ALAS-2013-154


Amazon Linux AMI Security Advisory: ALAS-2013-154
Advisory Release Date: 2014-09-15 22:27 Pacific
Severity: Medium
References: CVE-2013-0190 

Issue Overview:

The xen_failsafe_callback function in Xen for the Linux kernel 2.6.23 and other versions, when running a 32-bit PVOPS guest, allows local users to cause a denial of service (guest crash) by triggering an iret fault, leading to use of an incorrect stack pointer and stack corruption.


Affected Packages:

kernel,nvidia


Issue Correction:
Run yum update kernel nvidia to update your system. You will need to reboot your system in order for the new kernel to be running.

New Packages:
i686:
    kernel-tools-3.2.37-2.47.amzn1.i686
    kernel-headers-3.2.37-2.47.amzn1.i686
    kernel-debuginfo-3.2.37-2.47.amzn1.i686
    kernel-devel-3.2.37-2.47.amzn1.i686
    kernel-tools-debuginfo-3.2.37-2.47.amzn1.i686
    kernel-3.2.37-2.47.amzn1.i686
    kernel-debuginfo-common-i686-3.2.37-2.47.amzn1.i686

noarch:
    kernel-doc-3.2.37-2.47.amzn1.noarch

src:
    kernel-3.2.37-2.47.amzn1.src
    nvidia-313.18-2012.09.0.amzn1.src

x86_64:
    kernel-debuginfo-common-x86_64-3.2.37-2.47.amzn1.x86_64
    kernel-devel-3.2.37-2.47.amzn1.x86_64
    kernel-3.2.37-2.47.amzn1.x86_64
    kernel-debuginfo-3.2.37-2.47.amzn1.x86_64
    kernel-tools-debuginfo-3.2.37-2.47.amzn1.x86_64
    kernel-headers-3.2.37-2.47.amzn1.x86_64
    kernel-tools-3.2.37-2.47.amzn1.x86_64
    nvidia-kmod-3.2.37-2.47.amzn1-313.18-2012.09.0.amzn1.x86_64
    nvidia-313.18-2012.09.0.amzn1.x86_64