Hide Forgot
A flaw was found in the kernels handling of ceph authentication tickets. The auth reply could be returned to a client unvalidated.
Statement: This issue did not affect the versions of the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6, 7.0 and Red Hat Enterprise MRG 2 (as they did not include support for this feature).
Upstream fixes: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c27a3e4d667fdcad3db7b104f75659478e0c68d8
The tracking bug [Engineeringbug 1142287] has been closed as dupe, being tracked in EngineeringBZ 1142285.
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2014-6418