Linux Today: Linux News On Internet Time.

More on LinuxToday

Advisories, June 27, 2006

Jun 28, 2006, 04:45 (0 Talkback[s])

Debian GNU/Linux

Debian Security Advisory DSA 1103-1 Dann Frazier, Troy Heber
June 27th, 2006

Package : kernel-source-2.6.8
Vulnerability : several
Problem-Type : local/remote
Debian-specific: no
CVE ID : CVE-2005-3359 CVE-2006-0038 CVE-2006-0039 CVE-2006-0456 CVE-2006-0554 CVE-2006-0555 CVE-2006-0557 CVE-2006-0558 CVE-2006-0741 CVE-2006-0742 CVE-2006-0744 CVE-2006-1056 CVE-2006-1242 CVE-2006-1368 CVE-2006-1523 CVE-2006-1524 CVE-2006-1525 CVE-2006-1857 CVE-2006-1858 CVE-2006-1863 CVE-2006-1864 CVE-2006-2271 CVE-2006-2272 CVE-2006-2274

Several local and remote vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or the execution of arbitrary code. The Common Vulnerabilities and Exposures project identifies the following problems:


Franz Filz discovered that some socket calls permit causing inconsistent reference counts on loadable modules, which allows local users to cause a denial of service.


"Solar Designer" discovered that arithmetic computations in netfilter's do_replace() function can lead to a buffer overflow and the execution of arbitrary code. However, the operation requires CAP_NET_ADMIN privileges, which is only an issue in virtualization systems or fine grained access control systems.


"Solar Designer" discovered a race condition in netfilter's do_add_counters() function, which allows information disclosure of kernel memory by exploiting a race condition. Likewise, it requires CAP_NET_ADMIN privileges.


David Howells discovered that the s390 assembly version of the strnlen_user() function incorrectly returns some string size values.


It was discovered that the ftruncate() function of XFS can expose unallocated, which allows information disclosure of previously deleted files.


It was discovered that some NFS file operations on handles mounted with O_DIRECT can force the kernel into a crash.


It was discovered that the code to configure memory policies allows tricking the kernel into a crash, thus allowing denial of service.


It was discovered by Cliff Wickman that perfmon for the IA64 architecture allows users to trigger a BUG() assert, which allows denial of service.


Intel EM64T systems were discovered to be susceptible to a local DoS due to an endless recursive fault related to a bad elf entry address.


Alan and Gareth discovered that the ia64 platform had an incorrectly declared die_if_kernel() function as "does never return" which could be exploited by a local attacker resulting in a kernel crash.


The Linux kernel did not properly handle uncanonical return addresses on Intel EM64T CPUs, reporting exceptions in the SYSRET instead of the next instruction, causing the kernel exception handler to run on the user stack with the wrong GS. This may result in a DoS due to a local user changing the frames.


AMD64 machines (and other 7th and 8th generation AuthenticAMD processors) were found to be vulnerable to sensitive information leakage, due to how they handle saving and restoring the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending. This allows a process to determine portions of the state of floating point instructions of other processes.


Marco Ivaldi discovered that there was an unintended information disclosure allowing remote attackers to bypass protections against Idle Scans (nmap -sI) by abusing the ID field of IP packets and bypassing the zero IP ID in DF packet countermeasure. This was a result of the ip_push_pending_frames function improperly incremented the IP ID field when sending a RST after receiving unsolicited TCP SYN-ACK packets.


Shaun Tancheff discovered a buffer overflow (boundry condition error) in the USB Gadget RNDIS implementation allowing remote attackers to cause a DoS. While creating a reply message, the driver allocated memory for the reply data, but not for the reply structure. The kernel fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer. Attackers could crash the system, or possibly execute arbitrary machine code.


Oleg Nesterov reported an unsafe BUG_ON call in signal.c which was introduced by RCU signal handling. The BUG_ON code is protected by siglock while the code in switch_exit_pids() uses tasklist_lock. It may be possible for local users to exploit this to initiate a denial of service attack (DoS).


