RHSA-2019:3967: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: Memory corruption due to incorrect socket cloning (CVE-2018-9568) kernel: MIDI driver race condition leads to a double-free (CVE-2018-10902) kernel: Use-after-free due to race condition in AFPACKET implementation (CVE-2018-18559) Kernel: vhostnet: infinite loop while receiving packets leads to DoS (CVE-2019-3900) Kernel: page cache side channel attacks (CVE-2019-5489) Kernel: KVM: potential use-after-free via kvmioctlcreatedevice() (CVE-2019-6974) Kernel: KVM: nVMX: use-after-free of the hrtimer for emulation of the preemption timer (CVE-2019-7221) kernel: Inifinite loop vulnerability in mm/madvise.c:madvisewillneed() function allows local denial of service (CVE-2017-18208) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): A cluster node has multiple hung "mv" processes that are accessing a gfs2 filesystem. (BZ#1716321) Growing unreclaimable slab memory (BZ#1741918) [LLNL 7.5 Bug] slab leak causing a crash when using kmem control group (BZ#1748236) kernel build: parallelize redhat/mod-sign.sh (BZ#1755328) kernel build: speed up module compression step (BZ#1755337)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 3.10.0-862.44.2.el7 - Upgrade
Upgrade
redhat/kernel-abi-whiteliststo a version that resolves this vulnerability.Fixed in 3.10.0-862.44.2.el7 - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 3.10.0-862.44.2.el7 - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-862.44.2.el7 - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 3.10.0-862.44.2.el7 - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-862.44.2.el7 - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 3.10.0-862.44.2.el7 - Upgrade
Upgrade
redhat/kernel-docto a version that resolves this vulnerability.Fixed in 3.10.0-862.44.2.el7 - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 3.10.0-862.44.2.el7 - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 3.10.0-862.44.2.el7 - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-862.44.2.el7 - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 3.10.0-862.44.2.el7 - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 3.10.0-862.44.2.el7 - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 3.10.0-862.44.2.el7 - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-862.44.2.el7 - Upgrade
Upgrade
redhat/python-perfto a version that resolves this vulnerability.Fixed in 3.10.0-862.44.2.el7 - Upgrade
Upgrade
redhat/python-perf-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-862.44.2.el7 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-s390xto a version that resolves this vulnerability.Fixed in 3.10.0-862.44.2.el7 - Upgrade
Upgrade
redhat/kernel-kdumpto a version that resolves this vulnerability.Fixed in 3.10.0-862.44.2.el7 - Upgrade
Upgrade
redhat/kernel-kdump-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-862.44.2.el7 - Upgrade
Upgrade
redhat/kernel-kdump-develto a version that resolves this vulnerability.Fixed in 3.10.0-862.44.2.el7 - Upgrade
Upgrade
redhat/kernel-bootwrapperto a version that resolves this vulnerability.Fixed in 3.10.0-862.44.2.el7 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64to a version that resolves this vulnerability.Fixed in 3.10.0-862.44.2.el7 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64leto a version that resolves this vulnerability.Fixed in 3.10.0-862.44.2.el7
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:3967?
The severity of RHSA-2019:3967 is classified as important due to multiple vulnerabilities in the Linux kernel.
How do I fix RHSA-2019:3967?
You can fix RHSA-2019:3967 by updating to the kernel version 3.10.0-862.44.2.el7 or newer.
What vulnerabilities are addressed in RHSA-2019:3967?
RHSA-2019:3967 addresses vulnerabilities such as memory corruption due to incorrect socket cloning (CVE-2018-9568) and a MIDI driver race condition leading to a double-free (CVE-2018-10902).
Which systems are affected by RHSA-2019:3967?
RHSA-2019:3967 affects systems running specific versions of the Red Hat kernel package.
What happens if I do not address RHSA-2019:3967?
Failing to address RHSA-2019:3967 may leave your system vulnerable to exploitation through the identified security flaws.