RHSA-2019:2830: Important: kernel-rt security update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): A buffer overflow flaw was found in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host. (CVE-2019-14835)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:2830?
The severity of RHSA-2019:2830 is classified as Important.
How do I fix RHSA-2019:2830?
To fix RHSA-2019:2830, you need to update to kernel-rt version 3.10.0-1062.1.2.rt56.1025.el7 or later.
Which systems are affected by RHSA-2019:2830?
RHSA-2019:2830 affects systems running the Real Time Linux Kernel versions up to 3.10.0-1062.1.2.rt56.1025.el7.
What type of vulnerability is reported in RHSA-2019:2830?
RHSA-2019:2830 reports a buffer overflow vulnerability in the Linux kernel's vhost functionality.
Is there a reference for more details on RHSA-2019:2830?
You can find more information about RHSA-2019:2830 in the Red Hat bug tracker and security advisories.