RHSA-2019:2866: Important: kernel security update
The kernel packages contain the Linux kernel, the core of any Linux operating system.<br>Security Fix(es):<br><li> A buffer overflow flaw was found in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host. (CVE-2019-14835)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:2866?
The vulnerability RHSA-2019:2866 has a medium severity rating due to the potential for a buffer overflow in the Linux kernel's vhost functionality.
How do I fix RHSA-2019:2866?
To fix RHSA-2019:2866, you need to upgrade to kernel version 3.10.0-862.41.2.el7 or later.
What systems are affected by RHSA-2019:2866?
Systems running versions of the Red Hat kernel prior to 3.10.0-862.41.2.el7 are affected by RHSA-2019:2866.
What type of vulnerability does RHSA-2019:2866 describe?
RHSA-2019:2866 describes a buffer overflow vulnerability in the Linux kernel related to vhost functionality.
Is there a risk of exploitation with RHSA-2019:2866?
Yes, there is a risk of exploitation with RHSA-2019:2866 which could potentially lead to arbitrary code execution during migration.