Help - Search - Members - Calendar
Full Version: New Kernel (RHEL3)
The Planet Forums > Security > General Security > UNIX Security
Blue|Fusion
Please note there have been several new packages released today as well as a new kernel (2.4.21-27.EL).

To update, run the following:

up2date -uf kernel kernel-smp kernel-source

I'm updating now and I'll fill you in on how it goes.
Blue|Fusion
Updated and restarted...no problems yet.
damainman
why did they release a new one so soon? I haven't got an email alert about it. Is SM supporting this one?
budway
The request info can be obtained on the following link.


https://rhn.redhat.com/errata/rhel3es-errata.html
revo
There's an update to the just recently released kernel.
budway
QUOTE (revo)
There's an update to the just recently released kernel.


Really ?

These are the updates betwen day 20 and 23 of this month:

https://rhn.redhat.com/errata/rhel3es-errata.html


Date Advisory Synopsis

2004-12-23 RHBA-2004:696 Updated BIND packages
2004-12-23 RHSA-2004:651 Updated imlib packages fix security vulnerabilities
2004-12-23 RHSA-2004:654 Updated SquirrelMail package fixes security vulnerability
2004-12-23 RHSA-2004:674 Updated acrobat package fixes security issue
2004-12-23 RHSA-2004:689 Updated kernel packages fix security vulnerabilities
2004-12-21 RHBA-2004:501 Updated rpm package
2004-12-21 RHBA-2004:509 Updated kudzu packages
2004-12-21 RHBA-2004:511 Updated initscripts package
2004-12-21 RHBA-2004:512 Updated modutils packages
2004-12-21 RHBA-2004:513 Updated ipsec-tools package
2004-12-21 RHBA-2004:514 Updated devlabel package
2004-12-21 RHBA-2004:520 Updated autofs package
2004-12-21 RHBA-2004:524 Updated tcsh package
2004-12-21 RHBA-2004:525 Updated vsftpd package
2004-12-21 RHBA-2004:531 Updated metacity package
2004-12-21 RHBA-2004:532 Updated tftp packages
2004-12-21 RHBA-2004:535 Updated net-tools package
2004-12-21 RHBA-2004:540 Updated usermode package
2004-12-21 RHBA-2004:544 Updated procps package
2004-12-21 RHBA-2004:551 Updated pam packages
2004-12-21 RHBA-2004:556 Updated flash-plugin package
2004-12-21 RHBA-2004:561 Updated gdb and libunwind packages
2004-12-21 RHBA-2004:566 Updated dhcp and dhclient packages
2004-12-21 RHBA-2004:567 Updated bind packages
2004-12-21 RHBA-2004:568 Updated caching-nameserver package
2004-12-21 RHBA-2004:573 Updated redhat-config-netboot package
2004-12-21 RHBA-2004:574 Updated evolution package
2004-12-21 RHBA-2004:578 Updated ypserv package
2004-12-21 RHBA-2004:579 Updated quota package
2004-12-21 RHBA-2004:581 Updated firstboot package
2004-12-21 RHBA-2004:582 Updated rhn-applet package
2004-12-21 RHBA-2004:584 Updated gcc packages
2004-12-21 RHBA-2004:588 Updated net-snmp packages
2004-12-21 RHBA-2004:593 Updated at package
2004-12-21 RHBA-2004:594 Updated busybox package
2004-12-21 RHBA-2004:595 Updated yp-tools package
2004-12-21 RHBA-2004:598 Updated spamassassin package
2004-12-21 RHBA-2004:599 Updated perl-DateManip package
2004-12-21 RHBA-2004:601 Updated util-linux package available
2004-12-21 RHBA-2004:607 Updated jpackage-utils package
2004-12-21 RHBA-2004:616 Updated python packages
2004-12-21 RHBA-2004:630 Updated kernel-utils package
2004-12-21 RHBA-2004:643 Updated libuser packages
2004-12-21 RHBA-2004:656 Updated redhat-lsb package
