Issued:
2019-09-17
Updated:
2019-09-20

RHSA-2019:2809 - Important: kernel-alt security, bug fix, and enhancement update


Synopsis

Important: kernel-alt security, bug fix, and enhancement update

Type/Severity

Security Advisory Important

Topic

An update for kernel-alt is now available for Red Hat Enterprise Linux 7.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The kernel-alt packages provide the Linux kernel version 4.x.

Security Fix(es):

  • Kernel: page cache side channel attacks (CVE-2019-5489)

  • Kernel: KVM: potential use-after-free via kvm_ioctl_create_device() (CVE-2019-6974)

  • kernel: broken permission and object lifetime handling for PTRACE_TRACEME (CVE-2019-13272)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • [kernel-alt]: BUG: unable to handle kernel NULL pointer IP: crypto_remove_spawns+0x118/0x2e0 (BZ#1536967)

  • [HPE Apache] update ssif max_xmit_msg_size limit for multi-part messages (BZ#1610534)

  • RHEL-Alt-7.6 - powerpc/pseries: Fix unitialized timer reset on migration / powerpc/pseries/mobility: Extend start/stop topology update scope (LPM) (BZ#1673613)

  • RHEL-Alt-7.6 - s390: sha3_generic module fails and triggers panic when in FIPS mode (BZ#1673979)

  • RHEL-Alt-7.6 - System crashed after oom - During ICP deployment (BZ#1710304)

  • kernel-alt: Race condition in hashtables [rhel-alt-7.6.z] (BZ#1712127)

  • RHEL-Alt-7.6 - OP930:PM_Test:cpupower -r command set values for first 3 cores in quad and misses last core. (CORAL) (BZ#1717836)

  • RHEL-Alt-7.6 - disable runtime NUMA remapping for PRRN/LPM/VPHN (BZ#1717906)

  • fragmented packets timing out (BZ#1729066)

  • Backport TCP follow-up for small buffers (BZ#1733617)

Enhancement(s):

  • RHEL-Alt-7.6 - perfevent PMDA cannot create file descriptors for reading nest events using the perf API (pcp/kernel) (CORAL) (BZ#1723036)

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

The system must be rebooted for this update to take effect.

Affected Products

ProductVersionArch
Red Hat Enterprise Linux for Power 97ppc64le
Red Hat Enterprise Linux for IBM System z (Structure A)7s390x
Red Hat Enterprise Linux for ARM 647aarch64

Updated Packages

  • kernel-tools-debuginfo-4.14.0-115.12.1.el7a.ppc64le.rpm
  • kernel-4.14.0-115.12.1.el7a.s390x.rpm
  • kernel-tools-libs-4.14.0-115.12.1.el7a.aarch64.rpm
  • perf-debuginfo-4.14.0-115.12.1.el7a.s390x.rpm
  • perf-debuginfo-4.14.0-115.12.1.el7a.aarch64.rpm
  • kernel-devel-4.14.0-115.12.1.el7a.aarch64.rpm
  • kernel-debug-devel-4.14.0-115.12.1.el7a.s390x.rpm
  • kernel-debuginfo-4.14.0-115.12.1.el7a.ppc64le.rpm
  • kernel-devel-4.14.0-115.12.1.el7a.s390x.rpm
  • kernel-debuginfo-common-aarch64-4.14.0-115.12.1.el7a.aarch64.rpm
  • kernel-headers-4.14.0-115.12.1.el7a.ppc64le.rpm
  • kernel-4.14.0-115.12.1.el7a.aarch64.rpm
  • perf-debuginfo-4.14.0-115.12.1.el7a.ppc64le.rpm
  • python-perf-debuginfo-4.14.0-115.12.1.el7a.s390x.rpm
  • python-perf-4.14.0-115.12.1.el7a.aarch64.rpm
  • kernel-debug-debuginfo-4.14.0-115.12.1.el7a.aarch64.rpm
  • kernel-debuginfo-common-ppc64le-4.14.0-115.12.1.el7a.ppc64le.rpm
  • kernel-bootwrapper-4.14.0-115.12.1.el7a.ppc64le.rpm
  • kernel-debug-devel-4.14.0-115.12.1.el7a.ppc64le.rpm
  • kernel-kdump-4.14.0-115.12.1.el7a.s390x.rpm
  • kernel-4.14.0-115.12.1.el7a.ppc64le.rpm
  • kernel-abi-whitelists-4.14.0-115.12.1.el7a.noarch.rpm
  • kernel-devel-4.14.0-115.12.1.el7a.ppc64le.rpm
  • kernel-kdump-devel-4.14.0-115.12.1.el7a.s390x.rpm
  • kernel-tools-debuginfo-4.14.0-115.12.1.el7a.aarch64.rpm
  • kernel-tools-libs-4.14.0-115.12.1.el7a.ppc64le.rpm
  • perf-4.14.0-115.12.1.el7a.s390x.rpm
  • python-perf-4.14.0-115.12.1.el7a.ppc64le.rpm
  • python-perf-debuginfo-4.14.0-115.12.1.el7a.aarch64.rpm
  • kernel-debug-4.14.0-115.12.1.el7a.ppc64le.rpm
  • kernel-headers-4.14.0-115.12.1.el7a.aarch64.rpm
  • kernel-debug-debuginfo-4.14.0-115.12.1.el7a.s390x.rpm
  • kernel-tools-4.14.0-115.12.1.el7a.aarch64.rpm
  • kernel-debug-debuginfo-4.14.0-115.12.1.el7a.ppc64le.rpm
  • kernel-debuginfo-4.14.0-115.12.1.el7a.s390x.rpm
  • kernel-doc-4.14.0-115.12.1.el7a.noarch.rpm
  • kernel-debug-4.14.0-115.12.1.el7a.s390x.rpm
  • kernel-headers-4.14.0-115.12.1.el7a.s390x.rpm
  • kernel-tools-4.14.0-115.12.1.el7a.ppc64le.rpm
  • kernel-tools-libs-devel-4.14.0-115.12.1.el7a.ppc64le.rpm
  • perf-4.14.0-115.12.1.el7a.ppc64le.rpm
  • kernel-debug-4.14.0-115.12.1.el7a.aarch64.rpm
  • kernel-tools-libs-devel-4.14.0-115.12.1.el7a.aarch64.rpm
  • kernel-debug-devel-4.14.0-115.12.1.el7a.aarch64.rpm
  • python-perf-4.14.0-115.12.1.el7a.s390x.rpm
  • python-perf-debuginfo-4.14.0-115.12.1.el7a.ppc64le.rpm
  • kernel-alt-4.14.0-115.12.1.el7a.src.rpm
  • kernel-kdump-debuginfo-4.14.0-115.12.1.el7a.s390x.rpm
  • kernel-debuginfo-4.14.0-115.12.1.el7a.aarch64.rpm
  • perf-4.14.0-115.12.1.el7a.aarch64.rpm
  • kernel-debuginfo-common-s390x-4.14.0-115.12.1.el7a.s390x.rpm

Fixes

CVEs

References


Additional information