Wednesday, January 8, 2014

Fedora 20 for IBM System z 64bit official release

Hello everyone,

The Fedora 20 GA release for the IBM System z is here. This time again
a few weeks later than the primary release mainly because of me being
on vacation (again :-)) during the December holidays. The difference to
primary Fedora is this time a bit larger than it was in Fedora 19 for
various reasons. For example some packages now exclude non-x86
architectures even when they built just fine for earlier Fedora
releases. We would therefore welcome feedback about packages that work
just fine on secondary arches so that upstream projects would be more
willing to include our secondary architectures as supported.

The links to the actual release are here:

http://secondary.fedoraproject.org/pub/fedora-secondary/releases/20/Fedora/s390x/

http://secondary.fedoraproject.org/pub/fedora-secondary/releases/20/Everything/s390x/os/

and obviously on all sites that mirror the secondary arch content and we
still have few :-)

The first directory contains the normal installation trees as well as
one DVD ISO with the complete release.

Everything as usual contains, well, everything. :)


For general Fedora documentation please see
http://docs.fedoraproject.org/en-US/index.html

Additional information about known issues,
the current progress and state for future release, where and how the
team can be reached and just anything else Fedora on IBM System z
related can be found here:

http://fedoraproject.org/wiki/Architectures/s390x/20

For architecture specific release notes, please read it as there are
changes in the interactive installation process. It's a wiki so don't
hesitate to add your knowledge there. You can find useful information
also in the previous release notes linked from the current ones.

More information about Fedora on IBM System z can be found at
http://fedoraproject.org/wiki/Architectures/s390x


Thanks go out to everyone involved in making this happen!


Your Fedora/s390x Maintainers

--
Dan Horák, RHCE
Senior Software Engineer, Secondary architectures team

Red Hat Czech s.r.o., Purkyňova 99, 612 45 Brno
--
announce mailing list
announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/announce

Tuesday, January 7, 2014

[CentOS-announce] CentOS Project joins forces with Red Hat

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

With great excitement I'd like to announce that we are joining the Red
Hat family. The CentOS Project ( http://www.centos.org ) is joining
forces with Red Hat. Working as part of the Open Source and Standards
team ( http://community.redhat.com/ ) to foster rapid innovation
beyond the platform into the next generation of emerging technologies.
Working alongside the Fedora and RHEL ecosystems, we hope to further
expand on the community offerings by providing a platform that is
easily consumed, by other projects to promote their code while we
maintain the established base.

We are also launching the new CentOS.org website (
http://www.centos.org ).

- -------------
The new initiative is going to be overseen by the new CentOS Governing
Board. The initial Board comprises of the existing CentOS Core team
members :

- - Ralph Angenent
- - Tru Hyunh
- - Johnny Hughes JR
- - Jim Perrin
- - Karanbir Singh

and also sees new members:
- - Fabian Arrotin, who comes to the board nominated from the community
- - Carl Trieloff, Karsten Wade, and Mike McLean join us, nominated by
Red Hat.

Please join me in welcoming the new members to the Board.

The key operating points of the Board are going to be: Public, Open,
and Inclusive. You can find more information about the governance
model, the board, and the operating policies we are proposing at
http://www.centos.org/about/governance/

Furthermore, some of the existing CentOS Core members are moving to
take up roles at Red Hat, as a part of their sponsorship of the CentOS
Project, allowing these people to work on the Project as their primary
job function. This includes Johnny Hughes Jr, Jim Perrin, Fabian
Arrotin, and myself. We will be working with and operating out of the
Red Hat Open Source and Standards team in the CTO's Office.

- -------------
Some of the things that are not changing:
- - The CentOS Linux platform isn't changing. The process and methods
built up around the platform however are going to become more open,
more inclusive and transparent.
- - The sponsor driven content network that has been central to the
success of the CentOS efforts over the years stays intact.
- - The bugs, issues, and incident handling process stays as it has been
with more opportunities for community members to get involved at
various stages of the process.
- - The Red Hat Enterprise Linux to CentOS firewall will also remain.
Members and contributors to the CentOS efforts are still isolated from
the RHEL Groups inside Red Hat, with the only interface being srpm /
source path tracking, no sooner than is considered released. In
summary: we retain an upstream.

Feel free to reach out if you have specific concerns about how this
change impacts your CentOS story. URLs mentioned at the bottom of this
email should be a good starting point.

- -------------
Some of the key things that are changing:
- - Some of us now work for Red Hat, but not RHEL. This should not have
any impact to our ability to do what we have done in the past, it
should facilitate a more rapid pace of development and evolution for
our work on the community platform.

- - Red Hat is offering to sponsor some of the buildsystem and initial
content delivery resources - how we are able to consume these and when
we are able to make use of this is to be decided.

- - Sources that we consume, in the platform, in the addons, or the
parallel stacks such as Xen4CentOS will become easier to consume with
a git.centos.org being setup, with the scripts and rpm metadata needed
to create binaries being published there. The Board also aims to put
together a plan to allow groups to come together within the CentOS
ecosystem as a Special Interest Group (SIG) and build CentOS Variants
on our resources, as officially endorsed. You can read about the
proposal at http://www.centos.org/variants/

- - Because we are now able to work with the Red Hat legal teams, some
of the contraints that resulted in efforts like CentOS-QA being behind
closed doors, now go away and we hope to have the entire build, test,
and delivery chain open to anyone who wishes to come and join the effort.

