Bug 168925 - CVE-2005-2709 More sysctl flaws
Summary: CVE-2005-2709 More sysctl flaws
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 3
Classification: Red Hat
Component: kernel
Version: 3.0
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Alexander Viro
QA Contact: Brian Brock
URL:
Whiteboard: impact=moderate,reported=20050919,sou...
Keywords: Security
Depends On:
Blocks: 168424
TreeView+ depends on / blocked
 
Reported: 2005-09-21 11:43 UTC by Mark J. Cox
Modified: 2007-11-30 22:07 UTC (History)
10 users (show)

(edit)
Clone Of:
(edit)
Last Closed: 2006-01-19 16:00:32 UTC


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2006:0140 normal SHIPPED_LIVE Important: kernel security update 2006-01-19 05:00:00 UTC

Comment 2 Alexander Viro 2005-09-21 19:12:54 UTC
sysctls go away on network interfaces being removed.  Which includes
not only ppp et.al., but all sorts of tunnels, etc.  IOW, you can
wait for it to happen - in a lot of setups it will.  And in case of
e.g. ipv4 sysctls we are talking about >2Kb allocated on amd64, so
kmalloc() will pick full pages for each (per-interface) set of sysctls...

Comment 3 Ernie Petrides 2005-09-21 20:17:35 UTC
Thanks for the info, Al.  Reassigning.

Comment 11 Peter Martuccelli 2005-11-23 20:35:08 UTC
Patch posted 11/23 - security issue - moving to canfix list.

Comment 12 Ernie Petrides 2005-11-30 07:35:17 UTC
A fix for this problem has just been committed to the RHEL3 U7
patch pool this evening (in kernel version 2.4.21-37.12.EL).


Comment 14 Ernie Petrides 2006-01-11 23:34:36 UTC
A fix for this problem has also been committed to the RHEL3 E7
patch pool this evening (in kernel version 2.4.21-37.0.1.EL).


Comment 16 Red Hat Bugzilla 2006-01-19 16:00:33 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHSA-2006-0140.html



Note You need to log in before you can comment on or make changes to this bug.