2004-12-21 RHBA-2004:660 Updated redhat-config-securitylevel packages
2004-12-21 RHEA-2004:510 Updated hwdata package
2004-12-21 RHEA-2004:518 Updated anaconda and pump packages
2004-12-21 RHEA-2004:526 Updated vim packages
2004-12-21 RHEA-2004:530 New iscsi-initiator-tools package
2004-12-21 RHEA-2004:542 Updated krb5 packages
2004-12-21 RHEA-2004:545 Updated gimp-print packages
2004-12-21 RHEA-2004:570 Updated laus package
2004-12-21 RHEA-2004:571 Updated amtu package
2004-12-21 RHEA-2004:572 Updated eal3-certification packages
2004-12-21 RHEA-2004:580 Updated up2date packages
2004-12-21 RHEA-2004:589 Updated lvm package
2004-12-21 RHEA-2004:590 Updated tzdata package
2004-12-21 RHEA-2004:603 New perl-Crypt-SSLeay package
2004-12-21 RHEA-2004:608 Updated java-1.4.2-ibm packages
2004-12-21 RHEA-2004:680 New redhat-release package for Red Hat Enterprise Linux 3 Update 4
2004-12-21 RHEA-2004:682 New comps package for Red Hat Enterprise Linux 3 Update 4
2004-12-21 RHEA-2004:683 New rpmdb-redhat package for Red Hat Enterprise Linux 3 Update 4
2004-12-21 RHSA-2004:687 Updated php packages fix security issues and bugs
2004-12-20 RHBA-2004:423 Updated redhat-config-services package
2004-12-20 RHBA-2004:435 Updated redhat-config-date package
2004-12-20 RHBA-2004:443 Updated xscreensaver package
2004-12-20 RHBA-2004:450 Updated vte package
2004-12-20 RHBA-2004:461 Updated VNC packages
2004-12-20 RHBA-2004:471 Updated openssh packages
2004-12-20 RHBA-2004:472 Updated shadow-utils package
2004-12-20 RHBA-2004:473 Updated redhat-config-printer packages
2004-12-20 RHBA-2004:477 Updated rusers packages
2004-12-20 RHBA-2004:481 Updated mailman package
2004-12-20 RHBA-2004:485 Updates ypbind package
2004-12-20 RHBA-2004:492 Updated iputils package
2004-12-20 RHBA-2004:497 Updated psacct package
2004-12-20 RHBA-2004:500 Updated esound package
2004-12-20 RHBA-2004:506 Updated sysstat package
2004-12-20 RHBA-2004:541 Updated man-pages package
2004-12-20 RHBA-2004:550 Updated kernel packages available for Red Hat Enterprise Linux 3 Update 4
2004-12-20 RHBA-2004:557 Updated redhat-config-users package
2004-12-20 RHBA-2004:565 Updated packages fix multilib conflicts
2004-12-20 RHEA-2004:468 Updated sysreport package
2004-12-20 RHEA-2004:488 Updated gtk2, pango and librsvg2 packages
2004-12-20 RHSA-2004:489 Updated rh-postgresql packages
2004-12-20 RHSA-2004:583 Updated nfs-utils package fixes security vulnerabilities
2004-12-20 RHSA-2004:586 Updated glibc packages
2004-12-20 RHSA-2004:612 Updated XFree86 packages fix security issues
revo
2004-12-23 RHSA-2004:689 Updated kernel packages fix security vulnerabilities icon_rolleyes.gif
budway
QUOTE (revo)
2004-12-23 RHSA-2004:689 Updated kernel packages fix security vulnerabilities icon_rolleyes.gif



There are many many updates release this month.
I guess lott's of vul. was found and patch, that's goood.... really good!
voth
QUOTE (budway)
QUOTE (revo)
2004-12-23 RHSA-2004:689 Updated kernel packages fix security vulnerabilities icon_rolleyes.gif



There are many many updates release this month.
I guess lott's of vul. was found and patch, that's goood.... really good!


It's only as good as the current fix
APC Hosting
Seems my server has buggered up somehwere, I think it might be something to do with the kernel upgrade steve (rack911 ) done last night.