The changes we make are going to be community inclusive, and promoted,
proposed, formalised, and actioned in an open community centric manner
on the centos-devel mailing list. And I highly encourage everyone to
come along and participate.

- -------------
Contacting us works best via the established community mechanisms.
- - Real time chats via IRC ( http://wiki.centos.org/irc ) ; To keep
conversation sanity intact, I recommend using the #centos-devel
channel to discuss project related activity while #centos is best used
for end user conversations.

- - The Mailing lists are a great way to interface with the developers,
contributors and the community at large ( http://lists.centos.org ).
As with IRC, we recommend using the centos-devel list to talk about
project related issues while the general centos list is best used for
end user conversations.

- - The CentOS Forums are another great way to engage in conversation
with other users ( http://www.centos.org/forums ), if you prefer that
mechanism.

All the above mentioned venues are public and open to the community,
should you wish to discuss something privately, you can email us at
centosdev@centos.org. Press requests should be sent to
press@centos.org. Please note that it will take us much longer to
reply to private requests as compared to content on the public venues.

- -------------
In the coming days we are going to create opportunities for people to
come and get involved in more face to face interactions. Starting with
a regular scheduled office-hours format hangouts (
http://wiki.centos.org/OfficeHours ) that start early next week. We
are trying to split the sessions into two different timezones so as to
maximise the number of people who are able to join. The sessions will
run live, with #centos-devel on irc.freenode.net being used for
conversations alongside.

We are also running a CentOS Dojo on the 31st Jan 2014 at Belgium (
http://wiki.centos.org/Events/Dojo/Brussels2014 ); The event will run
two tracks, with lots of opportunities for social interaction between
the talks; followed by CentOS in the Clouds Hack sessions. We are
limited in the number of people we can accomodate, so I encourage
everyone to register early.

- -------------
I want to take this opportunity to thank all the sponsors, the
contributors and the CentOS team members for all their help over the
years, the project is built completely upon those contributions - and
I look forward to seeing even more involvement from everyone as we
move forward.

- -------------
A Request:

We are still sorting out content in various places and it might take a
day or two to get everything in place. In the mean time if you find
something stale and perhaps misleading in the new context ( or the old
one! ) please drop in on #centos-devel at irc.centos.org and let us know.

- -------------
Some URLS:
- - http://www.centos.org/ The CentOS Project
- - http://wiki.centos.org/ CentOS Community wiki
- - http://community.redhat.com/ RedHat OSAS
- -
http://www.redhat.com/about/news/press-archive/2014/1/red-hat-and-centos-join-forces
- - Red Hat Press Release
- - http://community.redhat.com/centos-faq - Red Hat FAQ's about the
initiative
- - http://wiki.centos.org/FAQ - CentOS FAQ's about the initiative


Enjoy! and regards,

Karanbir Singh and everyone from the CentOS team,


- --
Karanbir Singh, Project Chair, The CentOS Project
+44-207-0999389 | http://www.centos.org/ | twitter.com/CentOS
GnuPG Key : http://www.karan.org/publickey.asc
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iEYEARECAAYFAlLMbQcACgkQMA29nj4Tz1sTnQCgj2fYxYpTjA0KwH7TpCWjE4gg
w2cAniQWb/nh6Zn/8daSQ3EAfLIzGNKg
=KJOk
-----END PGP SIGNATURE-----
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce

[USN-2078-1] libXfont vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSzEz0AAoJEGVp2FWnRL6TNtMP/AkNG7/4R+hntyLKXuLpQMfu
wloldok1XDdpVHUq541J06Hz380IIT6kb1VmtkIpSG25BJtcUzfzPJdIXls0piPz
y9G//a/OlH9dTHWb/cIb45UlaPJhGyJ/Q3w0ckS7bxulKpvDvOVeAkL1DyH5yEJn
PJx+7MtCysBvwFXr1EIQymbCNYAghCwaMGFsTH/W1w+8qianFZyIXdflHQIhBq7X
XDu2fXF31k8jynm1rZ4dzYtD4VC79ETtXJAQOG6p0SXKdfGpdov/eE+21/lK42uD
0Eu+n6ahY4kPyutLR1erl3wf6h3sxlrMtj42ixxKDOw6MML3BfssaUgXlxjILRu1
dBlBVBolZqnNFyGLfgG/p1o0hH6kbm5CK9Q2rQAVf0J76U2bab3+IvPiWQuRCQ2f
zVGRCnpBfQD11Lef+SERWW1FJnTQfZbz3DjJF3uBulFVFaQY4miKfKcSubhOTBSj
Xf4dZzCikT1otkoGLJxCLC4amDdVqzqIQtwC0BRVyzN7MG6j0nczkvSj7t9YuX34
Pg/ZM/DpItthYEgZH75u6fFo9N4ATH59omFrwYbXb5Gc4tnOS93eFd9SPQWW6BM+
GJZlTvRona+Bm5LVuiHFGMUQIVma1NfmEKLjBC2Os6THrZL36VRdg0xf74DcJVF5
SgK9Juf1VmbiwaVn+6lv
=ktrb
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2078-1
January 07, 2014

libxfont vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.10
- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS
- Ubuntu 10.04 LTS

Summary:

libXfont could be made to crash or run programs as an administrator if it
opened a specially crafted font file.

