[RHSA-2019:0514] kernel-rt security and bug fix update
Severity
Important
Affected Packages
10
CVEs
3
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.
Security Fix(es):
kernel: Memory corruption due to incorrect socket cloning (CVE-2018-9568)
kernel: Unprivileged users able to inspect kernel stacks of arbitrary tasks (CVE-2018-17972)
kernel: Faulty computation of numberic bounds in the BPF verifier (CVE-2018-18445)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
- kernel-rt: update to the RHEL7.6.z batch#3 source tree (BZ#1672406)
Users of kernel-rt are advised to upgrade to these updated packages, which fix this bug.
Package | Affected Version |
---|---|
pkg:rpm/redhat/kernel-rt?arch=x86_64&distro=redhat-7 | < 3.10.0-957.10.1.rt56.921.el7 |
pkg:rpm/redhat/kernel-rt-trace?arch=x86_64&distro=redhat-7 | < 3.10.0-957.10.1.rt56.921.el7 |
pkg:rpm/redhat/kernel-rt-trace-kvm?arch=x86_64&distro=redhat-7 | < 3.10.0-957.10.1.rt56.921.el7 |
pkg:rpm/redhat/kernel-rt-trace-devel?arch=x86_64&distro=redhat-7 | < 3.10.0-957.10.1.rt56.921.el7 |
pkg:rpm/redhat/kernel-rt-kvm?arch=x86_64&distro=redhat-7 | < 3.10.0-957.10.1.rt56.921.el7 |
pkg:rpm/redhat/kernel-rt-doc?distro=redhat-7 | < 3.10.0-957.10.1.rt56.921.el7 |
pkg:rpm/redhat/kernel-rt-devel?arch=x86_64&distro=redhat-7 | < 3.10.0-957.10.1.rt56.921.el7 |
pkg:rpm/redhat/kernel-rt-debug?arch=x86_64&distro=redhat-7 | < 3.10.0-957.10.1.rt56.921.el7 |
pkg:rpm/redhat/kernel-rt-debug-kvm?arch=x86_64&distro=redhat-7 | < 3.10.0-957.10.1.rt56.921.el7 |
pkg:rpm/redhat/kernel-rt-debug-devel?arch=x86_64&distro=redhat-7 | < 3.10.0-957.10.1.rt56.921.el7 |
- ID
- RHSA-2019:0514
- Severity
- important
- URL
- https://access.redhat.com/errata/RHSA-2019:0514
- Published
-
2019-03-13T00:00:00
(5 years ago) - Modified
-
2019-03-13T00:00:00
(5 years ago) - Rights
- Copyright 2019 Red Hat, Inc.
- Other Advisories
-
- ALAS-2018-1100
- ALAS2-2018-1100
- ASA-201811-1
- ASA-201811-2
- ELSA-2019-0512
- ELSA-2019-2473
- ELSA-2019-2736
- ELSA-2019-4531
- ELSA-2019-4532
- ELSA-2019-4541
- ELSA-2019-4575
- ELSA-2019-4576
- ELSA-2019-4577
- FEDORA-2018-2ee3411cb8
- FEDORA-2018-9f4381d8c4
- FEDORA-2018-ec3bf1b228
- openSUSE-SU-2019:0065-1
- RHSA-2019:0512
- RHSA-2019:2473
- RHSA-2019:2736
- SSA:2019-030-01
- SUSE-SU-2018:3589-1
- SUSE-SU-2018:3593-1
- SUSE-SU-2018:3934-1
- SUSE-SU-2018:3961-1
- SUSE-SU-2018:4069-1
- SUSE-SU-2018:4072-1
- SUSE-SU-2018:4153-1
- SUSE-SU-2018:4154-1
- SUSE-SU-2018:4157-1
- SUSE-SU-2018:4158-1
- SUSE-SU-2018:4195-1
- SUSE-SU-2018:4196-1
- SUSE-SU-2018:4238-1
- SUSE-SU-2019:0148-1
- SUSE-SU-2019:0150-1
