Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Fedora 28 Kernel-Tools Advisory 2019-3da64f3e61 Critical KVM Issues

fedora
Calendar Grey February 16, 2019
Scroller Fedora
The recent security patch for Fedora 28's kernel-tools addresses significant KVM flaws, bolstering system resilience and improving overall performance.
The 4.20.8 stable kernel update contains a number of important fixes across the tree.

Summary

This package contains the tools/ directory from the kernel source

and the supporting documentation.

The 4.20.8 stable kernel update contains a number of important fixes across the

tree.

* Tue Feb 12 2019 Justin M. Forbes - 4.20.8-100

- Linux v4.20.8

* Mon Jan 28 2019 Justin M. Forbes - 4.20.5-100

- Linux v4.20.5

* Wed Jan 23 2019 Justin M. Forbes - 4.20.3-100

- Linux v4.20.3 rebase

* Wed Jan 16 2019 Jeremy Cline - 4.19.16-200

- Linux v4.19.16

* Thu Jan 10 2019 Jeremy Cline - 4.19.14-200

- Linux v4.19.14

* Mon Dec 17 2018 Jeremy Cline - 4.19.10-200

- Linux v4.19.10

* Wed Dec 5 2018 Jeremy Cline - 4.19.7-200

- Linux v4.19.7

* Sun Dec 2 2018 Jeremy Cline - 4.19.6-200

- Linux v4.19.6

* Tue Nov 27 2018 Jeremy Cline - 4.19.5-200

- Linux v4.19.5

* Wed Nov 21 2018 Jeremy Cline - 4.19.3-200

- Linux v4.19.3

* Wed Nov 14 2018 Jeremy Cline - 4.19.2-200

- Linux v4.19.2

* Mon Nov 5 2018 Laura Abbott - 4.18.17-200

- Linux v4.18.17

* Thu Oct 18 2018 Justin M. Forbes - 4.18.15-200

- Linux v4.18.15

* Wed Oct 10 2018 Laura Abbott - 4.18.13-200

- Linux v4.18.13

* Wed Sep 26 2018 Laura Abbott - 4.18.10-200

- Linux v4.18.10

* Tue Sep 11 2018 Laura Abbott - 4.18.7-200

- Linux v4.18.7

* Tue Sep 4 2018 Laura Abbott - 4.18.5-200

- Linux v4.18.5 rebase

* Fri Aug 24 2018 Justin M. Forbes - 4.17.19-100

- Linux v4.17.19

* Fri Aug 3 2018 Justin M. Forbes - 4.17.12-200

- Linux v4.17.12

* Tue Jul 17 2018 Justin M. Forbes - 4.17.7-200

- Linux v4.17.7

* Tue Jul 3 2018 Justin M. Forbes - 4.17.4-200

- Linux v4.17.4

* Mon Jun 18 2018 Justin M. Forbes - 4.17.2-200

- Linux v4.17.2 Rebase

* Tue May 22 2018 Jeremy Cline - 4.16.0-302

- Backport a second patch for kvm_stat Python 3 support

* Sat Apr 28 2018 Jeremy Cline - 4.16.0-301

- Bump the release so it's higher than F27

* Sat Apr 28 2018 Jeremy Cline - 4.16.0-2

- Backport a fix for Python 3 compatibility

[ 1 ] Bug #1671930 - CVE-2019-7222 Kernel: KVM: leak of uninitialized stack contents to guest

https://bugzilla.redhat.com/show_bug.cgi?id=1671930

[ 2 ] Bug #1671913 - CVE-2019-6974 Kernel: KVM: potential use-after-free via kvm_ioctl_create_device()

https://bugzilla.redhat.com/show_bug.cgi?id=1671913

[ 3 ] Bug #1671904 - CVE-2019-7221 Kernel: KVM: nVMX: use-after-free of the hrtimer for emulation of the preemption timer

https://bugzilla.redhat.com/show_bug.cgi?id=1671904

su -c 'dnf upgrade --advisory FEDORA-2019-3da64f3e61' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 28
Version: 4.20.8
Release: 100.fc28
Summary: Assortment of tools for the Linux kernel

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.