RHSA-2019:2566: Important: kernel security, bug fix, and enhancement update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: Missing check in fs/inode.c:inodeinitowner() does not clear SGID bit on non-directories for non-members (CVE-2018-13405) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): [Dell EMC 7.6 BUG] File system corrupting with I/O Stress on H330 PERC on AMD Systems (BZ#1698337) [RHEL7.7] Refined TSC clocksource calibration occasionally fails on some SkyLake-X servers (BZ#1719780) Poor system performance from thundering herd of kworkers competing for mddev->flushbio ownership (BZ#1721533) fragmented packets timing out (BZ#1729412) After update to RHEL 7.6 (3.10.0-957.1.3.el7.x8664) from 7.4, customer has experienced multiple panics in kernel at BUG at drivers/iommu/iova.c:859! (BZ#1731299) kernel build: speed up debuginfo extraction (BZ#1731463) Enhancement(s): [Intel 7.6 FEAT] Graphics Kernel Driver v4.15 updates (BZ#1716309)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:2566?
The severity of RHSA-2019:2566 is classified as important.
How do I fix RHSA-2019:2566?
To fix RHSA-2019:2566, update the kernel packages to version 3.10.0-862.41.1.el7 or later.
What vulnerability does RHSA-2019:2566 address?
RHSA-2019:2566 addresses a missing check in inode_init_owner() that does not clear the SGID bit on non-directories for non-members, identified by CVE-2018-13405.
Which versions of the kernel are affected by RHSA-2019:2566?
Versions of the kernel prior to 3.10.0-862.41.1.el7 are affected by RHSA-2019:2566.
What packages are affected by RHSA-2019:2566?
RHSA-2019:2566 affects various kernel packages including kernel, kernel-debug, kernel-devel, and others within the specified version range.