Software Description:
- libxfont: X11 font rasterisation library

Details:

It was discovered that libXfont incorrectly handled certain malformed BDF
fonts. An attacker could use a specially crafted font file to cause
libXfont to crash, or possibly execute arbitrary code in order to gain
privileges. The default compiler options for affected releases should
reduce the vulnerability to a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
libxfont1 1:1.4.6-1ubuntu0.1

Ubuntu 13.04:
libxfont1 1:1.4.5-2ubuntu0.13.04.1

Ubuntu 12.10:
libxfont1 1:1.4.5-2ubuntu0.12.10.1

Ubuntu 12.04 LTS:
libxfont1 1:1.4.4-1ubuntu0.1

Ubuntu 10.04 LTS:
libxfont1 1:1.4.1-1ubuntu0.2

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2078-1
CVE-2013-6462

Package Information:
https://launchpad.net/ubuntu/+source/libxfont/1:1.4.6-1ubuntu0.1
https://launchpad.net/ubuntu/+source/libxfont/1:1.4.5-2ubuntu0.13.04.1
https://launchpad.net/ubuntu/+source/libxfont/1:1.4.5-2ubuntu0.12.10.1
https://launchpad.net/ubuntu/+source/libxfont/1:1.4.4-1ubuntu0.1
https://launchpad.net/ubuntu/+source/libxfont/1:1.4.1-1ubuntu0.2

[announce] NYC*BUG upcoming and NYCBSDCon

Besides the meeting on Wednesday night, it will be the first chance to
purchase tickets for NYCBSDCon 2014 to be held before the meeting,
starting at 6 PM in the backroom. Be sure to bring $25 in cash to cover
your admission.

Online registration will open soon, but the cost will be higher than
paying in person.

Our speakers are lined up, and we'll be posting the full program shortly.

www.nycbsdcon.org

*******

January 8 2014, Wednesday
Suspenders at 111 Broadway just above Wall Street
645 PM

OpenBSD: A Crash Course, Brian Callahan

Abstract

With issues of privacy and security occupying the forefront of recent
international news, a reexamination of the technologies used in one's
personal and professional infrastructure is essential.

This talk will highlight why OpenBSD should be at the forefront of these
reexaminations. Whether you are a long time *BSD user or are completely
new to *BSD, you will discover why OpenBSD excels in these areas and why
its security reputation is well deserved.

Speaker Bio

Brian is a graduate student at Monmouth University studying
Anthropology. He is an OpenBSD developer, working primarily on ports.
_______________________________________________
announce mailing list
announce@lists.nycbug.org
http://www.nycbug.org/mailman/listinfo/announce

Ubuntu 13.04 (Raring Ringtail) reaches End of Life on January 27 2014

Ubuntu announced its 13.04 (Raring Ringtail) release almost 9 months
ago, on April 25, 2013. This was the first release with our new 9
month support cycle and, as such, the support period is now nearing
its end and Ubuntu 13.04 will reach end of life on Monday, January
27th. At that time, Ubuntu Security Notices will no longer include
information or updated packages for Ubuntu 13.04.

The supported upgrade path from Ubuntu 13.04 is via Ubuntu 13.10.
Instructions and caveats for the upgrade may be found at:

https://help.ubuntu.com/community/SaucyUpgrades

Ubuntu 13.10 continues to be actively supported with security updates
and select high-impact bug fixes. Announcements of security updates
for Ubuntu releases are sent to the ubuntu-security-announce mailing
list, information about which may be found at:

https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

Since its launch in October 2004 Ubuntu has become one of the most
highly regarded Linux distributions with millions of users in homes,
schools, businesses and governments around the world. Ubuntu is Open
Source software, costs nothing to download, and users are free to
customise or alter their software in order to meet their needs.

On behalf of the Ubuntu Release Team,

Adam Conrad

--
ubuntu-announce mailing list
ubuntu-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-announce

Monday, January 6, 2014

[USN-2077-1] Puppet vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSyuv1AAoJEGVp2FWnRL6TwjIP/Rt/Lao07akkRbe+I0kbjpri
E4OtSvn0mAHDRXqCYh3GYJqXq3jaOChTKJsHDDLVOpIQRQqQV2Y8tUKk1oYg7MtM
dtV6g/mDdfVgNOFBwsSuPgcpEzi0BQiX2o0y2uMllU6i/NfKwr6f+/yHRLQo4P3o
R38jC1Cl5LeBSGxqVLRod6GKjEOpjAaOOCST0TghAY6tqwclqqGTcA8jgG6x1CrX
w0I72EcT01/8/3MmC1B+3/sEyBo9FpqHUmcc6SQm7smuZbFmIoEtUlxmMoRC1LFJ
6Zr9C5ht64kPxNp9mB7ta6QyoFzK5k8sUzqq7tljNF2oeo/B1Je66zCnEfaVW1ug
9T4KIvpmvgQ7QH5rI4UuLLbYhuRm7uj4AqMoK3G2d1LZZqQLw1LPIOo94je/9cwU
+6dg/qwB4xV2LsgOgYx2A3ftdbtCafQP/TKVaud98IKZ57X2gG4gg7e2oM0TdvwS
sVu08RkUVjBKAvLxjXZ1ksorqX1Dw6zASGufk2dcfXo1WjG2QHfkugdo3Fvf0iM4
bXfQH66P73sf7mugn4gEN9od/XtHF6NDXRiviXqgWGLA4mDLO1lhbAVI68mYewPh
q/tflun4XSlTI3+L7CgjlFWjS/fMa2UgApDOF8rT6fow/tF1o7/P+bCju42rD9VD
YV1UBISSE3oyaFBqK9CJ
=xSXP
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2077-1
January 06, 2014