Hugh Dickins discovered an issue in the madvise_remove function wherein file and mmap restrictions are not followed, allowing local users to bypass IPC permissions and replace portions of readonly tmpfs files with zeroes.


Alexandra Kossovsky reported a NULL pointer dereference condition in ip_route_input() that can be triggered by a local user by requesting a route for a multicast IP address, resulting in a denial of service (panic).


Vlad Yasevich reported a data validation issue in the SCTP subsystem that may allow a remote user to overflow a buffer using a badly formatted HB-ACK chunk, resulting in a denial of service.


Vlad Yasevich reported a bug in the bounds checking code in the SCTP subsystem that may allow a remote attacker to trigger a denial of service attack when rounded parameter lengths are used to calculate parameter lengths instead of the actual values.


Mark Mosely discovered that chroots residing on an CIFS share can be escaped with specially crafted "cd" sequences.


Mark Mosely discovered that chroots residing on an SMB share can be escaped with specially crafted "cd" sequences.


The "Mu security team" discovered that carefully crafted ECNE chunks can cause a kernel crash by accessing incorrect state stable entries in the SCTP networking subsystem, which allows denial of service.


The "Mu security team" discovered that fragmented SCTP control chunks can trigger kernel panics, which allows for denial of service attacks.


It was discovered that SCTP packets with two initial bundled data packets can lead to infinite recursion, which allows for denial of service attacks.

The following matrix explains which kernel version for which architecture fix the problems mentioned above:

                                 Debian 3.1 (sarge)
     Source                      2.6.8-16sarge3
     Alpha architecture          2.6.8-16sarge3
     HP Precision architecture   2.6.8-6sarge3
     Intel IA-32 architecture    2.6.8-16sarge3
     Intel IA-64 architecture    2.6.8-14sarge3
     Motorola 680x0 architecture 2.6.8-4sarge3
     PowerPC architecture        2.6.8-12sarge3
     IBM S/390 architecture      2.6.8-5sarge3
     Sun Sparc architecture      2.6.8-15sarge3

Due to technical problems the built amd64 packages couldn't be processed by the archive script. Once this problem is resolved, an updated DSA 1103-2 will be sent out with the checksums for amd64.

The following matrix lists additional packages that were rebuilt for compatibility with or to take advantage of this update:

                                 Debian 3.1 (sarge)
     fai-kernels                 1.9.1sarge2

We recommend that you upgrade your kernel package immediately and reboot the machine. If you have built a custom kernel from the kernel source package, you will need to rebuild to take advantage of these fixes.

Upgrade Instructions

wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge

Source archives:
      Size/MD5 checksum: 1002 c13d8ebcabab9477e9dbf7a5d66fa4d4
      Size/MD5 checksum: 1043822 9dc3ae088c90a7be470b9436ca317fcc
      Size/MD5 checksum: 43929719 0393c05ffa4770c3c5178b74dc7a4282
      Size/MD5 checksum: 812 822e18074a76927a0a91c83916c991bb
      Size/MD5 checksum: 39108 45f3b6b40470a81768f113160754fdbd
      Size/MD5 checksum: 1008 6fa522a94872155497a0e057a05f8b61
      Size/MD5 checksum: 67361 863b56c6386182f58fda2054099e9e52
      Size/MD5 checksum: 1047 294c981159570b5253bc877ce0543b12
      Size/MD5 checksum: 90731 3215b0f2a0dc926db6e05b04ff5760ed
      Size/MD5 checksum: 1191 e26e2149236092d9227773a904eaed04
      Size/MD5 checksum: 64130 03de4cad1ccfa5ce38f5b4b97b71f5ad
      Size/MD5 checksum: 874 2e925606f9143b774ab2e86a12d62c44
      Size/MD5 checksum: 15464 7dfeb923284a92f3bca5e8ef62a52498
      Size/MD5 checksum: 1071 9e2657e0a79bd6b3cde0df2e5c9aa77e
      Size/MD5 checksum: 26926 5f6c84921c0f6041fdd269a6c66a0568
      Size/MD5 checksum: 846 89d3a1f59fb514c8c5a195e91eaa1997
      Size/MD5 checksum: 12972 e3c65e0b2998dad3c440a0c1af5cd99f
      Size/MD5 checksum: 1036 31e7168c06b98e03789c100b6a6fcf67
      Size/MD5 checksum: 24369 6c9e2b0e3a3f625cc4103b385f0c093c

