RHSA-2019:2899: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): A buffer overflow flaw was found in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host. (CVE-2019-14835) kernel: hw: Spectre SWAPGS gadget vulnerability (CVE-2019-1125) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): fs deadlock when a memory allocation waits on page writeback in NOFS context (BZ#1729103) fragmented packets timing out (BZ#1729409) kernel build: speed up debuginfo extraction (BZ#1731460) use "make -jN" for modulesinstall (BZ#1735079) shmem: consider shmmnt as a long-term mount (BZ#1737374) raid1d can hang in freezearray if handling a mix of read and write errors (BZ#1737792) Backport TCP follow-up for small buffers (BZ#1739125)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:2899?
The severity of RHSA-2019:2899 is classified as important.
How do I fix RHSA-2019:2899?
To fix RHSA-2019:2899, update the kernel packages to version 3.10.0-327.82.1.el7 or later.
What vulnerability does RHSA-2019:2899 address?
RHSA-2019:2899 addresses a buffer overflow flaw in the Linux kernel's vhost functionality.
Which packages are affected by RHSA-2019:2899?
Packages affected by RHSA-2019:2899 include kernel, kernel-debug, and various kernel tool packages.
Is RHSA-2019:2899 applicable to all Linux distributions?
RHSA-2019:2899 is specific to Red Hat and its derivatives, and may not apply to other Linux distributions.