RHSA-2016:0068: Important: kernel-rt security update
The kernel packages contain the Linux kernel, the core of any Linuxoperating system. A use-after-free flaw was found in the way the Linux kernel's key management subsystem handled keyring object reference counting in certainerror path of the joinsessionkeyring() function. A local, unprivilegeduser could use this flaw to escalate their privileges on the system.(CVE-2016-0728, Important)Red Hat would like to thank the Perception Point research team forreporting this issue.All kernel-rt users are advised to upgrade to these updated packages, whichcontain a backported patch to correct this issue. The system must berebooted for this update to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2016:0068?
The severity of RHSA-2016:0068 is classified as important.
How do I fix RHSA-2016:0068?
To fix RHSA-2016:0068, update to kernel version 3.10.0-327.rt56.170.el6 or later.
What software is affected by RHSA-2016:0068?
Affected software for RHSA-2016:0068 includes various kernel packages such as kernel-rt and kernel-rt-debug.
What type of vulnerability is described in RHSA-2016:0068?
RHSA-2016:0068 describes a use-after-free vulnerability in the Linux kernel's key management subsystem.
When was RHSA-2016:0068 released?
RHSA-2016:0068 was released on February 9, 2016.