RHSA-2018:1130: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: Use-after-free vulnerability in DCCP socket (CVE-2017-8824, Important) kernel: v4l2: disabled memory access protection mechanism allowing privilege escalation (CVE-2017-13166, Important) kernel: Incorrect type conversion for size during dma allocation (CVE-2017-9725, Moderate) kernel: Use-after-free in sndseqioctlcreateport() (CVE-2017-15265, Moderate) kernel: Missing namespace check in net/netlink/afnetlink.c allows for network monitors to observe systemwide activity (CVE-2017-17449, Moderate) kernel: netfilter: use-after-free in tcpmssmanglepacket function in net/netfilter/xtTCPMSS.c (CVE-2017-18017, Moderate) kernel: kvm: Reachable BUG() on out-of-bounds guest IRQ (CVE-2017-1000252, Moderate) kernel: Stack information leak in the EFS element (CVE-2017-1000410, Moderate) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.Red Hat would like to thank Mohamed Ghannam for reporting CVE-2017-8824; Jan H. Schönherr (Amazon) for reporting CVE-2017-1000252; and Armis Labs for reporting CVE-2017-1000410.Bug Fix(es):These updated kernel packages include also numerous bug fixes. Space precludes documenting all of these bug fixes in this advisory. See the bug fix descriptions in the related Knowledge Article:https://access.redhat.com/articles/3411331
Affected Software
Remediation
Event History
Frequently Asked Questions
What vulnerabilities are addressed in RHSA-2018:1130?
RHSA-2018:1130 addresses a serious use-after-free vulnerability in the DCCP socket and a vulnerability in the v4l2 memory access protection mechanism.
How do I fix RHSA-2018:1130?
To fix RHSA-2018:1130, update your kernel package to version 3.10.0-693.25.2.el7 or higher.
What is the severity of RHSA-2018:1130?
The severity of RHSA-2018:1130 is categorized as Important due to its potential impact on system security.
What systems are affected by RHSA-2018:1130?
RHSA-2018:1130 affects systems running the kernel packages prior to version 3.10.0-693.25.2.el7.
Are there any specific mitigations for the vulnerabilities in RHSA-2018:1130?
There are no specific mitigations other than applying the recommended kernel updates outlined in RHSA-2018:1130.