RHSA-2019:3878: Important: kernel security update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): hw: Intel GPU blitter manipulation can allow for arbitrary kernel memory write (CVE-2019-0155) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 2.6.32-754.24.3.el6 - Upgrade
Upgrade
redhat/kernel-abi-whiteliststo a version that resolves this vulnerability.Fixed in 2.6.32-754.24.3.el6 - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 2.6.32-754.24.3.el6 - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 2.6.32-754.24.3.el6 - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 2.6.32-754.24.3.el6 - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 2.6.32-754.24.3.el6 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-i686to a version that resolves this vulnerability.Fixed in 2.6.32-754.24.3.el6 - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 2.6.32-754.24.3.el6 - Upgrade
Upgrade
redhat/kernel-docto a version that resolves this vulnerability.Fixed in 2.6.32-754.24.3.el6 - Upgrade
Upgrade
redhat/kernel-firmwareto a version that resolves this vulnerability.Fixed in 2.6.32-754.24.3.el6 - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 2.6.32-754.24.3.el6 - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 2.6.32-754.24.3.el6 - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 2.6.32-754.24.3.el6 - Upgrade
Upgrade
redhat/python-perfto a version that resolves this vulnerability.Fixed in 2.6.32-754.24.3.el6 - Upgrade
Upgrade
redhat/python-perf-debuginfoto a version that resolves this vulnerability.Fixed in 2.6.32-754.24.3.el6 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-s390xto a version that resolves this vulnerability.Fixed in 2.6.32-754.24.3.el6 - Upgrade
Upgrade
redhat/kernel-kdumpto a version that resolves this vulnerability.Fixed in 2.6.32-754.24.3.el6 - Upgrade
Upgrade
redhat/kernel-kdump-debuginfoto a version that resolves this vulnerability.Fixed in 2.6.32-754.24.3.el6 - Upgrade
Upgrade
redhat/kernel-kdump-develto a version that resolves this vulnerability.Fixed in 2.6.32-754.24.3.el6 - Upgrade
Upgrade
redhat/kernel-bootwrapperto a version that resolves this vulnerability.Fixed in 2.6.32-754.24.3.el6 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64to a version that resolves this vulnerability.Fixed in 2.6.32-754.24.3.el6
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:3878?
The severity of RHSA-2019:3878 is classified as important.
How do I fix RHSA-2019:3878?
To fix RHSA-2019:3878, update the kernel packages to version 2.6.32-754.24.3.el6 or later.
What vulnerability does RHSA-2019:3878 address?
RHSA-2019:3878 addresses a vulnerability in the Intel GPU that allows arbitrary kernel memory writes, identified as CVE-2019-0155.
What packages are affected by RHSA-2019:3878?
Affected packages by RHSA-2019:3878 include kernel, kernel-debug, kernel-devel, and other related packages under the specified version.
Is it safe to ignore RHSA-2019:3878?
It is not recommended to ignore RHSA-2019:3878 as it poses a risk of arbitrary memory write that can compromise system security.