Critical Kernel Update - Red Hat Enterprise
SO: RHEL 5.x.
Type: Kernel
Importance: have security impact
How to Update:# yum update
# reboot
You should check after upgrade if you have he new kernel version by typing:
# uname -mrs
Security fixes:
a) A missing capability check was found in the Linux kernel do_change_type routine. This could allow a local unprivileged user to gain privileged access or cause a denial of service. (CVE-2008-2931, Important)
b) A flaw was found in the Linux kernel Direct-IO implementation. This could allow a local unprivileged user to cause a denial of service. (CVE-2007-6716, Important)
c) Tobias Klein reported a missing check in the Linux kernel Open Sound System (OSS) implementation. This deficiency could lead to a possible information leak. (CVE-2008-3272, Moderate)
d) a deficiency was found in the Linux kernel virtual filesystem (VFS) implementation. This could allow a local unprivileged user to attempt file creation within deleted directories, possibly causing a denial of service. (CVE-2008-3275, Moderate)
e) A flaw was found in the Linux kernel tmpfs implementation. This could allow a local unprivileged user to read sensitive information from the kernel. (CVE-2007-6417, Moderate)
Bug fix
a) A kernel crash may have occurred on heavily-used Samba servers after 24 to 48 hours of use.
b) On certain systems, if multiple InfiniBand queue pairs simultaneously fell into an error state, an overrun may have occurred, stopping traffic.
c) With bridging, when forward delay was set to zero, setting an interface to the forwarding state was delayed by one or possibly two timers, depending on whether STP was enabled. This may have caused long delays in moving an interface to the forwarding state. This issue caused packet loss when migrating virtual machines, preventing them from being migrated without interrupting applications.
11:11 AM | Tags: kernel, security | 0 Comments
Recovering the root password from the boot loader (GRUB)
When GRUB loads up, select the Red Hat Linux entry on the GRUB menu and then press "e" to edit the boot configuration.
Locate a line like this:
kernel /boot/vmlinuz-x.x.xx-x.xxx root=LABEL=/hdc
- type the number '1' at the end.
Doing so boots the computer into run level 1- single user mode you will automatically be logged in as root.
Type 'passwd' at the prompt, now you can enter a new password here.
4:55 AM | Tags: GRUB, kernel, linux, security | 0 Comments
Upgrade Kernel without Reboot using Ksplice
After kernel security patching or upgrade, Linux should be rebooted.
Ksplice is a GPL 2 Linux patch that provides Linux kernel security update and upgrades without reboot.
Tested on: kernel from 2.6.8 to actual version 2.6.25 and on Debain, Ubuntu, RHEl, Gentoo and other Linux distros.
Ksplice Download, Usage Examples and Documentation
2:51 PM | Tags: kernel, linux | 0 Comments
Ramback - Use a Terabyte of RAM
Ramback is a new kernel patch. An experimental new design for linux virtual memory system turn a large amount of system RAM into a fast RAM disk with automatic sync to magnetic media.
Read more
12:33 PM | Tags: kernel, linux | 0 Comments