Architecture independent components:
      Size/MD5 checksum: 6184022 54432fcfa3a56c502b0feabe6723c467
      Size/MD5 checksum: 1079878 a2ca885ba3b9b30d211c26647524cbc9
      Size/MD5 checksum: 34941458 74c1b17e994280ac14d7116a52b771bf
      Size/MD5 checksum: 35082 7b08d82ec9046359cd85ea87aad96995
      Size/MD5 checksum: 10934 0d1c81689deeaa145be9e4d3ae140a81

Alpha architecture:
      Size/MD5 checksum: 2757876 e94cdb8d12552d293018c7ca24199f47
      Size/MD5 checksum: 230608 fdf2cc6f010f2b618672422c3293f3b9
      Size/MD5 checksum: 225502 2a21bf8197792a789420b1838526186f
      Size/MD5 checksum: 2759828 544e1f44b4cebfaf97f4ae1870b56ab1
      Size/MD5 checksum: 232152 9ba670970518572ad7db755e7888ee8a
      Size/MD5 checksum: 227100 a836d721852b11fa6422f33dc81a5415
      Size/MD5 checksum: 20226800 f627945f7f8216fbe6961a9559766f29
      Size/MD5 checksum: 20068720 7aa6c0137c94e2e7ee45e5ae702cfe27
      Size/MD5 checksum: 20220874 d9c1642300f72cc5f3fc3b04865b3b3d
      Size/MD5 checksum: 20073352 1faa9472c15dd6142221fec2261b5628

HP Precision architecture:
      Size/MD5 checksum: 2798740 3bd227d7f6ce63d13f4eb4cef3cc7efa
      Size/MD5 checksum: 209500 8b284495343adf74bca8219421f4b48d
      Size/MD5 checksum: 208722 941a680674931ec594e3512c5736c9bf
      Size/MD5 checksum: 208356 7ab2df2b04391d75500083585a96701b
      Size/MD5 checksum: 207502 0a840281a00f4762978af411d7a3e7fb
      Size/MD5 checksum: 2802244 f82eaa9411813bbdee2e0c268a067c81
      Size/MD5 checksum: 211350 c221830c715cfebb1acb383d8f7c6a8a
      Size/MD5 checksum: 210570 96c096a16a6291f4b40716ac939bd063
      Size/MD5 checksum: 210220 fc6c20856e898e4bd881711e6392d4e9
      Size/MD5 checksum: 209468 6a00248dcf25809f02f7ab585429f27b
      Size/MD5 checksum: 16020358 6423b4288f949286ce1c70a743d03373
      Size/MD5 checksum: 16926452 be46b30fdb54c08c6cef2fcf7c9a2450
      Size/MD5 checksum: 17472682 d8ecab478805553c2f978dd405dca57d
      Size/MD5 checksum: 18305956 42ae9163eaba822e863ea8dd2cdedcaa
      Size/MD5 checksum: 16029232 665d462c1fae45714ff948289c8a3457
      Size/MD5 checksum: 16927312 a69c9e976ab6810bf7043a15daa1dd29
      Size/MD5 checksum: 17480298 66e35e40e7e2d82370f7ccba7544a59a
      Size/MD5 checksum: 18306822 88ade3c07fc414c82bf589def0bda600

