Package name kernel
Date November 19th, 2007
Advisory ID MDKSA-2007:226
Affected versions 2008.0

Problem Description

Some vulnerabilities were discovered and corrected in the Linux
2.6 kernel:

The tcp_sacktag_write_queue function in the Linux kernel 2.6.21
through 2.6.23.7 allows remote attackers to cause a denial of service
via crafted ACK responses that trigger a NULL pointer dereference
(CVE-2007-5501).

To update your kernel, please follow the directions located at:

http://www.mandriva.com/en/security/kernelupdate

Updated Packages

Mandriva Linux 2008.0

 bfb8abfb7532255d239ce8ef3b39966b  2008.0/i586/kernel-2.6.22.9-2mdv-1-1mdv2008.0.i586.rpm
 c68305809aa8704146ea1a59cd687ab1  2008.0/i586/kernel-desktop-2.6.22.9-2mdv-1-1mdv2008.0.i586.rpm
 89a439f86bd47820345287275fe25674  2008.0/i586/kernel-desktop-devel-2.6.22.9-2mdv-1-1mdv2008.0.i586.rpm
 a13eab853fc0b044456d90d98c8e9008  2008.0/i586/kernel-desktop-devel-latest-2.6.22.9-2mdv2008.0.i586.rpm
 229f00634e286da1ab490678cf201dab  2008.0/i586/kernel-desktop-latest-2.6.22.9-2mdv2008.0.i586.rpm
 e77c3f728f0ba5bf8491e27ef389df8c  2008.0/i586/kernel-desktop586-2.6.22.9-2mdv-1-1mdv2008.0.i586.rpm
 82d8110dc838a1a25b2d4de0e94872e3  2008.0/i586/kernel-desktop586-devel-2.6.22.9-2mdv-1-1mdv2008.0.i586.rpm
 0be66b6c155ff5888900f784bf21f555  2008.0/i586/kernel-desktop586-devel-latest-2.6.22.9-2mdv2008.0.i586.rpm
 48976bcfb3ecd30b2c2a671e49f2d241  2008.0/i586/kernel-desktop586-latest-2.6.22.9-2mdv2008.0.i586.rpm
 372de082e77dec0e87d93f389bff76cf  2008.0/i586/kernel-doc-2.6.22.9-2mdv2008.0.i586.rpm
 8fb68460352343d0c14b3d2c5581375f  2008.0/i586/kernel-laptop-2.6.22.9-2mdv-1-1mdv2008.0.i586.rpm
 0c76031c7eb78ba7da93b83ebf531541  2008.0/i586/kernel-laptop-devel-2.6.22.9-2mdv-1-1mdv2008.0.i586.rpm
 059f66f5340e538dda3d748276313975  2008.0/i586/kernel-laptop-devel-latest-2.6.22.9-2mdv2008.0.i586.rpm
 4d6c700c736a476718c809fb3a470ed9  2008.0/i586/kernel-laptop-latest-2.6.22.9-2mdv2008.0.i586.rpm
 57e0382893adc64445913de674815ad5  2008.0/i586/kernel-server-2.6.22.9-2mdv-1-1mdv2008.0.i586.rpm
 f2ea96b6c7f83f8de0f27dc1c2ea9193  2008.0/i586/kernel-server-devel-2.6.22.9-2mdv-1-1mdv2008.0.i586.rpm
 4de3613951fda9c4c92fcb35fe743a04  2008.0/i586/kernel-server-devel-latest-2.6.22.9-2mdv2008.0.i586.rpm
 4cc8313e4fed4a1a966bc4f4d0819f71  2008.0/i586/kernel-server-latest-2.6.22.9-2mdv2008.0.i586.rpm
 a30a7a388cdcdf089c39f7a7c26e34f0  2008.0/i586/kernel-source-2.6.22.9-2mdv-1-1mdv2008.0.i586.rpm
 5b919908b67f94571a4851caf08e8ece  2008.0/i586/kernel-source-latest-2.6.22.9-2mdv2008.0.i586.rpm 
 6e797fd0fea50e2b0290ca082ca9c1db  2008.0/SRPMS/kernel-2.6.22.9-2mdv2007.0.src.rpm

Mandriva Linux 2008.0/X86_64

 d30b2a76ab4e37f296f07380fa8d41a4  2008.0/x86_64/kernel-2.6.22.9-2mdv-1-1mdv2008.0.x86_64.rpm
 3cdbd2356b7400f831a8b759d13952ec  2008.0/x86_64/kernel-desktop-2.6.22.9-2mdv-1-1mdv2008.0.x86_64.rpm
 a60abdec0274a9f96be2fb1117eb2f4a  2008.0/x86_64/kernel-desktop-devel-2.6.22.9-2mdv-1-1mdv2008.0.x86_64.rpm
 272ac8a552c99a1b72303a92f474d46f  2008.0/x86_64/kernel-desktop-devel-latest-2.6.22.9-2mdv2008.0.x86_64.rpm
 8c78406bc678b51a4c84526b0874703e  2008.0/x86_64/kernel-desktop-latest-2.6.22.9-2mdv2008.0.x86_64.rpm
 8447a07d292dd930bba13a6d06bf6570  2008.0/x86_64/kernel-doc-2.6.22.9-2mdv2008.0.x86_64.rpm
 546663f7f08a1ed4a0e561c06960872e  2008.0/x86_64/kernel-laptop-2.6.22.9-2mdv-1-1mdv2008.0.x86_64.rpm
 482b6130e1695693ebfd610aade49255  2008.0/x86_64/kernel-laptop-devel-2.6.22.9-2mdv-1-1mdv2008.0.x86_64.rpm
 280678d50696a95f56735ad91fcc92ef  2008.0/x86_64/kernel-laptop-devel-latest-2.6.22.9-2mdv2008.0.x86_64.rpm
 f4fedb72b7d286f9b9dae772b8251a7a  2008.0/x86_64/kernel-laptop-latest-2.6.22.9-2mdv2008.0.x86_64.rpm
 c811160740d5c4e138430fb757803bcc  2008.0/x86_64/kernel-server-2.6.22.9-2mdv-1-1mdv2008.0.x86_64.rpm
 1078b15d6cb4a1c420e7212d4a7ca545  2008.0/x86_64/kernel-server-devel-2.6.22.9-2mdv-1-1mdv2008.0.x86_64.rpm
 e127a24e39d458865ebc54e61a7db34b  2008.0/x86_64/kernel-server-devel-latest-2.6.22.9-2mdv2008.0.x86_64.rpm
 347576ae981042a8277c2adcdb433cfc  2008.0/x86_64/kernel-server-latest-2.6.22.9-2mdv2008.0.x86_64.rpm
 464e4b918285dac78af1b2521ebac461  2008.0/x86_64/kernel-source-2.6.22.9-2mdv-1-1mdv2008.0.x86_64.rpm
 affd96915a01aa3927dda61bd1fad19d  2008.0/x86_64/kernel-source-latest-2.6.22.9-2mdv2008.0.x86_64.rpm 
 6e797fd0fea50e2b0290ca082ca9c1db  2008.0/SRPMS/kernel-2.6.22.9-2mdv2007.0.src.rpm

References

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5501

Upgrade

To upgrade automatically, use MandrivaUpdate.


Verification

Please verify the update prior to upgrading to ensure the integrity of the downloaded package. You can do this with the command :

		rpm --checksig package.rpm
		

You can get the GPG public key of the Mandriva Security Team to verify the GPG signature of each RPM.

If you use MandrivaUpdate, the verification of md5 checksum and GPG signature is performed automatically for you.