An out-of-bounds memory access flaw was found in the Linux kernel's perf and ftrace subsystems. On a system with syscall perf profiling on (CVE-2014-7825) an unprivileged local user could use this flaw to crash the system. On a system with ftrace syscall tracing on (CVE-2014-7826) an unprivileged local user could use this flaw to crash the system or escalate their privileges on the system. References: http://www.openwall.com/lists/oss-security/2014/11/06/11 Upstream fix: http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=086ba77a6db00ed858ff07451bedee197df868c9 Acknowledgements: Red Hat would like to thank Robert Święcki for reporting these issues.
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1161572]
Statement CVE-2014-7825: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5. This issue does affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 6, 7 and Red Hat Enterprise MRG 2. Future kernel updates for the respective releases may address this issue. Statement CVE-2014-7826: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5. This issue does affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 6, 7 and Red Hat Enterprise MRG 2. Future kernel updates for the respective releases may address this issue. Note that the impact on Red Hat Enterprise Linux 6, 7 and Red Hat Enterprise MRG 2 is limited to local denial of service. Privilege escalation is not possible.
kernel-3.17.3-300.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report.
kernel-3.17.3-200.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
This issue has been addressed in the following products: MRG for RHEL-6 v.2 Via RHSA-2014:1943 https://rhn.redhat.com/errata/RHSA-2014-1943.html
kernel-3.14.27-100.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report.
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2015:0290 https://rhn.redhat.com/errata/RHSA-2015-0290.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2015:0864 https://rhn.redhat.com/errata/RHSA-2015-0864.html