RHSA-2019:2741: Important: kernel-rt security and bug fix update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): kernel: Heap overflow in mwifiexupdatebssdescwithie function in marvell/mwifiex/scan.c (CVE-2019-3846) Kernel: KVM: nVMX: guest accesses L0 MSR causes potential DoS (CVE-2019-3887) kernel: brcmfmac heap buffer overflow in brcmfwowlndresults (CVE-2019-9500) kernel: Count overflow in FUSE request leading to use-after-free issues. (CVE-2019-11487) kernel: brcmfmac frame validation bypass (CVE-2019-9503) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): BUG: scheduling while atomic in zswap (BZ#1726362) kernel-rt: update to the RHEL8.0.z batch#3 source tree (BZ#1734475)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:2741?
The severity of RHSA-2019:2741 is critical due to the heap overflow vulnerability in the kernel.
How do I fix RHSA-2019:2741?
To fix RHSA-2019:2741, upgrade to kernel-rt packages version 4.18.0-80.11.1.rt9.156.el8_0 or later.
What are the affected packages in RHSA-2019:2741?
RHSA-2019:2741 affects several kernel-rt packages including kernel-rt, kernel-rt-core, and kernel-rt-debug among others.
Is the heap overflow in RHSA-2019:2741 exploitable remotely?
Yes, the heap overflow vulnerability in RHSA-2019:2741 can be exploited remotely.
What CVE is associated with RHSA-2019:2741?
The CVE associated with RHSA-2019:2741 is CVE-2019-3846.