puppet vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.10
- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS

Summary:

Puppet could be made to overwrite files.

Software Description:
- puppet: Centralized configuration management

Details:

It was discovered that Puppet incorrectly handled temporary files. A local
attacker could possibly use this issue to overwrite arbitrary files. In the
default installation of Ubuntu, this should be prevented by the Yama link
restrictions.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
puppet-common 3.2.4-2ubuntu2.2

Ubuntu 13.04:
puppet-common 2.7.18-4ubuntu1.3

Ubuntu 12.10:
puppet-common 2.7.18-1ubuntu1.4

Ubuntu 12.04 LTS:
puppet-common 2.7.11-1ubuntu2.6

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2077-1
CVE-2013-4969

Package Information:
https://launchpad.net/ubuntu/+source/puppet/3.2.4-2ubuntu2.2
https://launchpad.net/ubuntu/+source/puppet/2.7.18-4ubuntu1.3
https://launchpad.net/ubuntu/+source/puppet/2.7.18-1ubuntu1.4
https://launchpad.net/ubuntu/+source/puppet/2.7.11-1ubuntu2.6

[CentOS-announce] CEBA-2014:0005 CentOS 6 sssd Update

CentOS Errata and Bugfix Advisory 2014:0005

Upstream details at : https://rhn.redhat.com/errata/RHBA-2014-0005.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
0d31e0bfd94af81305f8e620a2c859c141d63ee6e7e1695da18ce9ff32b1d8ad libipa_hbac-1.9.2-129.el6_5.4.i686.rpm
bd616a723787d89ad2832219915964b1cbb5c45251e013323a17572d18279a7d libipa_hbac-devel-1.9.2-129.el6_5.4.i686.rpm
89ef63c0d8b7d94d53ae76130d82624de337b1b17124abd44f3e5c8dfe8fe442 libipa_hbac-python-1.9.2-129.el6_5.4.i686.rpm
d029a76709875099b811c8b788ca761a4851fed24a3e6cd8ac8301aeeebfe50e libsss_autofs-1.9.2-129.el6_5.4.i686.rpm
ca729ea089821db0a6e31fae61ef8af691ee44b1c1dd3b7cab3706561ac5de8f libsss_idmap-1.9.2-129.el6_5.4.i686.rpm
570b574f6edd9bc3aeead48a3c8c3dda1425a97c5b53b429c8e99d83236b706b libsss_idmap-devel-1.9.2-129.el6_5.4.i686.rpm
c4c441c07b31ffb3515725e08bfdb42bb0bf6a40731b21a8ccf737918765c0d1 libsss_sudo-1.9.2-129.el6_5.4.i686.rpm
fab7bb18cf94a75dc2ae89444cd26f593871ff74e0ee7d48d46666703121f3d3 libsss_sudo-devel-1.9.2-129.el6_5.4.i686.rpm
036a42feb61a07ae20a44ba2119f59f7208acdcb4a3f2c99578ae6fb8e950806 sssd-1.9.2-129.el6_5.4.i686.rpm
63b9d09340e4c54efec67109d168de2ec1c489e9f08e5eb0887cc155977c4406 sssd-client-1.9.2-129.el6_5.4.i686.rpm
82673b1596a9ac0dddcbbc09398607d20a2d852e65d37dc8294260d82d2ef485 sssd-tools-1.9.2-129.el6_5.4.i686.rpm

