-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
==================================================================== Red Hat Security Advisory
Synopsis: Important: kernel-rt security and bug fix update
Advisory ID: RHSA-2019:1891-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2019:1891
Issue date: 2019-07-29
CVE Names: CVE-2018-16871 CVE-2018-16884 CVE-2019-11085
CVE-2019-11811
====================================================================
1. Summary:
An update for kernel-rt is now available for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat Enterprise Linux Realtime (v. 7) - noarch, x86_64
Red Hat Enterprise Linux for Real Time for NFV (v. 7) - noarch, x86_64
3. Description:
The kernel-rt packages provide the Real Time Linux Kernel, which enables
fine-tuning for systems with extremely high determinism requirements.
Security Fix(es):
* kernel: nfs: use-after-free in svc_process_common() (CVE-2018-16884)
* kernel: insufficient input validation in kernel mode driver in Intel i915
graphics leads to privilege escalation (CVE-2019-11085)
* kernel: nfs: NULL pointer dereference due to an anomalized NFS message
sequence (CVE-2018-16871)
* kernel: use-after-free in drivers/char/ipmi/ipmi_si_intf.c,
ipmi_si_mem_io.c, ipmi_si_port_io.c (CVE-2019-11811)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Bug Fix(es):
* kernel-rt: update to the RHEL7.6.z batch#6 source tree (BZ#1718400)
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
The system must be rebooted for this update to take effect.
5. Bugs fixed (https://bugzilla.redhat.com/):
1655162 - CVE-2018-16871 kernel: nfs: NULL pointer dereference due to an anomalized NFS message sequence
1660375 - CVE-2018-16884 kernel: nfs: use-after-free in svc_process_common()
1709180 - CVE-2019-11811 kernel: use-after-free in drivers/char/ipmi/ipmi_si_intf.c, ipmi_si_mem_io.c, ipmi_si_port_io.c
1710405 - CVE-2019-11085 kernel: insufficient input validation in kernel mode driver in Intel i915 graphics leads to privilege escalation
1718400 - kernel-rt: update to the RHEL7.6.z batch#6 source tree
6. Package List:
Red Hat Enterprise Linux for Real Time for NFV (v. 7):
Source:
kernel-rt-3.10.0-957.27.2.rt56.940.el7.src.rpm
noarch:
kernel-rt-doc-3.10.0-957.27.2.rt56.940.el7.noarch.rpm
x86_64:
kernel-rt-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-debug-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-debug-debuginfo-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-debug-devel-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-debug-kvm-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-debug-kvm-debuginfo-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-debuginfo-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-debuginfo-common-x86_64-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-devel-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-kvm-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-kvm-debuginfo-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-trace-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-trace-debuginfo-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-trace-devel-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-trace-kvm-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-trace-kvm-debuginfo-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
Red Hat Enterprise Linux Realtime (v. 7):
Source:
kernel-rt-3.10.0-957.27.2.rt56.940.el7.src.rpm
noarch:
kernel-rt-doc-3.10.0-957.27.2.rt56.940.el7.noarch.rpm
x86_64:
kernel-rt-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-debug-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-debug-debuginfo-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-debug-devel-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-debuginfo-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-debuginfo-common-x86_64-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-devel-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-trace-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-trace-debuginfo-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-trace-devel-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2018-16871
https://access.redhat.com/security/cve/CVE-2018-16884
https://access.redhat.com/security/cve/CVE-2019-11085
https://access.redhat.com/security/cve/CVE-2019-11811
https://access.redhat.com/security/updates/classification/#important
8. Contact:
The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2019 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBXT8OCtzjgjWX9erEAQiiChAAgZ5ZbEu8ZUzbX+lCAQXxGxp7hrWUU5/u
NcaIUPpQzub48MSOFhGj6ae54aqGrpmZRg6+3VXNyAYSp+WInmNe/vZ6q9N4LvH2
bvJCIIBEQQ9TicG5SpZP6WqLyaNJHclvVZm6uA8MywOel4hDU/A2wkuyKkwiVecl
JeH4ge+R7AXWs8kIRcYulVgxbfvQzGS19QlMDGUqcu5tmXa7OUKU2ZO0MSt0XNjB
t9u1eKlbc8/hsc/wR60YfXx3Xl7d/ldof+KTtqxV10Dkmun0gRMPMy4T7H7Bnme0
pdH1Sqo+f3lAo//xqxs9tS3UInACOBPG47bkkOADxxJ5GVwQsKPTZeKPempfxjc1
p9al2O5cmJWXH+RDpnEGV1ghzBLmVZN7HlpTWW5TK+K2aOEgY3D2v4cGed4ORTWF
AgsTCpMfv/ree6+3n9Nu4yPFqbnFzwaWhjikcin1v+y0NQOtJYiLGIGEO15QQAFD
Jt7F7OLXH0xl7uonA3X4b8BAqimpxhWAbsw0cduAIT+8cRZS8EAQXXH3MhPZO9ak
aLd1/fr8qW50bD/vfKSSbNYrNw7ZDgM3aiToTLqpkH1iWmLQFId7WgNJ2cBqrnmt
IQ+iJXujQvsccfUiSjLdm4fcPL9NRgDm+OqvPIeXw6ji8kGIlovFWjFEumb9NAyr
KJypiIQ28Cg=WSWd
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
This email address is being protected from spambots. You need JavaScript enabled to view it.