Intel IA-32 architecture:
      Size/MD5 checksum: 2777236 af649947c652a9486461b92bbc33be8a
      Size/MD5 checksum: 256920 88db1b684f215fdd35de0989f148b57f
      Size/MD5 checksum: 254646 553205bb17cfc57f4c4a7aadff46650a
      Size/MD5 checksum: 251590 51ebd6202b7f347f66df0e189b2a3946
      Size/MD5 checksum: 254818 746967059979238eb49cfdcba572c07b
      Size/MD5 checksum: 251708 33a61355c7a48d87b7570b772e454760
      Size/MD5 checksum: 2779348 210a335431d029842eb82036d5326edf
      Size/MD5 checksum: 258446 1d48b727a22487e4b34f4894b2a9a7f2
      Size/MD5 checksum: 256322 8f73439c2a920c66ae05d3ceba45229a
      Size/MD5 checksum: 253564 4ce8f253c15562e9d11a985e135d94b4
      Size/MD5 checksum: 256504 5a5c2acd3ef2fb3764489ed77865739e
      Size/MD5 checksum: 253486 48f046411662bdde50195f8bdb421efa
      Size/MD5 checksum: 14058198 fd607b13caf99093ef31071ff7395d6d
      Size/MD5 checksum: 15531820 5871afdf04de65bda6f5eb3266b0621d
      Size/MD5 checksum: 15339250 f3ab94a1304a28732cea6be8dd871ac7
      Size/MD5 checksum: 15258514 cc888a3d69727d61b86a7f0945a51eff
      Size/MD5 checksum: 15118194 fb0e7f6b830b7a012f06bf7c25ff15cc
      Size/MD5 checksum: 14063774 13d8810b179bb8408645e7fab57d114a
      Size/MD5 checksum: 15536484 0a47b2f9fc33d4b7a52eb68b54419c82
      Size/MD5 checksum: 15346402 fffd9fb96343167ccc32356fa307152a
      Size/MD5 checksum: 15261026 cbdee84292a612fddca022377e38eebb
      Size/MD5 checksum: 15124168 248b85e7c59930aeb63fda6a0366b9a2

Intel IA-64 architecture:
      Size/MD5 checksum: 6606 27049d0c329dc1cad092b2d53c3322ec
      Size/MD5 checksum: 6678 f3967dddbec5691733d49246d09f8cb3
      Size/MD5 checksum: 6638 acc1b57c5a246304f9cee279574811e9
      Size/MD5 checksum: 6706 5c28f912ecc42291a9ec3ef0f13c6041
      Size/MD5 checksum: 3097054 691f7cd4d1b2f184e50ab566f20a13e4
      Size/MD5 checksum: 198662 72e0e4b4331b8a600de3a98d6ac59a82
      Size/MD5 checksum: 197920 6e19efeac81a2a9416328af58316c4cb
      Size/MD5 checksum: 198394 6d946fcc7b1fcf88c9ee9a47f7015384
      Size/MD5 checksum: 197828 8be7e8290bd8e7cf1b9c162c9e369b36
      Size/MD5 checksum: 3098862 aee4e1b99a34047fbf47941e2dced300
      Size/MD5 checksum: 199934 484af4636ad4d64ecbf89dd7b47cda03
      Size/MD5 checksum: 199302 8b6e3253f9c04054e1e9d2066e4323c0
      Size/MD5 checksum: 199582 8b97de7837305ad8728bc0ab4bfeccb1
      Size/MD5 checksum: 199190 508601b56facbca5211e2e3f1a819d4e
      Size/MD5 checksum: 6602 dea61776e4279d8906f3d552af3ed55c
      Size/MD5 checksum: 6670 d8ab34493a8cfc857dccd8a84743017a
      Size/MD5 checksum: 6630 04e4d5b971ec3523b80a3f2373afbf73
      Size/MD5 checksum: 6700 f5cc48a00ca305eaea622738ce0d6570
      Size/MD5 checksum: 22041474 4419d9b68b593646ed49ff194fcbcc9e
      Size/MD5 checksum: 22666884 7aab34e05eed41eee4b56ca45e1c4c2c
      Size/MD5 checksum: 21959066 27fe9dc58a04851cfbbac5b4a53f21ae
      Size/MD5 checksum: 22689900 4011393c3e3a94354d81c909a1aaef91
      Size/MD5 checksum: 21476428 ec3548487a558e67913419b84c84999c
      Size/MD5 checksum: 22133136 0d6292568fadcc40f65e87314315165c
      Size/MD5 checksum: 21408908 539197e6af86ff9583cf43d12ad109b1
      Size/MD5 checksum: 22154322 a4ae9740b9459b0a43c47b5b6e546515