x86_64:
0d31e0bfd94af81305f8e620a2c859c141d63ee6e7e1695da18ce9ff32b1d8ad libipa_hbac-1.9.2-129.el6_5.4.i686.rpm
ac4561121f9aaf41acae676fbb33cff958afb8c071a43274b7970df0c056191f libipa_hbac-1.9.2-129.el6_5.4.x86_64.rpm
bd616a723787d89ad2832219915964b1cbb5c45251e013323a17572d18279a7d libipa_hbac-devel-1.9.2-129.el6_5.4.i686.rpm
2a53eda1460fdf2cc9df81487c05c45c876d70fa104ee88833a40864bff84bd6 libipa_hbac-devel-1.9.2-129.el6_5.4.x86_64.rpm
09f2329cf4a85ce0ed1e2e5d57df1548b592143cc914d56996abf704ba34044b libipa_hbac-python-1.9.2-129.el6_5.4.x86_64.rpm
73eaff3cccaa30f13cf431c1b5b19461e9e2c931ea85e2a00fe73d5c2109104f libsss_autofs-1.9.2-129.el6_5.4.x86_64.rpm
ca729ea089821db0a6e31fae61ef8af691ee44b1c1dd3b7cab3706561ac5de8f libsss_idmap-1.9.2-129.el6_5.4.i686.rpm
a7ba5cea05f9519f873bd08bdb478aad7f79156f8db26a7aceaf264ce90593e9 libsss_idmap-1.9.2-129.el6_5.4.x86_64.rpm
570b574f6edd9bc3aeead48a3c8c3dda1425a97c5b53b429c8e99d83236b706b libsss_idmap-devel-1.9.2-129.el6_5.4.i686.rpm
f9346e709519c0bcb049d0f9d1cbe95692864bb8f114a96b1913f0763bf94dad libsss_idmap-devel-1.9.2-129.el6_5.4.x86_64.rpm
3ccbe1d1f618371ed1a71dc08fa30b5a997c0fcc119704202a901e5fd7cc9520 libsss_sudo-1.9.2-129.el6_5.4.x86_64.rpm
fab7bb18cf94a75dc2ae89444cd26f593871ff74e0ee7d48d46666703121f3d3 libsss_sudo-devel-1.9.2-129.el6_5.4.i686.rpm
9a72bb6896d6052055cecf2206d0cdd49bd7ef672040f2154da662402d34082d libsss_sudo-devel-1.9.2-129.el6_5.4.x86_64.rpm
6afd1e8393d11c7f977b715a49935db27868dc9375c614872d65d4084e9e5d36 sssd-1.9.2-129.el6_5.4.x86_64.rpm
63b9d09340e4c54efec67109d168de2ec1c489e9f08e5eb0887cc155977c4406 sssd-client-1.9.2-129.el6_5.4.i686.rpm
218cbec8a327d7077713b545d95738f962d2fec46d11a6ee415b9858cd01012b sssd-client-1.9.2-129.el6_5.4.x86_64.rpm
c7e5f0ab55282731cf7a4d0b316cec008135772a6b9eae5fc0c74f2f7bb9d81b sssd-tools-1.9.2-129.el6_5.4.x86_64.rpm

Source:
ccda87b7a3678c790b5802581d057d16f76ac908c1d317e55bb61b5730c892e3 sssd-1.9.2-129.el6_5.4.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce

Saturday, January 4, 2014

[CentOS-announce] CEBA-2014:0004 CentOS 6 kernel Update

CentOS Errata and Bugfix Advisory 2014:0004

Upstream details at : https://rhn.redhat.com/errata/RHBA-2014-0004.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
34c4d117faac1ba5a647ac7576a48a9a301577a1311b1ad22259c2b32cb8a0a8 kernel-2.6.32-431.3.1.el6.i686.rpm
daab71e92b367f886065f43920b930f1a5b3348819b81d0790124e5370591125 kernel-abi-whitelists-2.6.32-431.3.1.el6.noarch.rpm
68cfab16a48a4307d25f1d7be6384f122e1d4c2d7f56ef5c823ea6c3b614820f kernel-debug-2.6.32-431.3.1.el6.i686.rpm
7536e3613c16b14cbb161627840744d8a430b64002c4fc1516987e5f05fd1a0c kernel-debug-devel-2.6.32-431.3.1.el6.i686.rpm
1852acde5db7b864dab0a17a48d50d2947e3422dafba528a52d4028935037da9 kernel-devel-2.6.32-431.3.1.el6.i686.rpm
39aa17b77d7e2a9b2e87930e3426499f621ffa6197c0fa1f4e35e2bb6196defc kernel-doc-2.6.32-431.3.1.el6.noarch.rpm
bc4e725a973506786d0bafb5b1de14da829aacfa0400f53c18f3b56eee77fc7b kernel-firmware-2.6.32-431.3.1.el6.noarch.rpm
88eac5ea76326695f363a5b1cb14d212834484aa35f44646a16fb1c3486020e0 kernel-headers-2.6.32-431.3.1.el6.i686.rpm
a5c38eebb8ae8cdbe3d8876996848921a430833be657159988a125ce86eae717 perf-2.6.32-431.3.1.el6.i686.rpm
5155425da669468c00f0a9f77e1c8e6960cc679e350b6a2766764833956021dc python-perf-2.6.32-431.3.1.el6.i686.rpm

