Important: kernel (SL6)

Synopsis: Important: kernel security update
Advisory ID: SLSA-2013:0830-1
Issue Date: 2013-05-16
CVE Numbers: CVE-2013-2094

This update fixes the following security issue:

* It was found that the Scientific Linux 6.1 kernel update
(SLSA-2011:0542) introduced an integer conversion issue in the Linux
kernel’s Performance Events implementation. This led to a user-supplied
index into the perf_swevent_enabled array not being validated properly,
resulting in out-of-bounds kernel memory access. A local, unprivileged
user could use this flaw to escalate their privileges. (CVE-2013-2094,
Important)

A public exploit that affects Scientific Linux 6 is available.

The system must be rebooted for this update to take effect.

SL6
x86_64
kernel-2.6.32-358.6.2.el6.x86_64.rpm
kernel-debug-2.6.32-358.6.2.el6.x86_64.rpm
kernel-debug-debuginfo-2.6.32-358.6.2.el6.x86_64.rpm
kernel-debug-devel-2.6.32-358.6.2.el6.x86_64.rpm
kernel-debuginfo-2.6.32-358.6.2.el6.x86_64.rpm
kernel-debuginfo-common-x86_64-2.6.32-358.6.2.el6.x86_64.rpm
kernel-devel-2.6.32-358.6.2.el6.x86_64.rpm
kernel-headers-2.6.32-358.6.2.el6.x86_64.rpm
perf-2.6.32-358.6.2.el6.x86_64.rpm
perf-debuginfo-2.6.32-358.6.2.el6.x86_64.rpm
python-perf-debuginfo-2.6.32-358.6.2.el6.x86_64.rpm
python-perf-2.6.32-358.6.2.el6.x86_64.rpm
i386
kernel-2.6.32-358.6.2.el6.i686.rpm
kernel-debug-2.6.32-358.6.2.el6.i686.rpm
kernel-debug-debuginfo-2.6.32-358.6.2.el6.i686.rpm
kernel-debug-devel-2.6.32-358.6.2.el6.i686.rpm
kernel-debuginfo-2.6.32-358.6.2.el6.i686.rpm
kernel-debuginfo-common-i686-2.6.32-358.6.2.el6.i686.rpm
kernel-devel-2.6.32-358.6.2.el6.i686.rpm
kernel-headers-2.6.32-358.6.2.el6.i686.rpm
perf-2.6.32-358.6.2.el6.i686.rpm
perf-debuginfo-2.6.32-358.6.2.el6.i686.rpm
python-perf-debuginfo-2.6.32-358.6.2.el6.i686.rpm
python-perf-2.6.32-358.6.2.el6.i686.rpm
noarch
kernel-doc-2.6.32-358.6.2.el6.noarch.rpm
kernel-firmware-2.6.32-358.6.2.el6.noarch.rpm

– Scientific Linux Development Team