Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Fedora 28: 2018-3857a8b41a Critical: Kernel Tools Pointer Dereference

fedora
Calendar Grey December 1, 2018
Scroller Fedora
Fedora 28 sees a crucial kernel-tools upgrade addressing various bugs. Utilize dnf to ensure improved stability.
The v4.19.5 stable update contains important fixes across the tree

Summary

This package contains the tools/ directory from the kernel source

and the supporting documentation.

The v4.19.5 stable update contains important fixes across the tree

* Tue Nov 27 2018 Jeremy Cline - 4.19.5-200

- Linux v4.19.5

* Wed Nov 21 2018 Jeremy Cline - 4.19.3-200

- Linux v4.19.3

* Wed Nov 14 2018 Jeremy Cline - 4.19.2-200

- Linux v4.19.2

* Mon Nov 5 2018 Laura Abbott - 4.18.17-200

- Linux v4.18.17

* Thu Oct 18 2018 Justin M. Forbes - 4.18.15-200

- Linux v4.18.15

* Wed Oct 10 2018 Laura Abbott - 4.18.13-200

- Linux v4.18.13

* Wed Sep 26 2018 Laura Abbott - 4.18.10-200

- Linux v4.18.10

* Tue Sep 11 2018 Laura Abbott - 4.18.7-200

- Linux v4.18.7

* Tue Sep 4 2018 Laura Abbott - 4.18.5-200

- Linux v4.18.5 rebase

* Fri Aug 24 2018 Justin M. Forbes - 4.17.19-100

- Linux v4.17.19

* Fri Aug 3 2018 Justin M. Forbes - 4.17.12-200

- Linux v4.17.12

* Tue Jul 17 2018 Justin M. Forbes - 4.17.7-200

- Linux v4.17.7

* Tue Jul 3 2018 Justin M. Forbes - 4.17.4-200

- Linux v4.17.4

* Mon Jun 18 2018 Justin M. Forbes - 4.17.2-200

- Linux v4.17.2 Rebase

* Tue May 22 2018 Jeremy Cline - 4.16.0-302

- Backport a second patch for kvm_stat Python 3 support

* Sat Apr 28 2018 Jeremy Cline - 4.16.0-301

- Bump the release so it's higher than F27

* Sat Apr 28 2018 Jeremy Cline - 4.16.0-2

- Backport a fix for Python 3 compatibility

[ 1 ] Bug #1652656 - CVE-2018-19407 kernel: kvm: NULL pointer dereference in vcpu_scan_ioapic in arch/x86/kvm/x86.c

https://bugzilla.redhat.com/show_bug.cgi?id=1652656

[ 2 ] Bug #1649017 - CVE-2018-16862 kernel: cleancache: Infoleak of deleted files after reuse of old inodes

https://bugzilla.redhat.com/show_bug.cgi?id=1649017

su -c 'dnf upgrade --advisory FEDORA-2018-3857a8b41a' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 28
Version: 4.19.5
Release: 200.fc28
Summary: Assortment of tools for the Linux kernel

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.