x86_64:
e15259cfd6dacdcec24a5975df56149a65f6f027b585d27fc35c4520f4353062 kernel-2.6.32-431.3.1.el6.x86_64.rpm
daab71e92b367f886065f43920b930f1a5b3348819b81d0790124e5370591125 kernel-abi-whitelists-2.6.32-431.3.1.el6.noarch.rpm
0c3532615ab9cdadcf23843adad81fb19cab36d815611d5695bc80b2a321fd79 kernel-debug-2.6.32-431.3.1.el6.x86_64.rpm
d34677a8534e705ce75a985e56730efc0262a1a902d0f7d7af206817f954cc6d kernel-debug-devel-2.6.32-431.3.1.el6.x86_64.rpm
059b6dab8c655a7a796cfc14a8d20e80dae2a7a2a0328f0be22cbe6cbcbe97b0 kernel-devel-2.6.32-431.3.1.el6.x86_64.rpm
39aa17b77d7e2a9b2e87930e3426499f621ffa6197c0fa1f4e35e2bb6196defc kernel-doc-2.6.32-431.3.1.el6.noarch.rpm
bc4e725a973506786d0bafb5b1de14da829aacfa0400f53c18f3b56eee77fc7b kernel-firmware-2.6.32-431.3.1.el6.noarch.rpm
ea1fde8c16aa8be359ca6a405d87ff32589c7f2ca08f499e5d45e415dbf4bd29 kernel-headers-2.6.32-431.3.1.el6.x86_64.rpm
b45abf04cd19268befdb8530be5c454ee2b389f5f88d9a91c36e67892b65ca9b perf-2.6.32-431.3.1.el6.x86_64.rpm
28d7a61f170305f78af67c923ec47b53f79816acdb4816256214f3a31e429f9b python-perf-2.6.32-431.3.1.el6.x86_64.rpm

Source:
c676b2ec0d3d2222569157dc7ea67e7941b5f9615f0fe92834dbcb3707b8099c kernel-2.6.32-431.3.1.el6.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce

Friday, January 3, 2014

[USN-2076-1] Linux kernel (OMAP4) vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSxp0TAAoJEAUvNnAY1cPYABkP/1EtsztaGBWLhxctkFzIRYIW
BWjQv0jqc1y7MlrzTEHNuTxIhxb5uFjZZcd9gx7EvfupZajb0yGXIsiEen7aiAlS
4WETr7XXZklX7GTqJzVBgng2dWpGmb0kAc1vUwgjyVisLIz1Pw4rkMdwMz1c32/8
E6nG1xR5W9euzNTXAAqJ9T4w4xjGxHqTd8jWtVRGWTWhyuvsnEFD3Cr9oKFCuf4t
s3hZTbxvL6ApB5Cwpp8Rf3ZwTDiI0OG+DAV+XMbmkjGeZPks5aJAKpPIDpbKOKqb
CIpT2f0cS5moIOxp/Nm9mPlVwK8r9+GGdvsNvaisunPLn3RSbnuXwu4r3i5mK/Vt
SsN9XfMjm9rFChBPQjtVixUYKBHpL4Nwg6p8K3XgTMJNTPyxcS3FIenJwssGmcWe
Poz8ogj9XC77c7bnZ13kTycpnSzgguraRueGOzKCdbr8x7G+hQuMk2wRRLray9bJ
oBnE34hd+sYPtiXjhK13fk4ZJZjHSD6syM2PQVcnArVuDaZuPsZqMAtrQVZoCdrA
r/5cOHq99NXG0n8X3rgouRXil8RNzC49Q628NX3GxbLmN1gJTL502SeLARLQq15E
xopq3ddPH9iG6Nh1qKJmn4IStNE8hl7iQk7IwadxaTcAWVIaegNLLApS789MAJgO
D0YB9Px7blzsxYqGlXFj
=Xjky
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2076-1
January 03, 2014

linux-ti-omap4 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.10

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-ti-omap4: Linux kernel for OMAP4

Details:

Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)

Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)

Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)

Nico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo
Devices USB over WiFi devices. A local user could exploit this flaw to
cause a denial of service or possibly unspecified impact. (CVE-2013-4513)

Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Agere Systems HERMES II Wireless PC Cards. A local user with the
CAP_NET_ADMIN capability could exploit this flaw to cause a denial of
service or possibly gain adminstrative priviliges. (CVE-2013-4514)

Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Beceem WIMAX chipset based devices. An unprivileged local user
could exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-4515)

A flaw was discovered in the Linux kernel's compat ioctls for Adaptec
AACRAID scsi raid devices. An unprivileged local user could send
administrative commands to these devices potentially compromising the data
stored on the device. (CVE-2013-6383)

Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could exploit this flaw to cause a denial of service (memory
corruption) or possibly gain privileges. (CVE-2013-6763)

Evan Huus reported a buffer overflow in the Linux kernel's radiotap header
parsing. A remote attacker could cause a denial of service (buffer over-
read) via a specially crafted header. (CVE-2013-7027)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
linux-image-3.5.0-237-omap4 3.5.0-237.53

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References:
http://www.ubuntu.com/usn/usn-2076-1
CVE-2013-2930, CVE-2013-4345, CVE-2013-4511, CVE-2013-4513,
CVE-2013-4514, CVE-2013-4515, CVE-2013-6383, CVE-2013-6763,
CVE-2013-7027

Package Information:
https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.5.0-237.53

