RHSA-2019:4154: Important: kernel-alt security, bug fix, and enhancement update
The kernel-alt packages provide the Linux kernel version 4.x.<br>Security Fix(es):<br><li> Kernel: KVM: OOB memory access via mmio ring buffer (CVE-2019-14821)</li> <li> kernel: Race condition in drivers/md/dm.c:dmgetfromkobject() allows local users to cause a denial of service (CVE-2017-18203)</li> <li> kernel: use-after-free Read in vhosttransportsendpkt (CVE-2018-14625)</li> <li> kernel: Information leak in cdromioctldrivestatus (CVE-2018-16658)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> IPMI use after free issue seen on Marvell ThunderX2 (BZ#1732163)</li> <li> kernel: siginfo delivers SEGVMAPERR instead of SEGVACCERR [rhel-alt-7.6.z] (BZ#1757189)</li> Enhancement(s):<br><li> [Marvell 7.7 z-stream BUG] CN99xx: DIMM label not extracted in EDAC hw error log (BZ#1721427)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:4154?
The severity of RHSA-2019:4154 is classified as medium.
How do I fix RHSA-2019:4154?
To fix RHSA-2019:4154, update the kernel-alt package to version 4.14.0-115.16.1.el7a or later.
What vulnerabilities are addressed in RHSA-2019:4154?
RHSA-2019:4154 addresses two vulnerabilities, including CVE-2019-14821 related to KVM and an unspecified race condition.
What software is affected by RHSA-2019:4154?
RHSA-2019:4154 affects several packages, including kernel-alt, kernel, and various kernel-debug packages.
When was RHSA-2019:4154 released?
RHSA-2019:4154 was released on November 18, 2019.