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
The system must be rebooted for this update to take effect.
The kernel-rt packages provide the Real Time Linux Kernel, which enables
fine-tuning for systems with extremely high determinism requirements.
Security Fix(es):
* kernel: nfs: use-after-free in svc_process_common() (CVE-2018-16884)
* kernel: insufficient input validation in kernel mode driver in Intel i915
graphics leads to privilege escalation (CVE-2019-11085)
* kernel: nfs: NULL pointer dereference due to an anomalized NFS message
sequence (CVE-2018-16871)
* kernel: use-after-free in drivers/char/ipmi/ipmi_si_intf.c,
ipmi_si_mem_io.c, ipmi_si_port_io.c (CVE-2019-11811)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Bug Fix(es):
* kernel-rt: update to the RHEL7.6.z batch#6 source tree (BZ#1718400)
https://access.redhat.com/security/cve/CVE-2018-16871 https://access.redhat.com/security/cve/CVE-2018-16884 https://access.redhat.com/security/cve/CVE-2019-11085 https://access.redhat.com/security/cve/CVE-2019-11811 https://access.redhat.com/security/updates/classification/#important
Red Hat Enterprise Linux for Real Time for NFV (v. 7):
Source:
kernel-rt-3.10.0-957.27.2.rt56.940.el7.src.rpm
noarch:
kernel-rt-doc-3.10.0-957.27.2.rt56.940.el7.noarch.rpm
x86_64:
kernel-rt-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-debug-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-debug-debuginfo-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-debug-devel-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-debug-kvm-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-debug-kvm-debuginfo-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-debuginfo-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-debuginfo-common-x86_64-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-devel-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-kvm-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-kvm-debuginfo-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-trace-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-trace-debuginfo-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-trace-devel-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-trace-kvm-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
kernel-rt-trace-kvm-debuginfo-3.10.0-957.27.2.rt56.940.el7.x86_64.rpm
Red Hat Enterprise Linux Realtime (v. 7):
Source:
kernel-rt-3.10.0-957.27.2.rt56.940.el7.src.rpm
noarch:
Read the Full Advisory
An update for kernel-rt is now available for Red Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.
Red Hat Enterprise Linux Realtime (v. 7) - noarch, x86_64
Red Hat Enterprise Linux for Real Time for NFV (v. 7) - noarch, x86_64
1655162 - CVE-2018-16871 kernel: nfs: NULL pointer dereference due to an anomalized NFS message sequence
1660375 - CVE-2018-16884 kernel: nfs: use-after-free in svc_process_common()
1709180 - CVE-2019-11811 kernel: use-after-free in drivers/char/ipmi/ipmi_si_intf.c, ipmi_si_mem_io.c, ipmi_si_port_io.c
1710405 - CVE-2019-11085 kernel: insufficient input validation in kernel mode driver in Intel i915 graphics leads to privilege escalation
1718400 - kernel-rt: update to the RHEL7.6.z batch#6 source tree
Get the latest Linux and open source security news straight to your inbox.