[USN-2074-1] Linux kernel (OMAP4) vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSxpz0AAoJEAUvNnAY1cPY4iUP/021/Lah76nFE6UMMAZkHSqJ
d4S4LWMV6ypZsQLuoBztcgepDUb1S4OVvNnyqfwaI17n9nZsW9XCcrwu4qfmVxJZ
3r3Uo8i1ULMlFrhl2sTXqWPZRCwIAjk1jX+RigrJ0ldP+jQPhJjWpIRfEgwk90N5
5cLwQC98inM4qpsUGVVVS4JMvj4g/Amb5D5u5uujHoq0pjIgs6aD34pvDo3Tv2/w
jnYzrU7cioPtdFkMWbfNvjBphA47pxoAthm6uLMsYIm5CqdfAw4AQEycX9LZ/sDE
BNe0p5stsxNi+nWgDHr9JNWMaNjNB0hXHTtgN/r2XJQAMdDXK89cCOE1rWi4LwPy
+2Ai1s5yPDDhWZNWUUC7H4iFSqvG185qRl9Bz2m+EwinhFY4oZgVjBpImRNre+oN
Ja0XGtykSdd6rK5wU39cx8/YGVellnjVLILlz3RVBs/rrW0IAuHnVJsV6FYdg7Dk
6rEm3RQBPw/4B6OBboAeH63f1y+W/koLbvzKa00qPlGSPNnsAIaetnVrX3jAicEB
hkXjxYuXxR0xkmKeBg3pRruRZimnSBqRpOTZl8Csund+ShcJCvdUhodJqJGLj3TK
hnZKEQNLyDr/S2zf19TNtG1TWeKBxIm2QShy1ZuuApC1bmtxhtop5hU6hso/72Xt
g9BJN8UrVQkuF8+B3RIm
=8JbZ
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2074-1
January 03, 2014

linux-ti-omap4 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-ti-omap4: Linux kernel for OMAP4

Details:

Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)

Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)

Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)

Nico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo
Devices USB over WiFi devices. A local user could exploit this flaw to
cause a denial of service or possibly unspecified impact. (CVE-2013-4513)

Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Agere Systems HERMES II Wireless PC Cards. A local user with the
CAP_NET_ADMIN capability could exploit this flaw to cause a denial of
service or possibly gain adminstrative priviliges. (CVE-2013-4514)

Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Beceem WIMAX chipset based devices. An unprivileged local user
could exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-4515)

A flaw was discovered in the Linux kernel's compat ioctls for Adaptec
AACRAID scsi raid devices. An unprivileged local user could send
administrative commands to these devices potentially compromising the data
stored on the device. (CVE-2013-6383)

Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could exploit this flaw to cause a denial of service (memory
corruption) or possibly gain privileges. (CVE-2013-6763)

Evan Huus reported a buffer overflow in the Linux kernel's radiotap header
parsing. A remote attacker could cause a denial of service (buffer over-
read) via a specially crafted header. (CVE-2013-7027)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
linux-image-3.5.0-237-omap4 3.5.0-237.53

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References:
http://www.ubuntu.com/usn/usn-2074-1
CVE-2013-2930, CVE-2013-4345, CVE-2013-4511, CVE-2013-4513,
CVE-2013-4514, CVE-2013-4515, CVE-2013-6383, CVE-2013-6763,
CVE-2013-7027

Package Information:
https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.5.0-237.53

[USN-2073-1] Linux kernel vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSxpy0AAoJEAUvNnAY1cPYBAoP/2gjxCvbAT9dZ7K+Qu2IfPbO
w5gjGWwa38ykRYQufNkhRY4TMq1U0M8IgRh8WPF/xbt7NOogW2PC4gxEzLn7YmGg
02ekOrONitAb7a8EjGp1ff2wWipyxchkmj0m14hERnIhODOqdlSqZqmg/pfOUKaF
tZK6JuOnjSOXcqZhIqqSzHp2TQd1fK1NE9Li1/pNLyKGMUv1Ds5FhIHtK+x5KGdi
RD+Cl0ovhgUfaT84rTVDeuFlZ/2QszE312mUjOSzcsYw6nke59X4YwXm2KFTob5J
vMBg1sgknEHwR+D32iMxCuS1ldSrPabsNo3tJSvYW3I/Xj5t1sq+EOLwZCzW0t2c
r1y0I/sAPxgLijNTfKWkbSh+21qnDptcugUP2oy7emtQ/sPF258vvtleZ71BAfL2
+M2KII+CYLLUFjx156PVKpvJGnR0bKkWBUbLiCXIrfANhXBz0V+5SqgeSO+SXNx3
cvLiOXe2cSR0KiCujPPUCbpSYtzsThWauxaV/Lu4whNSSdk6EvcuZXCmjCEULih/
S7hik0GNBzxR2numta59PnR7sRC9jp9BC9HesmSrmE28B/F+HcTLNZZ7EQd7+y6W
4fiJM4v0O5tURpXW1FPodmAOMqgqPbwTFw7C1KKRZ72X+bz0V0m275Cz1AYfyMnH
6CqFNFv0u6zySjmMh/iD
=O6mh
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2073-1
January 03, 2014

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

Hannes Frederic Sowa discovered a flaw in the Linux kernel's UDP
Fragmentation Offload (UFO). An unprivileged local user could exploit this
flaw to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2013-4470)

Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)

Nico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo
Devices USB over WiFi devices. A local user could exploit this flaw to
cause a denial of service or possibly unspecified impact. (CVE-2013-4513)

Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Agere Systems HERMES II Wireless PC Cards. A local user with the
CAP_NET_ADMIN capability could exploit this flaw to cause a denial of
service or possibly gain adminstrative priviliges. (CVE-2013-4514)

Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Beceem WIMAX chipset based devices. An unprivileged local user
could exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-4515)

Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for the SystemBase Multi-2/PCI serial card. An unprivileged user
could obtain sensitive information from kernel memory. (CVE-2013-4516)

