RHSA-2019:4057: Important: kernel-rt security and bug fix update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): Kernel: page cache side channel attacks (CVE-2019-5489) kernel: Handling of mightcancel queueing is not properly pretected against race (CVE-2017-10661) kernel: Inifinite loop vulnerability in mm/madvise.c:madvisewillneed() function allows local denial of service (CVE-2017-18208) kernel: use-after-free in drivers/char/ipmi/ipmisiintf.c, ipmisimemio.c, ipmisiportio.c (CVE-2019-11811) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): update the MRG 2.5.z 3.10 realtime-kernel sources (BZ#1765670) [MRG/R] pipstress hangs when a priority inversion occurs (BZ#1772562)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:4057?
The severity of RHSA-2019:4057 is classified as moderate.
How do I fix RHSA-2019:4057?
You can fix RHSA-2019:4057 by updating the kernel-rt packages to version 3.10.0-693.61.1.rt56.656.el6.
Which systems are affected by RHSA-2019:4057?
RHSA-2019:4057 affects systems using kernel-rt packages version 3.10.0-693.61.1.rt56.656.el6.
What vulnerabilities are addressed in RHSA-2019:4057?
RHSA-2019:4057 addresses page cache side-channel attacks identified as CVE-2019-5489.
What is the main purpose of the kernel-rt packages in RHSA-2019:4057?
The kernel-rt packages are designed to provide a Real Time Linux Kernel for systems requiring high determinism.