Summary
The remote host is missing an update to kernel
announced via advisory FEDORA-2009-10165.
Solution
Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update kernel' at the command line.
For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
https://secure1.securityspace.com/smysecure/catid.html?in=FEDORA-2009-10165
Insight
Update Information:
Update to kernel 2.6.27.35:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.31 http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.32 http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.33 http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.34 http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.35
ChangeLog:
* Sat Sep 26 2009 Chuck Ebbert 2.6.27.35-170.2.94 - Backport appletalk: Fix skb leak when ipddp interface is not loaded (fixes CVE-2009-2903)
* Sat Sep 26 2009 Chuck Ebbert 2.6.27.35-170.2.93 - Backport KVM: x86: Disallow hypercalls for guest callers in rings > 0 (fixes CVE-2009-3290)
* Thu Sep 24 2009 Chuck Ebbert 2.6.27.35-170.2.92 - Linux 2.6.27.35
- Drop merged patches:
linux-2.6-nfsd-report-short-writes-fix.patch
linux-2.6-nfsd-report-short-writes.patch
* Tue Sep 15 2009 Chuck Ebbert 2.6.27.34-170.2.91 - Linux 2.6.27.34
- Drop merged patch: linux-2.6-slub-fix-destroy-by-rcu.patch * Wed Sep 9 2009 Chuck Ebbert 2.6.27.32-170.2.90 - 2.6.27.32 final
- Drop linux-2.6-ocfs2-handle-len-0.patch, added after .32-rc1 * Mon Sep 7 2009 Chuck Ebbert 2.6.27.32-170.2.89.rc1 - Backport fix for b43 on ppc64 to 2.6.27 (#514787) * Sun Sep 6 2009 Chuck Ebbert 2.6.27.32-170.2.88.rc1 - Add patches requested for the next stable release:
linux-2.6-slub-fix-destroy-by-rcu.patch (fixes bug in 2.6.27.29) linux-2.6-ocfs2-handle-len-0.patch (fixes bug in 2.6.27.32-rc1) * Fri Sep 4 2009 Chuck Ebbert 2.6.27.32-170.2.87.rc1 - Copy fix for NFS short write reporting from F-10 2.6.29 kernel (#493500)
References
Severity
Classification
-
CVE CVE-2008-5079, CVE-2009-0065, CVE-2009-1895, CVE-2009-1897, CVE-2009-2406, CVE-2009-2407, CVE-2009-2692, CVE-2009-2847, CVE-2009-2903, CVE-2009-3001, CVE-2009-3002, CVE-2009-3290 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities