RHSA-2019:2809: Important: kernel-alt security, bug fix, and enhancement update
The kernel-alt packages provide the Linux kernel version 4.x.<br>Security Fix(es):<br><li> Kernel: page cache side channel attacks (CVE-2019-5489)</li> <li> Kernel: KVM: potential use-after-free via kvmioctlcreatedevice() (CVE-2019-6974)</li> <li> kernel: broken permission and object lifetime handling for PTRACETRACEME (CVE-2019-13272)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> [kernel-alt]: BUG: unable to handle kernel NULL pointer IP: cryptoremovespawns+0x118/0x2e0 (BZ#1536967)</li> <li> [HPE Apache] update ssif maxxmitmsgsize limit for multi-part messages (BZ#1610534)</li> <li> RHEL-Alt-7.6 - powerpc/pseries: Fix unitialized timer reset on migration / powerpc/pseries/mobility: Extend start/stop topology update scope (LPM) (BZ#1673613)</li> <li> RHEL-Alt-7.6 - s390: sha3generic module fails and triggers panic when in FIPS mode (BZ#1673979)</li> <li> RHEL-Alt-7.6 - System crashed after oom - During ICP deployment (BZ#1710304)</li> <li> kernel-alt: Race condition in hashtables [rhel-alt-7.6.z] (BZ#1712127)</li> <li> RHEL-Alt-7.6 - OP930:PMTest:cpupower -r command set values for first 3 cores in quad and misses last core. (CORAL) (BZ#1717836)</li> <li> RHEL-Alt-7.6 - disable runtime NUMA remapping for PRRN/LPM/VPHN (BZ#1717906)</li> <li> fragmented packets timing out (BZ#1729066)</li> <li> Backport TCP follow-up for small buffers (BZ#1733617)</li> Enhancement(s):<br><li> RHEL-Alt-7.6 - perfevent PMDA cannot create file descriptors for reading nest events using the perf API (pcp/kernel) (CORAL) (BZ#1723036)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:2809?
The severity of RHSA-2019:2809 is categorized as important.
How do I fix RHSA-2019:2809?
To fix RHSA-2019:2809, update the affected packages to the specified version 4.14.0-115.12.1.el7a.
What vulnerabilities are addressed in RHSA-2019:2809?
RHSA-2019:2809 addresses vulnerabilities including CVE-2019-5489 and CVE-2019-6974.
Which packages are affected by RHSA-2019:2809?
Affected packages include kernel-alt, kernel, and several related kernel packages.
Is RHSA-2019:2809 relevant for all Linux kernel versions?
RHSA-2019:2809 is specifically relevant for Linux kernel version 4.14.0-115.12.1.el7a.