RHSA-2019:2864: Important: kernel security update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): A buffer overflow flaw was found in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host. (CVE-2019-14835)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:2864?
The severity of RHSA-2019:2864 is classified as important.
How do I fix RHSA-2019:2864?
To fix RHSA-2019:2864, update the affected packages to the version 3.10.0-957.35.2.el7 or later.
What software is affected by RHSA-2019:2864?
RHSA-2019:2864 affects the kernel and its related packages in the specified version.
Is a workaround available for RHSA-2019:2864?
There are no known workaround options for the vulnerability addressed in RHSA-2019:2864.
What type of vulnerability is described in RHSA-2019:2864?
RHSA-2019:2864 describes a buffer overflow vulnerability in the Linux kernel's vhost functionality.