RHEL 7 : kernel (RHSA-2015:2152)

high Nessus Plugin ID 86972

Synopsis

The remote Red Hat host is missing one or more security updates.

Description

The remote Redhat Enterprise Linux 7 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2015:2152 advisory.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

* A flaw was found in the way the Linux kernel's file system implementation handled rename operations in which the source was inside and the destination was outside of a bind mount. A privileged user inside a container could use this flaw to escape the bind mount and, potentially, escalate their privileges on the system. (CVE-2015-2925, Important)

* A race condition flaw was found in the way the Linux kernel's IPC subsystem initialized certain fields in an IPC object structure that were later used for permission checking before inserting the object into a globally visible list. A local, unprivileged user could potentially use this flaw to elevate their privileges on the system. (CVE-2015-7613, Important)

* It was found that reporting emulation failures to user space could lead to either a local (CVE-2014-7842) or a L2->L1 (CVE-2010-5313) denial of service. In the case of a local denial of service, an attacker must have access to the MMIO area or be able to access an I/O port. (CVE-2010-5313, CVE-2014-7842, Moderate)

* A flaw was found in the way the Linux kernel's KVM subsystem handled non-canonical addresses when emulating instructions that change the RIP (for example, branches or calls). A guest user with access to an I/O or MMIO region could use this flaw to crash the guest. (CVE-2014-3647, Moderate)

* It was found that the Linux kernel memory resource controller's (memcg) handling of OOM (out of memory) conditions could lead to deadlocks.
An attacker could use this flaw to lock up the system. (CVE-2014-8171, Moderate)

* A race condition flaw was found between the chown and execve system calls. A local, unprivileged user could potentially use this flaw to escalate their privileges on the system. (CVE-2015-3339, Moderate)

* A flaw was discovered in the way the Linux kernel's TTY subsystem handled the tty shutdown phase. A local, unprivileged user could use this flaw to cause a denial of service on the system. (CVE-2015-4170, Moderate)

* A NULL pointer dereference flaw was found in the SCTP implementation.
A local user could use this flaw to cause a denial of service on the system by triggering a kernel panic when creating multiple sockets in parallel while the system did not have the SCTP module loaded. (CVE-2015-5283, Moderate)

* A flaw was found in the way the Linux kernel's perf subsystem retrieved userlevel stack traces on PowerPC systems. A local, unprivileged user could use this flaw to cause a denial of service on the system. (CVE-2015-6526, Moderate)

* A flaw was found in the way the Linux kernel's Crypto subsystem handled automatic loading of kernel modules. A local user could use this flaw to load any installed kernel module, and thus increase the attack surface of the running kernel. (CVE-2013-7421, CVE-2014-9644, Low)

* An information leak flaw was found in the way the Linux kernel changed certain segment registers and thread-local storage (TLS) during a context switch. A local, unprivileged user could use this flaw to leak the user space TLS base address of an arbitrary process. (CVE-2014-9419, Low)

* It was found that the Linux kernel KVM subsystem's sysenter instruction emulation was not sufficient. An unprivileged guest user could use this flaw to escalate their privileges by tricking the hypervisor to emulate a SYSENTER instruction in 16-bit mode, if the guest OS did not initialize the SYSENTER model-specific registers (MSRs). Note: Certified guest operating systems for Red Hat Enterprise Linux with KVM do initialize the SYSENTER MSRs and are thus not vulnerable to this issue when running on a KVM hypervisor. (CVE-2015-0239, Low)

* A flaw was found in the way the Linux kernel handled the securelevel functionality after performing a kexec operation. A local attacker could use this flaw to bypass the security mechanism of the securelevel/secureboot combination. (CVE-2015-7837, Low)

