RHSA-2019:2837: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): Kernel: page cache side channel attacks (CVE-2019-5489) kernel: a NULL pointer dereference in drivers/scsi/megaraid/megaraidsasbase.c leading to DoS (CVE-2019-11810) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): [RHEL7.7] Refined TSC clocksource calibration occasionally fails on some SkyLake-X servers (BZ#1719781) tc: incorrect flows statistic on bond device (shared block) (BZ#1719786) Qlogic qla2xxx driver version 10.x.x.x pins all irq requests to cpu0 and associated cores (BZ#1720956) libceph: handle an empty authorize reply (BZ#1722769) RHEL7.6 - pkey: Indicate old mkvp only if old and curr. mkvp are different (BZ#1723153) RHEL7.6 - qdio: clear intparm during shutdown (BZ#1723154) [RHEL7] Fix Spectre V1 vulnerability in vhost code (BZ#1724079) [Stratus] 802.3ad bond group member disabled after reboot (or I/O failure testing) (BZ#1725037) Accept validate negotiate if server returns NTSTATUSNOTSUPPORTED. (BZ#1726563) [Regression] RHEL7.6 - losing dirty bit during THP splitting, possible memory corruption (mm-) (BZ#1727108) [Intel 7.7 BUG] BUG: unable to handle kernel paging request at 000000006b4fd010 (BZ#1727110) KVM tracebacks causing significant latency to VM (BZ#1728174) NULL pointer dereference in vxlandellink+0xaa (BZ#1728198) [rhel7]NULL pointer dereference at vxlanfillmetadatadst (BZ#1728199) After update to RHEL 7.6 (3.10.0-957.1.3.el7.x8664) from 7.4, customer has experienced multiple panics in kernel at BUG at drivers/iommu/iova.c:859! (BZ#1731300) kernel build: speed up debuginfo extraction (BZ#1731464) hpsa driver hard lockup trying to complete a no longer valid completion on the stack (BZ#1731980) XFS: forced shutdown in xfstranscancel during create near ENOSPC (BZ#1731982) TCP packets are segmented when sent to the VLAN device when coming from VXLAN dev. (BZ#1732812) panic handing smb2reconnect due to a use after free (BZ#1737381) Backport TCP follow-up for small buffers (BZ#1739129)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:2837?
The severity of RHSA-2019:2837 is classified as important due to the potential for denial of service and security vulnerabilities.
How do I fix RHSA-2019:2837?
To fix RHSA-2019:2837, update the kernel packages to version 3.10.0-957.35.1.el7 or later.
What vulnerabilities are addressed in RHSA-2019:2837?
RHSA-2019:2837 addresses vulnerabilities such as page cache side channel attacks (CVE-2019-5489) and a NULL pointer dereference that can lead to denial of service.
Which systems are affected by RHSA-2019:2837?
Systems running the relevant kernel and related packages such as kernel-devel, kernel-debug, and kernel-tools are affected by RHSA-2019:2837.
Is there a risk of data loss from the vulnerabilities in RHSA-2019:2837?
While RHSA-2019:2837 specifically mentions denial of service vulnerabilities, there is a potential risk of data loss if an attacker exploits these issues.