f9da9bd78 7.2/en/os/ia64/iptables-ipv6-1.2.5-3.ia64.rpm 35c17902e921f84e07202bc36c77bcbd 7.2/en/os/ia64/kernel-2.4.9-40.ia64.rpm 71757ded05ea9ec37fc81ce7459df3f3 7.2/en/os/ia64/kernel-doc-2.4.9-40.ia64.rpm cb4a9c26a725e65169e5e82638a6f0be 7.2/en/os/ia64/kernel-smp-2.4.9-40.ia64.rpm 785bafa5b9b56338562f7a7b6f6db991 7.2/en/os/ia64/kernel-source-2.4.9-40.ia64.rpm b2881ce4c011e08d32e817499c813974 7.2/en/os/ia64/modutils-2.4.18-3.7x.ia64.rpm d1fbc32d6d55dad80129e0bef7360168 7.2/en/os/ia64/modutils-devel-2.4.18-3.7x.ia64.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: http://www.redhat.com/about/contact/pgpkey.html You can verify each package with the following command: rpm --checksig <filename> If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg <filename> 7. References: http://www.kernel.org/pub/linux/kernel/v2.4/ Copyright(c) 2000, 2001, 2002 Red Hat, Inc. _______________________________________________ Redhat-watch-list mailing list To unsubscribe, visit: https://listman.redhat.com/mailman/listinfo/redhat-watch-list