RHSA-2009:0411: Moderate security update
41
device when it started monitoring the path. With this update, multipathd now correctly configures the
device, even when udev notices it first, thus resolving the issue.
All users of device-mapper-multipath are advised to upgrade to these updated packages, which
resolve this issue.
1.36.2. RHSA-2009:0411: Moderate security update
Important
This update has already been released (prior to the GA of this release) as the security
errata
RHSA-2009:0411
238
Updated device-mapper-multipath packages that fix a security issue are now available for Red Hat
Enterprise Linux 4 and 5.
This update has been rated as having moderate security impact by the Red Hat Security Response
Team.
The device-mapper multipath packages provide tools to manage multipath devices by issuing
instructions to the device-mapper multipath kernel module, and by managing the creation and removal
of partitions for device-mapper devices.
It was discovered that the multipathd daemon set incorrect permissions on the socket used to
communicate with command line clients. An unprivileged, local user could use this flaw to send
commands to multipathd, resulting in access disruptions to storage devices accessible via multiple
paths and, possibly, file system corruption on these devices. (
CVE-2009-0115
239
)
Users of device-mapper-multipath are advised to upgrade to these updated packages, which contain
a backported patch to resolve this issue. The multipathd service must be restarted for the changes to
take effect.
Important: the version of the multipathd daemon in Red Hat Enterprise Linux 5 has a known issue
which may cause a machine to become unresponsive when the multipathd service is stopped. This
issue is tracked in the Bugzilla bug #494582; a link is provided in the References section of this
erratum. Until this issue is resolved, we recommend restarting the multipathd service by issuing the
following commands in sequence:
# killall -KILL multipathd
# service multipathd restart
1.36.3. RHBA-2009:0283: bug fix update
Note
This update has already been released (prior to the GA of this release) as errata
RHBA-2009:0283
240
239
https://www.redhat.com/security/data/cve/CVE-2009-0115.html
Summary of Contents for ENTERPRISE 5.4 RELEASE NOTES
Page 1: ...Red Hat Enterprise Linux 5 4 Technical Notes Every Change to Every Package ...
Page 18: ...xviii ...
Page 306: ...288 ...
Page 464: ...446 ...
Page 466: ...448 ...