- SUSE-SU-2019:0196-1
- SUSE-SU-2019:0222-1
- SUSE-SU-2019:0224-1
- SUSE-SU-2019:0320-1
- SUSE-SU-2019:0439-1
- SUSE-SU-2019:0541-1
- SUSE-SU-2019:1289-1
- SUSE-SU-2019:1527-1
- SUSE-SU-2019:1532-1
- SUSE-SU-2019:1533-1
- SUSE-SU-2019:1534-1
- SUSE-SU-2019:1692-1
- USN-3821-1
- USN-3821-2
- USN-3832-1
- USN-3835-1
- USN-3847-1
- USN-3847-2
- USN-3847-3
- USN-3871-1
- USN-3871-3
- USN-3871-4
- USN-3871-5
- USN-3880-1
- USN-3880-2
Source | # ID | Name | URL |
---|---|---|---|
Bugzilla | 1636349 | https://bugzilla.redhat.com/1636349 | |
Bugzilla | 1640596 | https://bugzilla.redhat.com/1640596 | |
Bugzilla | 1655904 | https://bugzilla.redhat.com/1655904 | |
RHSA | RHSA-2019:0514 | https://access.redhat.com/errata/RHSA-2019:0514 | |
CVE | CVE-2018-17972 | https://access.redhat.com/security/cve/CVE-2018-17972 | |
CVE | CVE-2018-18445 | https://access.redhat.com/security/cve/CVE-2018-18445 | |
CVE | CVE-2018-9568 | https://access.redhat.com/security/cve/CVE-2018-9568 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/redhat/kernel-rt?arch=x86_64&distro=redhat-7 | redhat | kernel-rt | < 3.10.0-957.10.1.rt56.921.el7 | redhat-7 | x86_64 | |
Affected | pkg:rpm/redhat/kernel-rt-trace?arch=x86_64&distro=redhat-7 | redhat | kernel-rt-trace | < 3.10.0-957.10.1.rt56.921.el7 | redhat-7 | x86_64 | |
Affected | pkg:rpm/redhat/kernel-rt-trace-kvm?arch=x86_64&distro=redhat-7 | redhat | kernel-rt-trace-kvm | < 3.10.0-957.10.1.rt56.921.el7 | redhat-7 | x86_64 | |
Affected | pkg:rpm/redhat/kernel-rt-trace-devel?arch=x86_64&distro=redhat-7 | redhat | kernel-rt-trace-devel | < 3.10.0-957.10.1.rt56.921.el7 | redhat-7 | x86_64 | |
Affected | pkg:rpm/redhat/kernel-rt-kvm?arch=x86_64&distro=redhat-7 | redhat | kernel-rt-kvm | < 3.10.0-957.10.1.rt56.921.el7 | redhat-7 | x86_64 | |
Affected | pkg:rpm/redhat/kernel-rt-doc?distro=redhat-7 | redhat | kernel-rt-doc | < 3.10.0-957.10.1.rt56.921.el7 | redhat-7 | ||
Affected | pkg:rpm/redhat/kernel-rt-devel?arch=x86_64&distro=redhat-7 | redhat | kernel-rt-devel | < 3.10.0-957.10.1.rt56.921.el7 | redhat-7 | x86_64 | |
Affected | pkg:rpm/redhat/kernel-rt-debug?arch=x86_64&distro=redhat-7 | redhat | kernel-rt-debug | < 3.10.0-957.10.1.rt56.921.el7 | redhat-7 | x86_64 | |
Affected | pkg:rpm/redhat/kernel-rt-debug-kvm?arch=x86_64&distro=redhat-7 | redhat | kernel-rt-debug-kvm | < 3.10.0-957.10.1.rt56.921.el7 | redhat-7 | x86_64 | |
Affected | pkg:rpm/redhat/kernel-rt-debug-devel?arch=x86_64&distro=redhat-7 | redhat | kernel-rt-debug-devel | < 3.10.0-957.10.1.rt56.921.el7 | redhat-7 | x86_64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |