Where
-Infinity
0
Severity
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virtext" field, this issue could allow a malicious L1 to disable both VMLOAD/VMSAVE intercepts and VLS (Virtual VMLOAD/VMSAVE) for the L2 guest. As a result, the L2 guest would be allowed to read/write physical pages of the host, resulting in a crash of the entire system, leak of sensitive data or potential guest-to-host escape.

1 / 3

Remedy

This vulnerability can be mitigated by disabling the nested virtualization feature: ``` # modprobe -r kvm_amd # modprobe kvm_amd nested=0 ``` Disabling VLS (Virtual VMLOAD/VMSAVE) is an alternative mitigation: ``` # modprobe kvm_amd vls=0 ```

Remedy

Disable nested virtualisation when loading the KVM AMD module: modprobe kvm_amd nested=0
First published (updated )
Severity
8.1
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

A flaw was found in the kernel-rt in which an attacker could submit a specially crafted ICMP echo request which can trigger a sysrq function based on values in the ICMP packet.

This feature was introduced in the kernel-rt only and is not shipping with standard Red Hat Enterprise Linux kernels.

Remote attacker could exploit this feature using bruteforce to submit arbitrary SysRq commands.

Resources: https://www.kernel.org/pub/linux/kernel/projects/rt/4.4/patch-4.4.7-rt16.patch.gz

Upstream discussion: https://lwn.net/Articles/448790/

CVE request: http://seclists.org/oss-sec/2016/q2/349

1 / 2
Source: Red Hat
First published (updated )
Severity
7.9
Race Condition, Use After Free
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

1 / 3

Remedy

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation baser or stability. The possible solution is to disable Bluetooth completely: https://access.redhat.com/solutions/2682931
First published (updated )
Severity
7
Use After Free, Null Pointer Dereference

Important: kernel-rt security update

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a> The system must be rebooted for this update to take effect.
First published (updated )
Severity
7
Use After Free

Important: kernel-rt security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a> The system must be rebooted for this update to take effect.
First published (updated )
Severity
7
Use After Free, Null Pointer Dereference

Important: kernel-rt security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a> The system must be rebooted for this update to take effect.
First published (updated )
Severity
7
Use After Free

Important: kernel-rt security and bug fix update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a> The system must be rebooted for this update to take effect.
First published (updated )
Severity
7

Important: kernel-rt security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7
Use After Free

Important: kernel-rt security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a> The system must be rebooted for this update to take effect.
First published (updated )
Severity
7

Important: kernel-rt security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a> The system must be rebooted for this update to take effect.
First published (updated )
Severity
7

Important: kernel-rt security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a> The system must be rebooted for this update to take effect.
First published (updated )
Severity
7

Important: kernel-rt security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a> The system must be rebooted for this update to take effect.
First published (updated )
Severity
7
Use After Free

Important: kernel-rt security and bug fix update

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a> The system must be rebooted for this update to take effect.
First published (updated )
Severity
7
Use After Free

Important: kernel-rt security and bug fix update

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a> The system must be rebooted for this update to take effect.
First published (updated )
Severity
7
Use After Free

Important: kernel-rt security and bug fix update

1 / 2

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a> The system must be rebooted for this update to take effect.
First published (updated )
Severity
7
Use After Free

Important: kernel-rt security update

1 / 2

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a> The system must be rebooted for this update to take effect.
First published (updated )
Severity
7

Important: kernel-rt security and bug fix update

1 / 2

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a> The system must be rebooted for this update to take effect.
First published (updated )
Severity
7

Important: kernel-rt security and bug fix update

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a> The system must be rebooted for this update to take effect.
First published (updated )
Severity
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

A flaw was found in the Linux kernel. A memory leak in the ccp-ops crypto driver can allow attackers to cause a denial of service. This vulnerability is similar with the older CVE-2019-18808. The highest threat from this vulnerability is to system availability.

1 / 4

Remedy

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation baser or stability.
First published (updated )
Severity
5.5
Race Condition, Use After Free, Double Free
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

A use-after-free vulnerability was found in a network namespaces code affecting the Linux kernel since v4.0-rc1 through v4.15-rc5. The function getnetnsbyid() does not check for the net::count value after it has found a peer network in netnsids idr which could lead to double free and memory corruption. This vulnerability could allow an unprivileged local user to induce kernel memory corruption on the system, leading to a crash. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.

