MGASA-2014-0265
Dashboard / Vulnerabilities / MGASA-2014-0265
MGASA-2014-0265
Summary: Updated kernel packages fixes security vulnerabilities.
Details: Updated kernel packages fixes security vulnerabilities. The kernel has been updated to the upstream 3.12.21 longterm kernel, and fixes the following security issues: media-device: fix infoleak in ioctl media_enum_entities() (CVE-2014-1739) The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification. (CVE-2014-3153) kernel/auditsc.c in the Linux kernel through 3.14.5, when CONFIG_AUDITSYSCALL is enabled with certain syscall rules, allows local users to obtain potentially sensitive single-bit values from kernel memory or cause a denial of service (OOPS) via a large value of a syscall number. To avoid this and other issues CONFIG_AUDITSYSCALL has been disabled. (CVE-2014-3917) Other changes: iwlwifi: mvm: disable beacon filtering ALSA: hda - Fix onboard audio on Intel H97/Z97 chipsets For other upstream changes, see the referenced changelog.
References: https://advisories.mageia.org/MGASA-2014-0265.html, https://bugs.mageia.org/show_bug.cgi?id=13449, https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.12.21
Affected packages
Package
Name: kernel
Purl: pkg:rpm/mageia/kernel?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
