RHSA-2019:3217: Important: kernel-alt security and bug fix update
The kernel-alt packages provide the Linux kernel version 4.x.Security Fix(es): kernel: MIDI driver race condition leads to a double-free (CVE-2018-10902) kernel: Use-after-free in blkdrainqueue() function in block/blk-core.c (CVE-2018-20856) kernel: brcmfmac heap buffer overflow in brcmfwowlndresults (CVE-2019-9500) hardware: bluetooth: BR/EDR encryption key negotiation attacks (KNOB) (CVE-2019-9506) kernel: a NULL pointer dereference in drivers/scsi/megaraid/megaraidsasbase.c leading to DoS (CVE-2019-11810) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): kernel modules pkey and paess390 are not available (BZ#1719192) pkey: Indicate old mkvp only if old and curr. mkvp are different (BZ#1720621) System dropped into Mon running softboots Exception: 501 (Hardware Interrupt) at c00000000000a814 replayinterruptreturn+0x0/0x4 (ipmi) (BZ#1737563) kernel: jump label transformation performance (BZ#1739143) Backport i40e MDD detection removal for PFs (BZ#1747618)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:3217?
The severity of RHSA-2019:3217 is categorized as important due to multiple vulnerabilities that include a race condition and use-after-free issues.
How do I fix RHSA-2019:3217?
To fix RHSA-2019:3217, update the affected kernel-alt packages to version 4.14.0-115.14.1.el7a or later.
What vulnerabilities are addressed in RHSA-2019:3217?
RHSA-2019:3217 addresses vulnerabilities including CVE-2018-10902 and CVE-2018-20856, which involve a race condition and use-after-free errors in the Linux kernel.
What are the affected components in RHSA-2019:3217?
RHSA-2019:3217 affects several components including kernel-alt, kernel-debug, and kernel-headers, among others, across multiple architectures.
Is there a specific package version required for RHSA-2019:3217?
Yes, the specific package version required for RHSA-2019:3217 is 4.14.0-115.14.1.el7a.