RHSA-2018:0181: Important: kernel-rt security and bug fix update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): A flaw was found in the Linux kernel's key management system where it was possible for an attacker to escalate privileges or crash the machine. If a user key gets negatively instantiated, an error code is cached in the payload area. A negatively instantiated key may be then be positively instantiated by updating it with valid data. However, the ->update key type method must be aware that the error code may be there. (CVE-2015-8539, Important) It was found that fanoutadd() in 'net/packet/afpacket.c' in the Linux kernel, before version 4.13.6, allows local users to gain privileges via crafted system calls that trigger mishandling of packetfanout data structures, because of a race condition (involving fanoutadd and packetdobind) that leads to a use-after-free bug. (CVE-2017-15649, Important) A vulnerability was found in the Linux kernel where the keyctlsetreqkeykeyring() function leaks the thread keyring. This allows an unprivileged local user to exhaust kernel memory and thus cause a DoS. (CVE-2017-7472, Moderate) Red Hat would like to thank Dmitry Vyukov of Google engineering for reporting CVE-2015-8539.Bug Fix(es): The mlx5 driver has a number of configuration options, including the selective support for network protocols, such as InfiniBand and Ethernet. Due to a regression in the configuration of the MRG-RT kernel, the Ethernet mode of the driver was turned off. The regression has been resolved by enabling the mlx5 Ethernet mode, making the Ethernet protocol to work again. (BZ#1422778) The migratedisable/enable() kernel operations are used to pin a thread to a CPU temporarily. This method is a kernel-rt specific. To keep RHEL-RT's kernel up-to-date with the latest real-time kernel, the migratedisable/enable routine was updated to the version present on kernel v4.9-rt. However, this version showed to be problematic. The changes in the migratedisable/enabled have been thus reverted to a stable version, avoiding the kernel BUG. (BZ#1507831) The kernel-rt packages have been upgraded to version 3.10.0-693.15.1.rt56.601, which provides a number of security and bug fixes over the previous version. (BZ#1519504)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2018:0181?
RHSA-2018:0181 has a medium severity rating due to a flaw in the kernel's key management allowing potential privilege escalation.
How do I fix RHSA-2018:0181?
To fix RHSA-2018:0181, update to the kernel-rt package version 3.10.0-693.17.1.rt56.604.el6.
What software is affected by RHSA-2018:0181?
The impacted software includes various kernel-rt packages such as kernel-rt, kernel-rt-debug, and kernel-rt-debuginfo among others.
Is RHSA-2018:0181 related to real-time systems?
Yes, RHSA-2018:0181 pertains to vulnerabilities in the Real Time Linux Kernel, which is critical for high determinism requirements in systems.
What are the potential risks if RHSA-2018:0181 is not addressed?
If RHSA-2018:0181 is not addressed, systems may remain susceptible to privilege escalation attacks.