First published: Tue Mar 13 2018(Updated: )
The kernel packages contain the Linux kernel, the core of any Linux operating system.<br>Security Fix(es):<br><li> hw: cpu: speculative execution branch target injection (s390-only) (CVE-2017-5715, Important)</li> <li> hw: cpu: speculative execution bounds-check bypass (s390 and powerpc) (CVE-2017-5753, Important)</li> <li> hw: cpu: speculative execution permission faults handling (powerpc-only) (CVE-2017-5754)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> If an NFSv3 client mounted a subdirectory of an exported file system, a directory entry to the mount hosting the export was incorrectly held even after clearing the cache. Consequently, attempts to unmount the subdirectory with the umount command failed with the EBUSY error. With this update, the underlying source code has been fixed, and the unmount operation now succeeds as expected in the described situation. (BZ#1538587)</li> <li> The Return Trampoline (Retpoline) mechanism mitigates the branch target injection, also known as the Spectre variant 2 vulnerability. With this update, Retpoline has been implemented into the Red Hat Enterprise Linux kernel. (BZ#1543023)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/kernel | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/kernel-abi-whitelists | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/kernel-debug | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/kernel-debug-debuginfo | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/kernel-debug-debuginfo | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/kernel-debug-devel | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/kernel-debug-devel | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/kernel-debuginfo | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/kernel-debuginfo | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/kernel-debuginfo-common-i686 | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/kernel-devel | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/kernel-doc | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/kernel-firmware | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/kernel-headers | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/perf | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/perf-debuginfo | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/perf-debuginfo | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/python-perf | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/python-perf-debuginfo | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/python-perf-debuginfo | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/kernel-debug | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/kernel-devel | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/kernel-headers | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/perf | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/python-perf | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/kernel-debuginfo-common-s390x | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/kernel-kdump | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/kernel-kdump-debuginfo | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/kernel-kdump-devel | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/kernel-bootwrapper | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
redhat/kernel-debuginfo-common-ppc64 | <2.6.32-573.53.1.el6 | 2.6.32-573.53.1.el6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2018:0496 is classified as Important.
To fix RHSA-2018:0496, you should update the kernel packages to version 2.6.32-573.53.1.el6.
RHSA-2018:0496 addresses the speculative execution vulnerabilities including branch target injection and bounds-check bypass.
RHSA-2018:0496 affects the Linux kernel versions prior to 2.6.32-573.53.1.el6 on s390 and other architectures.
No, RHSA-2018:0496 specifically applies to Red Hat Enterprise Linux systems.