RHSA-2019:2862: Important: kernel-alt security update
The kernel-alt packages provide the Linux kernel version 4.x.Security Fix(es): A buffer overflow flaw was found in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host. (CVE-2019-14835)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:2862?
The severity of RHSA-2019:2862 is classified as important.
How do I fix RHSA-2019:2862?
To fix RHSA-2019:2862, update the affected kernel-alt and kernel packages to version 4.14.0-115.13.1.el7a.
What vulnerability does RHSA-2019:2862 address?
RHSA-2019:2862 addresses a buffer overflow vulnerability in the Linux kernel's vhost functionality.
What systems are affected by RHSA-2019:2862?
RHSA-2019:2862 affects systems running specific versions of the RHEL kernel-alt and related kernel packages.
Is there a workaround for RHSA-2019:2862?
There is no official workaround for RHSA-2019:2862; applying the recommended updates is the only solution.