References:

https://marc.info/?l=linux-netdev&m=151370451121029&w=2

https://marc.info/?t=151370468900001&r=1&w=2 (a whole thread)

http://seclists.org/oss-sec/2018/q1/7

An upstream patch:

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=21b5944350052d2583e82dd59b19a9ba94a007f0

1 / 3
Source: Red Hat
First published (updated )
Severity
5.5
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

A local user can trigger a flaw in the Linux kernel's handling of key lookups in the keychain subsystem.

The keyrejectandlink() function contains an error in which a key-lookup can fail and in an attempt to cache the failed lookup may attempt to free memory which can still be in use.

This could crash the system or at worse free a memory block which would then be re-used by another kernel mechanism causing a user after free.

Product bug:

https://bugzilla.redhat.com/showbug.cgi?id=1341352

Upstream patch:

https://www.spinics.net/lists/linux-kernel-janitors/msg26069.html

1 / 3
Source: Red Hat
First published (updated )
Severity
5.5
Null Pointer Dereference
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way the user closes the LR-WPAN connection. This flaw allows a local user to crash the system. The highest threat from this vulnerability is to system availability.

1 / 3

Remedy

To mitigate this issue, prevent the module mac802154 from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically.
First published (updated )
Severity
4

Moderate: tuned security update

1 / 2
Source: Red Hat

Remedy

<tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> tuned-2.20.0-1.el8_6.2.src.rpm </td> <td class="checksum">SHA-256: 81467752d97fded60b5337e4b39e5d2eebe18ae6f843f254fc6d317388947907</td> </tr> <tr> <th colspan="2">ppc64le</th> </tr> <tr> <td class="name"> tuned-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: 718a0909d75338944cd66581062773a0351a92cc5e101db4e51754a67a030f36</td> </tr> <tr> <td class="name"> tuned-gtk-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: 9c15b52c8034d81adb25aea74251843e5f8f365bca9cb8f5c3b796f51330396e</td> </tr> <tr> <td class="name"> tuned-profiles-atomic-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: 3d04fdeb4a4b2ef3a6dae89b01e0bb1a1afbe751745e23138060d0761fb3ceba</td> </tr> <tr> <td class="name"> tuned-profiles-compat-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: 168ffc131f788af40c549f3b724be968a089dc877d9f779331145f71270c250d</td> </tr> <tr> <td class="name"> tuned-profiles-cpu-partitioning-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: 3df63b8a477496e846d0e466b2452f2bbaed64e14c9c5bb08d7c73b9e6a96908</td> </tr> <tr> <td class="name"> tuned-profiles-mssql-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: 7e8bc7a55990a393188134422b6522eb8999760d6799935db0479d26668b4cde</td> </tr> <tr> <td class="name"> tuned-profiles-oracle-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: c4a6fd36eb282a9353a0ce53cb8f82f1408d154f9784e644bce26ffe0053bc43</td> </tr> <tr> <td class="name"> tuned-utils-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: 8f79fc9133a8fe021541f259e03511475586c3a8cfac35ee0e135bc599d84449</td> </tr> <tr> <td class="name"> tuned-utils-systemtap-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: d7f79dbc9300724eb46cae2f0f2f5268f34a2a33cec7641ed4846f1fa6e9f390</td> </tr> </tbody>Red Hat Enterprise Linux for SAP Applications for Power LE - Update Services for SAP Solutions 8.6 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <th colspan="2">ppc64le</th> </tr> <tr> <td class="name"> tuned-profiles-sap-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: 8be51ab5f385618633fb6bfb89e0baaac4f97c13342d3328d57c757ee4ceab22</td> </tr> </tbody>Red Hat Enterprise Linux for SAP Solutions for Power LE - Update Services for SAP Solutions 8.6 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <th colspan="2">ppc64le</th> </tr> <tr> <td class="name"> tuned-profiles-sap-hana-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: 84e9e6a6a9a9bea81628d4d1e76bf824287843d18b8800a7de15315837721f90</td> </tr> </tbody>Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.6 