The vendor explicitly identifies these products as affected by this CVE.
- kernel as a component of Red Hat Enterprise Linux 6
- kernel-abi-whitelists as a component of Red Hat Enterprise Linux 6
- kernel-bootwrapper as a component of Red Hat Enterprise Linux 6
- kernel-debug as a component of Red Hat Enterprise Linux 6
- kernel-debug-devel as a component of Red Hat Enterprise Linux 6
- kernel-devel as a component of Red Hat Enterprise Linux 6
- kernel-doc as a component of Red Hat Enterprise Linux 6
- kernel-firmware as a component of Red Hat Enterprise Linux 6
- kernel-headers as a component of Red Hat Enterprise Linux 6
- kernel-kdump as a component of Red Hat Enterprise Linux 6
- kernel-kdump-devel as a component of Red Hat Enterprise Linux 6
- kernel.src as a component of Red Hat Enterprise Linux 6
- Summary
- A flaw was found in the Linux kernel’s SCSI driver component qla2xxx (used with FCP-2 devices). When the terminate_rport_io() function is invoked , the driver may exit cleanup before all outstanding I/O operations have returned. This can lead to a use-after-free condition when resources are freed while I/Os are still pending.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect.
