RHSA-2019:2865: Important: kpatch-patch security update
This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel.Security Fix(es): A buffer overflow flaw was found in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host. (CVE-2019-14835) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 3_10_0-957_35_1-1-1.el7 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 3_10_0-957_35_1-debuginfo-1-1.el7 - Upgrade
Upgrade
kpatch-patch-3_10_0-957_35_1-1-1.el7to a version that resolves this vulnerability.Fixed in 3_10_0-957_35_1-1-1.el7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch kpatch-patch-3_10_0-957_35_1-debuginfo-1-1.el7
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:2865?
The severity of RHSA-2019:2865 is classified as important.
How do I fix RHSA-2019:2865?
To fix RHSA-2019:2865, you should update the kpatch-patch package to version 3_10_0-957_35_1-1-1.el7.
What systems are affected by RHSA-2019:2865?
RHSA-2019:2865 affects systems using the kpatch-patch package with specific versions as outlined in the advisory.
What vulnerabilities does RHSA-2019:2865 address?
RHSA-2019:2865 addresses a buffer overflow flaw in the Linux kernel's vhost functionality.
Is there a specific kernel version required for RHSA-2019:2865?
Yes, RHSA-2019:2865 requires the kernel version to be 3_10_0-957_35_1 for the patch to be effective.