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> tuned-2.20.0-1.el8_6.2.src.rpm </td> <td class="checksum">SHA-256: 81467752d97fded60b5337e4b39e5d2eebe18ae6f843f254fc6d317388947907</td> </tr> <tr> <th colspan="2">x86_64</th> </tr> <tr> <td class="name"> tuned-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: 718a0909d75338944cd66581062773a0351a92cc5e101db4e51754a67a030f36</td> </tr> <tr> <td class="name"> tuned-gtk-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: 9c15b52c8034d81adb25aea74251843e5f8f365bca9cb8f5c3b796f51330396e</td> </tr> <tr> <td class="name"> tuned-profiles-atomic-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: 3d04fdeb4a4b2ef3a6dae89b01e0bb1a1afbe751745e23138060d0761fb3ceba</td> </tr> <tr> <td class="name"> tuned-profiles-compat-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: 168ffc131f788af40c549f3b724be968a089dc877d9f779331145f71270c250d</td> </tr> <tr> <td class="name"> tuned-profiles-cpu-partitioning-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: 3df63b8a477496e846d0e466b2452f2bbaed64e14c9c5bb08d7c73b9e6a96908</td> </tr> <tr> <td class="name"> tuned-profiles-mssql-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: 7e8bc7a55990a393188134422b6522eb8999760d6799935db0479d26668b4cde</td> </tr> <tr> <td class="name"> tuned-profiles-oracle-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: c4a6fd36eb282a9353a0ce53cb8f82f1408d154f9784e644bce26ffe0053bc43</td> </tr> <tr> <td class="name"> tuned-utils-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: 8f79fc9133a8fe021541f259e03511475586c3a8cfac35ee0e135bc599d84449</td> </tr> <tr> <td class="name"> tuned-utils-systemtap-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: d7f79dbc9300724eb46cae2f0f2f5268f34a2a33cec7641ed4846f1fa6e9f390</td> </tr> </tbody>Red Hat Enterprise Linux for SAP Applications for x86_64 - Update Services for SAP Solutions 8.6 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <th colspan="2">x86_64</th> </tr> <tr> <td class="name"> tuned-profiles-sap-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: 8be51ab5f385618633fb6bfb89e0baaac4f97c13342d3328d57c757ee4ceab22</td> </tr> </tbody>Red Hat Enterprise Linux for SAP Solutions for x86_64 - Update Services for SAP Solutions 8.6 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <th colspan="2">x86_64</th> </tr> <tr> <td class="name"> tuned-profiles-sap-hana-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: 84e9e6a6a9a9bea81628d4d1e76bf824287843d18b8800a7de15315837721f90</td> </tr> </tbody>Red Hat Enterprise Linux for Real Time - Telecommunications Update Service 8.6 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <th colspan="2">x86_64</th> </tr> <tr> <td class="name"> tuned-profiles-realtime-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: 7cabad2e8c997341e4982c3cccc2f380704f964c6c88c1774f29d836b22e03e1</td> </tr> </tbody>Red Hat Enterprise Linux for Real Time for NFV - Telecommunications Update Service 8.6 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <th colspan="2">x86_64</th> </tr> <tr> <td class="name"> tuned-profiles-nfv-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: e2295ea629c64011c5fc719a203605259fd4cd1b2b28edf6cb74cdaa887dc2b4</td> </tr> <tr> <td class="name"> tuned-profiles-nfv-guest-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: 27f2ef96ec6ab27783d57f04a22331d1b18b59497ded35c7164cd53cc32018e8</td> </tr> <tr> <td class="name"> tuned-profiles-nfv-host-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: ef13d2bbefbbd3776de00945e219351c55b68f7c896c7e5e8f6469fa9cc051df</td> </tr> <tr> <td class="name"> tuned-profiles-realtime-2.20.0-1.el8_6.2.noarch.rpm </td> <td class="checksum">SHA-256: 7cabad2e8c997341e4982c3cccc2f380704f964c6c88c1774f29d836b22e03e1</td> </tr> </tbody>
First published (updated )
Severity
4

Moderate: kernel security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a> The system must be rebooted for this update to take effect.
First published (updated )
Severity
4

Moderate: kernel-rt security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a> The system must be rebooted for this update to take effect.
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203