Motorola 680x0 architecture:
      Size/MD5 checksum: 3305628 8029426256d755ea724ed7b46243c1ba
      Size/MD5 checksum: 3101728 677b103a57ce6de26b072245dfd585f7
      Size/MD5 checksum: 3014324 f7a8e8b9c7d4eacecd1f1d69f1ee2c34
      Size/MD5 checksum: 2986734 fd1f14cc2856a55bb6948bdf956ea0d5
      Size/MD5 checksum: 3173334 e32fa0fd9460b9e19bd24c8cc413684f
      Size/MD5 checksum: 2978518 6e682497437fa9d1912ea5fd3374c82f
      Size/MD5 checksum: 3047534 f9daecf9203da30c95cd9ab9647d8c54
      Size/MD5 checksum: 3108200 9a81b37d60bdcf95d6cbc3ca5eb83d1a
      Size/MD5 checksum: 2992046 cfae06d516a2695eb961e574570661a4

PowerPC architecture:
      Size/MD5 checksum: 407330 3025ba5c61db0cd42b9d0ab1a3e01b1c
      Size/MD5 checksum: 406624 21742d40c3c0bac0d64e970c0944c59f
      Size/MD5 checksum: 406548 b9ce59161b3faf818f77239a468828e4
      Size/MD5 checksum: 406518 e40256427db90a027ed2be8a7b50997c
      Size/MD5 checksum: 406882 c899bf1d81895ee43306a8b19e3c8ee8
      Size/MD5 checksum: 407320 45108a12629a9eddd40b071db4b92e4e
      Size/MD5 checksum: 405670 bd347754ea8c4cee14686b207e6cf46d
      Size/MD5 checksum: 405666 1dec752373178a4aef51f74c6d917073
      Size/MD5 checksum: 405598 c39f371744ca92eec853ad8746f0f009
      Size/MD5 checksum: 405568 b346b94897fca3c678daadc99b515428
      Size/MD5 checksum: 405912 14475ec4cdc9b337ad2dc0ab3a772bdb
      Size/MD5 checksum: 405698 4c3c94aa9afb4e6d73986bbfa26484bb
      Size/MD5 checksum: 5143830 3a6cd285eba77baae74a2a16f8029be2
      Size/MD5 checksum: 5147620 32c5daf3656ab15416c3a42a5be21afc
      Size/MD5 checksum: 13577038 981f85ad155781610e2069f28b1eb4e7
      Size/MD5 checksum: 13929444 b11a91f117e0d25b6df7a56cd2c0f0d6
      Size/MD5 checksum: 13560822 44f1276a6cd811646ebf3ccb2da06067
      Size/MD5 checksum: 13920572 fd32c8d3f0dbb55430075b57546f9390
      Size/MD5 checksum: 13594454 93d70ceed88a16e7af0fe3db1a2c5baa
      Size/MD5 checksum: 13847204 5f22d24e351ce6040f9fa995e5a7906a
      Size/MD5 checksum: 13494684 2ab633af498a4486190d3754c530e7f4
      Size/MD5 checksum: 13855580 1245c9d474405a277864484b0237252f
      Size/MD5 checksum: 13486150 80b9f2ed16acb2c9fdb7c9cb133a4c03
      Size/MD5 checksum: 13842602 e4013da64e44e6e0401aa87b1e68c1ce
      Size/MD5 checksum: 13514634 a3fbbf23d7b805431a5f9f28aadd25ab
      Size/MD5 checksum: 13769858 20783767bb65e7ea6ca76662438bf7ca

IBM S/390 architecture:
      Size/MD5 checksum: 5083010 42c4dd8c6c67ce7940f0d24bb745385c