I got this email

IMPORTANT: Do not ignore this email.
The hostname (server1.MY DOMAIN) resolves to . It should resolve to SERVER IP. Please be sure to correct /etc/hosts as well as the 'A' entry in zone file for the domain.

Some are all of these problems can be caused by
/etc/resolv.conf being setup incorrectly. Please check this file if you
believe everything else is correct.


You may be able to
automaticly correct this problem by using the ' Add an A entry for your
hostname ' under ' Dns Functions ' in your Web Host Manager


I try to do what email says but get this

IP=SERVER IP Bind reloading on server1 using rndc zone: [MY DOMAIN] Error reloading bind on server1: rndc: connect failed: connection refused Add Complete

Any ideas on this?

Andrew
adamuk
upgraded hour ago so far so good.
Blue|Fusion
Upgraded last night to 2.4.21-27.0.1.ELsmp and running fine.
gordonrp
Do SM upgrade the kernel on boxes with silver services for free?

gp
Blue|Fusion
Yes. You just submit a ticket to update the kernel to the latest one via up2date and they will update it. They will not reboot the server; you have that honor wink.gif .

Honestly...kernel updates via up2date are very very very simple to do. Here is a very fast and easy way of doing it:
up2date -uf kernel kernel-smp kernel-doc kernel-utils kernel-source

Once all done (and some may packages say already up to date):
vi /boot/grub/grub.conf
Edit the default= value to the appropriate kernel. They are listed in there from 0, not 1. If the first kernel listed in their is the latest SMP kernel you updated to, you would enter the 0 value for default. If the SMP is first, but you don't need SMP support, then you would use 1.

Once that is complete, save the file and reboot your server.

Once rebooted:
rpm -qa | grep kernel

You will get a list that will look like this:
root@solaris [~]# rpm -qa | grep kernel
kernel-doc-2.4.21-27.0.1.EL
kernel-utils-2.4-8.37.7
kernel-2.4.21-27.0.1.EL
kernel-2.4.21-27.EL
kernel-smp-2.4.21-27.0.1.EL
kernel-smp-2.4.21-27.EL
kernel-pcmcia-cs-3.1.31-13
kernel-source-2.4.21-27.0.1.EL

The 2 in orange are the older kernels which can safely be deleted (assuming your not running them, and use uname -r to confirm) with the following:
rpm -e kernel-2.4.21-27.EL kernel-smp-2.4.21-27.EL

It seems difficult reading it, but it really takes under 3 minutes to do. Usually even less than that.
gordonrp
Thanks, Im sure I could probably handle it myself. But if they don't mind doing it then I would rather have them do it.

cheers,
gp
Blue|Fusion
QUOTE (gordonrp)
Thanks, Im sure I could probably handle it myself. But if they don't mind doing it then I would rather have them do it.

cheers,
gp


Well there's no fun in that...plus this is how you learn things ;-)

When I got my first server in May I didn't know what a kernel was let alone how to update it. lol.
dezignguy
QUOTE (Blue|Fusion)
Well there's no fun in that...plus this is how you learn things ;-)


Like how much downtime your customers can take? When you screwed up a kernel and your server won't boot? ;-)
Blue|Fusion
If you screw up a kernel...thats why you leave an old one on and a tech can come by and select that kernel on boot.

I have only had one incident with downtime from a kernel upgrade which happened to be a corrupted install of the kernel RPM anyway, but the tech took care of that within 10 minutes. icon_biggrin.gif
budway
QUOTE (dezignguy)
QUOTE (Blue|Fusion)
Well there's no fun in that...plus this is how you learn things ;-)


Like how much downtime your customers can take? When you screwed up a kernel and your server won't boot? ;-)


Your on the right side....(safe side) If the person is not confortable doing kernel upgrade they should not perform does on a live/prodution machine...

If you wanna learn get a really old pc and load linux on it you can play and harm no one icon_cry.gif
gordonrp
Exactly, thanks for the info etc. I will have SM take care of it. I am willing to experiment, and I have a c omputer setup here for that.

gp
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.