DESCRIPTION
The Linux kernel is responsible for handling the basic functions of
the GNU/Linux operating system.
This announcement fixes two local vulnerabilities in the kernel
package:
1) mremap() local vulnerability (CAN-2003-0985[2])
Paul Starzetz <ihaquer_at_isec.pl> from iSEC Security Research
reported[1] another vulnerability in the Linux memory management code
which can be used by local attackers to obtain root privileges or
cause a denial of service condition (DoS).
2) Information leak in RTC code (CAN-2003-0984[3])
Russell King <rmk_at_arm.linux.org.uk> reported that real time clock
(RTC) routines in Linux kernel 2.4.23 and earlier do not properly
initialize their structures, which could leak kernel data to user
space.
SOLUTION
It is recommended that all Conectiva Linux users upgrade the kernel
package.
IMPORTANT: exercise caution and preparation when upgrading the
kernel, since it will require a reboot after the new packages are
installed. In particular, Conectiva Linux 9 will most likely require
an initrd file (which is automatically created in the /boot directory
after the new packages are installed). Generic kernel update
instructions can be obtained in the manuals and in our faq page[4].