From: bugzilla at (
Subject: [RHSA-2002:206-12] New kernel fixes local security issues

                   Red Hat, Inc. Red Hat Security Advisory

Synopsis:          New kernel fixes local security issues
Advisory ID:       RHSA-2002:206-12
Issue date:        2002-09-23
Updated on:        2002-10-15
Product:           Red Hat Linux
Cross references:  
Obsoletes:         RHBA-2002:110

1. Topic:

Updated kernel fixes local security issues and provides several updated
drivers to support newer hardware and fix bugs under Red Hat Linux 7.3.

2. Relevant releases/architectures:

Red Hat Linux 7.3 - athlon, i386, i586, i686, noarch
Red Hat Linux 8.0 - athlon, i386, i586, i686, noarch

3. Problem description:

The Linux kernel handles the basic functions of the operating system. A
security code audit of the 2.4 kernel found a number of possible local
security vulnerabilities which could allow a local user to obtain elevated
(root) privileges. The vulnerabilities were found in the ixj telephony card
driver, the pcilynx firewire driver, and the bttv video capture card driver.

In addition, several drivers (e100, e1000, tg3n and IDE) have been updated
to support newer hardware for Red Hat Linux 7.3, and a number of bugs have
been fixed in IDE tapestreamer driver.

All Red Hat Linux 7.3 and 8.0 users should upgrade to this errata kernel
which is not vulnerable to these security issues.

NOTE: As with the 8.0 release, IDE DMA on CD-ROM drives is disabled by
default. If you are sure that your CD-ROM drive is capable of IDE
DMA, place the following line in the /etc/modules.conf file:

options ide-cd dma=1

Thanks to Silvio Cesare for finding the local security issues.

4. Solution:

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

The procedure for upgrading the kernel manually is documented at:

Please read the directions for your architecture carefully before
proceeding with the kernel upgrade.

Please note that this update is also available via Red Hat Network. Many
people find this to be an easier way to apply updates. To use Red Hat
Network, launch the Red Hat Update Agent with the following command:


This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system. Note that you need to select the kernel
explicitly on default configurations of up2date.

5. Bug IDs fixed ( for more info):

73339 - apm locks up Asus A7N266VM (nForce chipset)
74879 - aha152x driver broken
71622 - cs4232 module is not auto-loaded on use
75107 - boot time in /proc/stat is incorrect
75113 - /proc/uptime shows wrong uptime (slightly) and idle time (totally)
74589 - speedstep doesn't work on IBM ThinkPad T30 (pentium 4)

6. RPMs required:

These packages are GPG signed by Red Hat, Inc. for security.  Our key
is available at:

You can verify each package with the following command:
    rpm --checksig  <filename>

If you only wish to verify that each package has not been corrupted or
tampered with, examine only the md5sum with the following command:
    rpm --checksig --nogpg <filename>

8. References:

Copyright(c) 2000, 2001, 2002 Red Hat, Inc.

