First published: Tue Aug 13 2019(Updated: )
The kernel packages contain the Linux kernel, the core of any Linux operating system.<br>Security Fix(es):<br><li> kernel: Missing check in fs/inode.c:inode_init_owner() does not clear SGID bit on non-directories for non-members (CVE-2018-13405)</li> <li> kernel: hw: Spectre SWAPGS gadget vulnerability (CVE-2019-1125)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel | <2.6.32-504.80.2.el6 | 2.6.32-504.80.2.el6 |
redhat/kernel | <2.6.32-504.80.2.el6 | 2.6.32-504.80.2.el6 |
redhat/kernel-abi-whitelists | <2.6.32-504.80.2.el6 | 2.6.32-504.80.2.el6 |
redhat/kernel-debug | <2.6.32-504.80.2.el6 | 2.6.32-504.80.2.el6 |
redhat/kernel-debug-debuginfo | <2.6.32-504.80.2.el6 | 2.6.32-504.80.2.el6 |
redhat/kernel-debug-devel | <2.6.32-504.80.2.el6 | 2.6.32-504.80.2.el6 |
redhat/kernel-debuginfo | <2.6.32-504.80.2.el6 | 2.6.32-504.80.2.el6 |
redhat/kernel-devel | <2.6.32-504.80.2.el6 | 2.6.32-504.80.2.el6 |
redhat/kernel-doc | <2.6.32-504.80.2.el6 | 2.6.32-504.80.2.el6 |
redhat/kernel-firmware | <2.6.32-504.80.2.el6 | 2.6.32-504.80.2.el6 |
redhat/kernel-headers | <2.6.32-504.80.2.el6 | 2.6.32-504.80.2.el6 |
redhat/perf | <2.6.32-504.80.2.el6 | 2.6.32-504.80.2.el6 |
redhat/perf-debuginfo | <2.6.32-504.80.2.el6 | 2.6.32-504.80.2.el6 |
redhat/python-perf | <2.6.32-504.80.2.el6 | 2.6.32-504.80.2.el6 |
redhat/python-perf-debuginfo | <2.6.32-504.80.2.el6 | 2.6.32-504.80.2.el6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2019:2476 is classified as important.
To fix RHSA-2019:2476, update the kernel packages to version 2.6.32-504.80.2.el6 or later.
RHSA-2019:2476 addresses vulnerabilities including CVE-2018-13405 related to the SGID bit and issues with Spectre SWAPGS.
RHSA-2019:2476 affects Red Hat Enterprise Linux 6 systems with specific kernel versions up to 2.6.32-504.80.2.el6.
Specific mitigations are not provided; the recommended action is to apply the security update.