A flaw was discovered in the Linux kernel's compat ioctls for Adaptec
AACRAID scsi raid devices. An unprivileged local user could send
administrative commands to these devices potentially compromising the data
stored on the device. (CVE-2013-6383)

Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could exploit this flaw to cause a denial of service (memory
corruption) or possibly gain privileges. (CVE-2013-6763)

Evan Huus reported a buffer overflow in the Linux kernel's radiotap header
parsing. A remote attacker could cause a denial of service (buffer over-
read) via a specially crafted header. (CVE-2013-7027)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
linux-image-3.8.0-35-generic 3.8.0-35.50

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References:
http://www.ubuntu.com/usn/usn-2073-1
CVE-2013-4470, CVE-2013-4511, CVE-2013-4513, CVE-2013-4514,
CVE-2013-4515, CVE-2013-4516, CVE-2013-6383, CVE-2013-6763,
CVE-2013-7027

Package Information:
https://launchpad.net/ubuntu/+source/linux/3.8.0-35.50

[USN-2075-1] Linux kernel vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSxpzTAAoJEAUvNnAY1cPY0E0P/1avSxW7x1bY0AxPNjMlfhqa
05lKlOxuHEnl6JuxNLNmT9Upb8wNJQOzNLbEIZJoy4LexFkKNXyInmIsOiKbQYAC
fkmwPmjFb+nNXR4nNwBOqNC8Q0v0v1fJtTIqV9TE72kIC1nVhcJpPtC5jen2ijiV
/THwEhYLpMfaEqNg9sX8PmLnXW0Mh/eugbUj7TnB96vgyhH/p8Jc8wLuT1V3Z6Ie
cRlR6ZE8FRu81g11s+z9384e6CzLIeSu2r3AB36aOij4ANqJB69L1D9wEl84O0hq
JtgPJO16DklTWnZzSZQxLIFueHhgtGxc1fG22KR4yVqanxBhRrFHvjandyYHxmfk
yXCicc1QDJ2c12i+S/4+JuSP34mWCR0gsnKzxF3LVMJak1RjZ2RRd0UTUPESVi/u
/e8qnP1AjcQilpyEu3Bigl8/QjTk1cFjj5hkE3UNp/ZaWxPCHPAC8gEQZHxJ1Cby
WW8Eyze7znlzT17kR+JtkKdVCwDJtg3SqmhxegJM4YBNJGJS8r8jLti7rxedBraw
+43gTesdmAvbsnKWElkg/Jvs5epoHsXwouRLJfzpQ+AXg521h0zOVwz1TydrTU7O
PQP1FUv63X/uU4IAKABwnBPBguTkwi1M9o3g3KAMUu3kD4nVlmDG8uc4n/7Ydx5o
Ofu2+s/rPxrYutzRTlac
=sIHM
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2075-1
January 03, 2014

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.10

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)

Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)

Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)

Jason Wang discovered a bug in the network flow dissector in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (infinite loop). (CVE-2013-4348)

Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)

Nico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo
Devices USB over WiFi devices. A local user could exploit this flaw to
cause a denial of service or possibly unspecified impact. (CVE-2013-4513)

Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Agere Systems HERMES II Wireless PC Cards. A local user with the
CAP_NET_ADMIN capability could exploit this flaw to cause a denial of
service or possibly gain adminstrative priviliges. (CVE-2013-4514)

Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Beceem WIMAX chipset based devices. An unprivileged local user
could exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-4515)

Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for the SystemBase Multi-2/PCI serial card. An unprivileged user
could obtain sensitive information from kernel memory. (CVE-2013-4516)

Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
debugfs filesystem. An administrative local user could exploit this flaw to
cause a denial of service (OOPS). (CVE-2013-6378)

Nico Golde and Fabian Yamaguchi reported a flaw in the driver for Adaptec
AACRAID scsi raid devices in the Linux kernel. A local user could use this
flaw to cause a denial of service or possibly other unspecified impact.
(CVE-2013-6380)

A flaw was discovered in the Linux kernel's compat ioctls for Adaptec
AACRAID scsi raid devices. An unprivileged local user could send
administrative commands to these devices potentially compromising the data
stored on the device. (CVE-2013-6383)

Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could exploit this flaw to cause a denial of service (memory
corruption) or possibly gain privileges. (CVE-2013-6763)

A race condition flaw was discovered in the Linux kernel's ipc shared
memory implimentation. A local user could exploit this flaw to cause a
denial of service (system crash) or possibly have unspecied other impacts.
(CVE-2013-7026)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
linux-image-3.11.0-15-generic 3.11.0-15.23
linux-image-3.11.0-15-generic-lpae 3.11.0-15.23

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References:
http://www.ubuntu.com/usn/usn-2075-1
CVE-2013-2929, CVE-2013-2930, CVE-2013-4345, CVE-2013-4348,
CVE-2013-4511, CVE-2013-4513, CVE-2013-4514, CVE-2013-4515,
CVE-2013-4516, CVE-2013-6378, CVE-2013-6380, CVE-2013-6383,
CVE-2013-6763, CVE-2013-7026

Package Information:
https://launchpad.net/ubuntu/+source/linux/3.11.0-15.23