- Issued:
- 2019-09-17
- Updated:
- 2019-09-20
RHSA-2019:2809 - Important: kernel-alt security, bug fix, and enhancement update
Synopsis
Important: kernel-alt security, bug fix, and enhancement update
Type/Severity
Security Advisory Important
Topic
An update for kernel-alt is now available for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
The kernel-alt packages provide the Linux kernel version 4.x.
Security Fix(es):
-
Kernel: page cache side channel attacks (CVE-2019-5489)
-
Kernel: KVM: potential use-after-free via kvm_ioctl_create_device() (CVE-2019-6974)
-
kernel: broken permission and object lifetime handling for PTRACE_TRACEME (CVE-2019-13272)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
-
[kernel-alt]: BUG: unable to handle kernel NULL pointer IP: crypto_remove_spawns+0x118/0x2e0 (BZ#1536967)
-
[HPE Apache] update ssif max_xmit_msg_size limit for multi-part messages (BZ#1610534)
-
RHEL-Alt-7.6 - powerpc/pseries: Fix unitialized timer reset on migration / powerpc/pseries/mobility: Extend start/stop topology update scope (LPM) (BZ#1673613)
-
RHEL-Alt-7.6 - s390: sha3_generic module fails and triggers panic when in FIPS mode (BZ#1673979)
-
RHEL-Alt-7.6 - System crashed after oom - During ICP deployment (BZ#1710304)
-
kernel-alt: Race condition in hashtables [rhel-alt-7.6.z] (BZ#1712127)
-
RHEL-Alt-7.6 - OP930:PM_Test:cpupower -r command set values for first 3 cores in quad and misses last core. (CORAL) (BZ#1717836)
-
RHEL-Alt-7.6 - disable runtime NUMA remapping for PRRN/LPM/VPHN (BZ#1717906)
-
fragmented packets timing out (BZ#1729066)
-
Backport TCP follow-up for small buffers (BZ#1733617)
Enhancement(s):
- RHEL-Alt-7.6 - perfevent PMDA cannot create file descriptors for reading nest events using the perf API (pcp/kernel) (CORAL) (BZ#1723036)
Solution
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258
The system must be rebooted for this update to take effect.
Affected Products
| Product | Version | Arch |
|---|---|---|
| Red Hat Enterprise Linux for Power 9 | 7 | ppc64le |
| Red Hat Enterprise Linux for IBM System z (Structure A) | 7 | s390x |
| Red Hat Enterprise Linux for ARM 64 | 7 | aarch64 |
Updated Packages
- kernel-tools-debuginfo-4.14.0-115.12.1.el7a.ppc64le.rpm
- kernel-4.14.0-115.12.1.el7a.s390x.rpm
- kernel-tools-libs-4.14.0-115.12.1.el7a.aarch64.rpm
- perf-debuginfo-4.14.0-115.12.1.el7a.s390x.rpm
- perf-debuginfo-4.14.0-115.12.1.el7a.aarch64.rpm
- kernel-devel-4.14.0-115.12.1.el7a.aarch64.rpm
- kernel-debug-devel-4.14.0-115.12.1.el7a.s390x.rpm
- kernel-debuginfo-4.14.0-115.12.1.el7a.ppc64le.rpm
- kernel-devel-4.14.0-115.12.1.el7a.s390x.rpm
- kernel-debuginfo-common-aarch64-4.14.0-115.12.1.el7a.aarch64.rpm
- kernel-headers-4.14.0-115.12.1.el7a.ppc64le.rpm
- kernel-4.14.0-115.12.1.el7a.aarch64.rpm
- perf-debuginfo-4.14.0-115.12.1.el7a.ppc64le.rpm
- python-perf-debuginfo-4.14.0-115.12.1.el7a.s390x.rpm
- python-perf-4.14.0-115.12.1.el7a.aarch64.rpm
- kernel-debug-debuginfo-4.14.0-115.12.1.el7a.aarch64.rpm
- kernel-debuginfo-common-ppc64le-4.14.0-115.12.1.el7a.ppc64le.rpm
- kernel-bootwrapper-4.14.0-115.12.1.el7a.ppc64le.rpm
- kernel-debug-devel-4.14.0-115.12.1.el7a.ppc64le.rpm
- kernel-kdump-4.14.0-115.12.1.el7a.s390x.rpm
- kernel-4.14.0-115.12.1.el7a.ppc64le.rpm
- kernel-abi-whitelists-4.14.0-115.12.1.el7a.noarch.rpm
- kernel-devel-4.14.0-115.12.1.el7a.ppc64le.rpm
- kernel-kdump-devel-4.14.0-115.12.1.el7a.s390x.rpm
- kernel-tools-debuginfo-4.14.0-115.12.1.el7a.aarch64.rpm
- kernel-tools-libs-4.14.0-115.12.1.el7a.ppc64le.rpm
- perf-4.14.0-115.12.1.el7a.s390x.rpm
- python-perf-4.14.0-115.12.1.el7a.ppc64le.rpm
- python-perf-debuginfo-4.14.0-115.12.1.el7a.aarch64.rpm
- kernel-debug-4.14.0-115.12.1.el7a.ppc64le.rpm
- kernel-headers-4.14.0-115.12.1.el7a.aarch64.rpm
- kernel-debug-debuginfo-4.14.0-115.12.1.el7a.s390x.rpm
- kernel-tools-4.14.0-115.12.1.el7a.aarch64.rpm
- kernel-debug-debuginfo-4.14.0-115.12.1.el7a.ppc64le.rpm
- kernel-debuginfo-4.14.0-115.12.1.el7a.s390x.rpm
- kernel-doc-4.14.0-115.12.1.el7a.noarch.rpm
- kernel-debug-4.14.0-115.12.1.el7a.s390x.rpm
- kernel-headers-4.14.0-115.12.1.el7a.s390x.rpm
- kernel-tools-4.14.0-115.12.1.el7a.ppc64le.rpm
- kernel-tools-libs-devel-4.14.0-115.12.1.el7a.ppc64le.rpm
- perf-4.14.0-115.12.1.el7a.ppc64le.rpm
- kernel-debug-4.14.0-115.12.1.el7a.aarch64.rpm
- kernel-tools-libs-devel-4.14.0-115.12.1.el7a.aarch64.rpm
- kernel-debug-devel-4.14.0-115.12.1.el7a.aarch64.rpm
- python-perf-4.14.0-115.12.1.el7a.s390x.rpm
- python-perf-debuginfo-4.14.0-115.12.1.el7a.ppc64le.rpm
- kernel-alt-4.14.0-115.12.1.el7a.src.rpm
- kernel-kdump-debuginfo-4.14.0-115.12.1.el7a.s390x.rpm
- kernel-debuginfo-4.14.0-115.12.1.el7a.aarch64.rpm
- perf-4.14.0-115.12.1.el7a.aarch64.rpm
- kernel-debuginfo-common-s390x-4.14.0-115.12.1.el7a.s390x.rpm
Fixes
- This content is not included.BZ - 1664110
- This content is not included.BZ - 1671913
- This content is not included.BZ - 1730895
CVEs
References
Additional information
- The Red Hat security contact is This content is not included.secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.
- Offline Security Data data is available for integration with other systems. See Offline Security Data API to get started.