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

http://www.nessus.org/u?1fa68217

http://www.nessus.org/u?8e32462e

https://access.redhat.com/articles/1749293

https://access.redhat.com/errata/RHSA-2015:2152

https://access.redhat.com/security/updates/classification/#important

https://bugzilla.redhat.com/show_bug.cgi?id=1243998

https://bugzilla.redhat.com/show_bug.cgi?id=1249107

https://bugzilla.redhat.com/show_bug.cgi?id=1251331

https://bugzilla.redhat.com/show_bug.cgi?id=1257528

https://bugzilla.redhat.com/show_bug.cgi?id=1268270

https://bugzilla.redhat.com/show_bug.cgi?id=1271759

https://bugzilla.redhat.com/show_bug.cgi?id=1272472

https://bugzilla.redhat.com/show_bug.cgi?id=839466

https://bugzilla.redhat.com/show_bug.cgi?id=1033907

https://bugzilla.redhat.com/show_bug.cgi?id=1033908

https://bugzilla.redhat.com/show_bug.cgi?id=1033910

https://bugzilla.redhat.com/show_bug.cgi?id=1033911

https://bugzilla.redhat.com/show_bug.cgi?id=1034497

https://bugzilla.redhat.com/show_bug.cgi?id=1036792

https://bugzilla.redhat.com/show_bug.cgi?id=1064059

https://bugzilla.redhat.com/show_bug.cgi?id=1076738

https://bugzilla.redhat.com/show_bug.cgi?id=1076769

https://bugzilla.redhat.com/show_bug.cgi?id=1144897

https://bugzilla.redhat.com/show_bug.cgi?id=1163762

https://bugzilla.redhat.com/show_bug.cgi?id=1177260

https://bugzilla.redhat.com/show_bug.cgi?id=1182243

https://bugzilla.redhat.com/show_bug.cgi?id=1184155

https://bugzilla.redhat.com/show_bug.cgi?id=1185469

https://bugzilla.redhat.com/show_bug.cgi?id=1186112

https://bugzilla.redhat.com/show_bug.cgi?id=1186448

https://bugzilla.redhat.com/show_bug.cgi?id=1190546

https://bugzilla.redhat.com/show_bug.cgi?id=1191604

https://bugzilla.redhat.com/show_bug.cgi?id=1198109

https://bugzilla.redhat.com/show_bug.cgi?id=1205258

https://bugzilla.redhat.com/show_bug.cgi?id=1206198

https://bugzilla.redhat.com/show_bug.cgi?id=1209367

https://bugzilla.redhat.com/show_bug.cgi?id=1214030

https://bugzilla.redhat.com/show_bug.cgi?id=1218454

https://bugzilla.redhat.com/show_bug.cgi?id=1218879

https://bugzilla.redhat.com/show_bug.cgi?id=1233284

Plugin Details

Severity: High

ID: 86972

File Name: redhat-RHSA-2015-2152.nasl

Version: 2.28

Type: local

Agent: unix

Published: 11/20/2015

Updated: 11/4/2024

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2015-3288

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:kernel-tools, p-cpe:/a:redhat:enterprise_linux:kernel, p-cpe:/a:redhat:enterprise_linux:kernel-headers, cpe:/o:redhat:enterprise_linux:7, p-cpe:/a:redhat:enterprise_linux:kernel-tools-libs-devel, p-cpe:/a:redhat:enterprise_linux:kernel-debug-devel, p-cpe:/a:redhat:enterprise_linux:kernel-kdump, p-cpe:/a:redhat:enterprise_linux:kernel-bootwrapper, p-cpe:/a:redhat:enterprise_linux:kernel-tools-libs, p-cpe:/a:redhat:enterprise_linux:python-perf, p-cpe:/a:redhat:enterprise_linux:kernel-kdump-devel, p-cpe:/a:redhat:enterprise_linux:kernel-devel, p-cpe:/a:redhat:enterprise_linux:kernel-debug, p-cpe:/a:redhat:enterprise_linux:perf

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 11/19/2015

Vulnerability Publication Date: 11/10/2014

Reference Information

CVE: CVE-2010-5313, CVE-2013-7421, CVE-2014-3647, CVE-2014-7842, CVE-2014-8171, CVE-2014-9419, CVE-2014-9644, CVE-2015-0239, CVE-2015-2925, CVE-2015-3288, CVE-2015-3339, CVE-2015-4170, CVE-2015-5283, CVE-2015-6526, CVE-2015-7553, CVE-2015-7613, CVE-2015-7837, CVE-2015-8215, CVE-2016-0774

CWE: 20, 200, 22, 248, 362, 391, 456, 665, 667, 732, 749, 833, 835

RHSA: 2015:2152