[elrepo] Announcement: EL5 and EL6 Updated kmod-tg3 Release [3.129d-2][CVE-2013-1929]

Alan Bartlett ajb at elrepo.org
Thu Jul 11 15:37:09 EDT 2013


Announcing the release of updated kmod-tg3 packages into the EL5 and
EL6 elrepo repositories:

http://elrepo.org/tiki/kmod-tg3

This package provides an updated tg3 driver, version 3.129d-2, which
addresses CVE-2013-1929:

A heap-based buffer overflow in the way the driver parsed the vital
product data (VPD) of devices could allow an attacker with physical
access to a system to cause a denial of service or, potentially,
escalate their privileges.

It is built to depend upon the specific ABI provided by a range of
releases of the same variant of the Linux kernel and not on any one
specific build.

The following files are currently syncing to the mirrors:

EL5:

x86
kmod-tg3-3.129d-2.el5.elrepo.i686.rpm
kmod-tg3-PAE-3.129d-2.el5.elrepo.i686.rpm
kmod-tg3-xen-3.129d-2.el5.elrepo.i686.rpm

x86_64
kmod-tg3-3.129d-2.el5.elrepo.x86_64.rpm
kmod-tg3-xen-3.129d-2.el5.elrepo.x86_64.rpm

SRPMS
tg3-kmod-3.129d-2.el5.elrepo.src.rpm

EL6:

x86
kmod-tg3-3.129d-2.el6.elrepo.i686.rpm

x86_64
kmod-tg3-3.129d-2.el6.elrepo.x86_64.rpm

SRPMS
tg3-kmod-3.129d-2.el6.elrepo.src.rpm

You may update your system by:

yum --disablerepo=\* --enablerepo=elrepo update kmod-tg3

Once the package has been installed, remember to unload the existing
driver before loading the updated version into the kernel:

/sbin/ifdown ethN
/sbin/modprobe -r tg3
/sbin/modprobe tg3
/sbin/ifup ethN

Thank you,

The ELRepo Team.


More information about the elrepo mailing list