RHSA-2019:3076: Important: kpatch-patch security update
This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.<br>Security Fix(es):<br><li> kernel: Use-after-free in blkdrainqueue() function in block/blk-core.c (CVE-2018-20856)</li> <li> kernel: Heap overflow in mwifiexupdatebssdescwithie function in marvell/mwifiex/scan.c (CVE-2019-3846)</li> <li> hardware: bluetooth: BR/EDR encryption key negotiation attacks (KNOB) (CVE-2019-9506)</li> <li> kernel: Heap overflow in mwifiexuapparsetailies function in drivers/net/wireless/marvell/mwifiex/ie.c (CVE-2019-10126)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:3076?
RHSA-2019:3076 is considered a moderate security vulnerability affecting the kernel.
How do I fix RHSA-2019:3076?
To fix RHSA-2019:3076, update the kpatch-patch package to a remedied version such as 3_10_0-1062-1-5.el7.
What software is affected by RHSA-2019:3076?
The vulnerable software affected by RHSA-2019:3076 is the kpatch-patch package on Red Hat Enterprise Linux 7.
What are the security issues addressed in RHSA-2019:3076?
RHSA-2019:3076 addresses a use-after-free vulnerability and a heap overflow vulnerability in the kernel.
Is it safe to ignore RHSA-2019:3076?
Ignoring RHSA-2019:3076 may expose your system to security risks involving kernel vulnerabilities.