Summary
The remote host is missing an update to kernel
announced via advisory FEDORA-2009-8684.
Solution
Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update kernel' at the command line.
For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
https://secure1.securityspace.com/smysecure/catid.html?in=FEDORA-2009-8684
Insight
Update Information:
Fix oops in clock_nanosleep syscall which allows an ordinary user to cause a null ptr dereference in the kernel. CVE-2009-2767. Fixes BUG_ON() in the intel gem page fault code breaking GNOME Shell.
ChangeLog:
* Sat Aug 15 2009 Kyle McMartin 2.6.29.6-217.2.8
- CVE-2009-2767: Fix clock_nanosleep NULL ptr deref.
* Fri Aug 14 2009 Kyle McMartin 2.6.29.6-217.2.7
- CVE-2009-2692: Fix sock sendpage NULL ptr deref.
* Thu Aug 13 2009 Kristian Høgsberg - 2.6.29.6-217.2.6 - Backport 0e7ddf7e to fix bad BUG_ON() in i915 gem fence management code. Adds drm-i915-gem-bad-bug-on.patch, fixes #514091.
* Wed Aug 12 2009 John W. Linville 2.6.29.6-217.2.5 - iwlwifi: fix TX queue race
* Mon Aug 10 2009 Jarod Wilson 2.6.29.6-217.2.4
- Add tunable pad threshold support to lirc_imon
- Blacklist all iMON devices in usbhid driver so lirc_imon can bind - Add new device ID to lirc_mceusb (#512483)
- Enable IR transceiver on the HD PVR
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2009-1895, CVE-2009-1897, CVE-2009-2406, CVE-2009-2407, CVE-2009-2692, CVE-2009-2767 -
CVSS Base Score: 7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities