Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 11 articles for you...
98

Red Hat Enterprise Linux 8.2 RHSA-2023-4126-01 Important Kernel Fix

An update for kernel-rt is now available for Red Hat Enterprise Linux 8.2 Telecommunications Update Service. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel-rt security and bug fix update Advisory ID: RHSA-2023:4126-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:4126 Issue date: 2023-07-18 CVE Names: CVE-2023-0461 CVE-2023-1281 CVE-2023-1390 CVE-2023-32233 ==================================================================== 1. Summary: An update for kernel-rt is now available for Red Hat Enterprise Linux 8.2 Telecommunications Update Service. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Real Time TUS (v. 8.2) - x86_64 Red Hat Enterprise Linux Real Time for NFV TUS (v. 8.2) - x86_64 3. Description: The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: net/ulp: use-after-free in listening ULP sockets (CVE-2023-0461) * kernel: tcindex: use-after-free vulnerability in traffic control index filter allows privilege escalation (CVE-2023-1281) * kernel: remote DoS in TIPC kernel module (CVE-2023-1390) * kernel: netfilter: use-after-free in nf_tables when processing batch requests can lead to privilege escalation (CVE-2023-32233) For more details about the security issue(s), including the impact, a CVSS score,acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * kernel-rt: update RT source tree to the RHEL-8.2.z27 source tree (BZ#2209127) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2176192 - CVE-2023-0461 kernel: net/ulp: use-after-free in listening ULP sockets 2178212 - CVE-2023-1390 kernel: remote DoS in TIPC kernel module 2181847 - CVE-2023-1281 kernel: tcindex: use-after-free vulnerability in traffic control index filter allows privilege escalation 2196105 - CVE-2023-32233 kernel: netfilter: use-after-free in nf_tables when processing batch requests can lead to privilege escalation 6. Package List: Red Hat Enterprise Linux Real Time for NFV TUS (v. 8.2): Source: kernel-rt-4.18.0-193.109.1.rt13.160.el8_2.src.rpm x86_64: kernel-rt-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-core-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-debug-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-debug-core-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-debug-debuginfo-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-debug-devel-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-debug-kvm-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-debug-modules-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-debug-modules-extra-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-debuginfo-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-debuginfo-common-x86_64-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-devel-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-kvm-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-modules-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-modules-extra-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm Red Hat Enterprise Linux Real Time TUS (v.8.2): Source: kernel-rt-4.18.0-193.109.1.rt13.160.el8_2.src.rpm x86_64: kernel-rt-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-core-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-debug-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-debug-core-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-debug-debuginfo-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-debug-devel-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-debug-modules-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-debug-modules-extra-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-debuginfo-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-debuginfo-common-x86_64-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-devel-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-modules-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm kernel-rt-modules-extra-4.18.0-193.109.1.rt13.160.el8_2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-0461 https://access.redhat.com/security/cve/CVE-2023-1281 https://access.redhat.com/security/cve/CVE-2023-1390 https://access.redhat.com/security/cve/CVE-2023-32233 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJktmwOAAoJENzjgjWX9erE/bAP/13KpeTH0KZgRa34ZpWWaYij 6p3R83Bz7WnamsjPzVV6PHS/EZ//KdZZvCoUwxHR5Vc8toKlg2BMwETpdWMVCtyj BZ28ZBc/rWjOrQLdnvuY+C5cIqqWB2zqQQKCQsXVd1xmsZR1WL2fFOLY/99YQrZu UyOvXPXvOrMFd2JNJVgfk0pjrntcO19Ql40gFQ3zT8LKfseWL4907MsIGfTgT4ou fi28Ckx/GUzPyvO6A0sr4EPfX93Ckyj8e3kX5UxC+70+jV91L4d0rGhkgPgiB9Xp iIu8/NqMK39ywywFL/RJpruWEdUkpKi6ahVGOeLW4Ph5PsgGTRsyPYfv3kN0Ddlh SWq1lT0KcHOo94fcfE9DD/jX8X8VIKJSMAFxjhhRlIuIQskDqAEMfVW+9PFAdMsX lEPtny2OHm7XLuo1Zei2XWJfS4/CR3Pdvsxbni3dNYu+VQhX5Ot0ZMtTxdflP3TF Ouc15lQxRdGZ+14x+2ZbqWTLqd3nzE0baU41X7gPv1wMWmjbkhgXQtxLLqsM2hyF O4z0kKsy9ePGxxiGMv0Lt63BKO3/y5NiVrCYpGApC/U88cT+qy2vBS9YVm5rZAc+ 0t3uyOiHFRITDGCP0+Ppjx33YAbX7e3A0k5DkkAkXfJCHJa1pDddRwdo4p5IlIh9 lBmGBMSGy7/PZfhv++Aa =PBqO -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical kernel-rt upgrade ready for Red Hat Enterprise Linux 8.2 Telecommunications. Implement security patches and resolve bugs promptly.. kernel-rt update, red hat enterprise, security advisory, telecommunications, bug fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 18, 2023 Important Red Hat
98

Red Hat Enterprise Linux 7.6: RHSA-2021-2355-01 Important Kernel Update

An update for kernel is now available for Red Hat Enterprise Linux 7.6 Advanced Update Support, Red Hat Enterprise Linux 7.6 Telco Extended Update Support, and Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2021:2355-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:2355 Issue date: 2021-06-09 CVE Names: CVE-2019-19532 CVE-2020-12362 CVE-2020-25211 CVE-2020-25705 ==================================================================== 1. Summary: An update for kernel is now available for Red Hat Enterprise Linux 7.6 Advanced Update Support, Red Hat Enterprise Linux 7.6 Telco Extended Update Support, and Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server AUS (v. 7.6) - noarch, x86_64 Red Hat Enterprise Linux Server E4S (v. 7.6) - noarch, ppc64le, x86_64 Red Hat Enterprise Linux Server Optional AUS (v. 7.6) - x86_64 Red Hat Enterprise Linux Server Optional E4S (v. 7.6) - ppc64le, x86_64 Red Hat Enterprise Linux Server Optional TUS (v. 7.6) - x86_64 Red Hat Enterprise Linux Server TUS (v. 7.6) - noarch, x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: Integer overflow in Intel(R) Graphics Drivers (CVE-2020-12362) * kernel: Local buffer overflow in ctnetlink_parse_tuple_filter in net/netfilter/nf_conntrack_netlink.c(CVE-2020-25211) * kernel: malicious USB devices can lead to multiple out-of-bounds write (CVE-2019-19532) * kernel: ICMP rate limiting can be used for DNS poisoning attack (CVE-2020-25705) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * memcg: mem_cgroup_idr can be updated in an uncoordinated manner which can lead to corruption (BZ#1931901) * Kernel experiences panic in update_group_power() due to division error even with Bug 1701115 fix (BZ#1961624) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1781821 - CVE-2019-19532 kernel: malicious USB devices can lead to multiple out-of-bounds write 1877571 - CVE-2020-25211 kernel: Local buffer overflow in ctnetlink_parse_tuple_filter in net/netfilter/nf_conntrack_netlink.c 1894579 - CVE-2020-25705 kernel: ICMP rate limiting can be used for DNS poisoning attack 1930246 - CVE-2020-12362 kernel: Integer overflow in Intel(R) Graphics Drivers 6. Package List: Red Hat Enterprise Linux Server AUS (v.7.6): Source: kernel-3.10.0-957.76.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-957.76.1.el7.noarch.rpm kernel-doc-3.10.0-957.76.1.el7.noarch.rpm x86_64: bpftool-3.10.0-957.76.1.el7.x86_64.rpm kernel-3.10.0-957.76.1.el7.x86_64.rpm kernel-debug-3.10.0-957.76.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-957.76.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-957.76.1.el7.x86_64.rpm kernel-devel-3.10.0-957.76.1.el7.x86_64.rpm kernel-headers-3.10.0-957.76.1.el7.x86_64.rpm kernel-tools-3.10.0-957.76.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-957.76.1.el7.x86_64.rpm perf-3.10.0-957.76.1.el7.x86_64.rpm perf-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm python-perf-3.10.0-957.76.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm Red Hat Enterprise Linux Server E4S (v.7.6): Source: kernel-3.10.0-957.76.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-957.76.1.el7.noarch.rpm kernel-doc-3.10.0-957.76.1.el7.noarch.rpm ppc64le: kernel-3.10.0-957.76.1.el7.ppc64le.rpm kernel-bootwrapper-3.10.0-957.76.1.el7.ppc64le.rpm kernel-debug-3.10.0-957.76.1.el7.ppc64le.rpm kernel-debug-debuginfo-3.10.0-957.76.1.el7.ppc64le.rpm kernel-debug-devel-3.10.0-957.76.1.el7.ppc64le.rpm kernel-debuginfo-3.10.0-957.76.1.el7.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-957.76.1.el7.ppc64le.rpm kernel-devel-3.10.0-957.76.1.el7.ppc64le.rpm kernel-headers-3.10.0-957.76.1.el7.ppc64le.rpm kernel-tools-3.10.0-957.76.1.el7.ppc64le.rpm kernel-tools-debuginfo-3.10.0-957.76.1.el7.ppc64le.rpm kernel-tools-libs-3.10.0-957.76.1.el7.ppc64le.rpm kernel-tools-libs-devel-3.10.0-957.76.1.el7.ppc64le.rpm perf-3.10.0-957.76.1.el7.ppc64le.rpm perf-debuginfo-3.10.0-957.76.1.el7.ppc64le.rpm python-perf-3.10.0-957.76.1.el7.ppc64le.rpm python-perf-debuginfo-3.10.0-957.76.1.el7.ppc64le.rpm x86_64: bpftool-3.10.0-957.76.1.el7.x86_64.rpm kernel-3.10.0-957.76.1.el7.x86_64.rpm kernel-debug-3.10.0-957.76.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-957.76.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-957.76.1.el7.x86_64.rpm kernel-devel-3.10.0-957.76.1.el7.x86_64.rpm kernel-headers-3.10.0-957.76.1.el7.x86_64.rpm kernel-tools-3.10.0-957.76.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-957.76.1.el7.x86_64.rpm perf-3.10.0-957.76.1.el7.x86_64.rpm perf-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm python-perf-3.10.0-957.76.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm Red Hat Enterprise Linux Server TUS (v.7.6): Source: kernel-3.10.0-957.76.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-957.76.1.el7.noarch.rpm kernel-doc-3.10.0-957.76.1.el7.noarch.rpm x86_64: bpftool-3.10.0-957.76.1.el7.x86_64.rpm kernel-3.10.0-957.76.1.el7.x86_64.rpm kernel-debug-3.10.0-957.76.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-957.76.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-957.76.1.el7.x86_64.rpm kernel-devel-3.10.0-957.76.1.el7.x86_64.rpm kernel-headers-3.10.0-957.76.1.el7.x86_64.rpm kernel-tools-3.10.0-957.76.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-957.76.1.el7.x86_64.rpm perf-3.10.0-957.76.1.el7.x86_64.rpm perf-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm python-perf-3.10.0-957.76.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional AUS (v. 7.6): x86_64: kernel-debug-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-957.76.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-957.76.1.el7.x86_64.rpm perf-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional E4S (v.7.6): ppc64le: kernel-debug-debuginfo-3.10.0-957.76.1.el7.ppc64le.rpm kernel-debug-devel-3.10.0-957.76.1.el7.ppc64le.rpm kernel-debuginfo-3.10.0-957.76.1.el7.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-957.76.1.el7.ppc64le.rpm kernel-tools-debuginfo-3.10.0-957.76.1.el7.ppc64le.rpm kernel-tools-libs-devel-3.10.0-957.76.1.el7.ppc64le.rpm perf-debuginfo-3.10.0-957.76.1.el7.ppc64le.rpm python-perf-debuginfo-3.10.0-957.76.1.el7.ppc64le.rpm x86_64: kernel-debug-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-957.76.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-957.76.1.el7.x86_64.rpm perf-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional TUS (v. 7.6): x86_64: kernel-debug-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-957.76.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-957.76.1.el7.x86_64.rpm perf-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-957.76.1.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2019-19532 https://access.redhat.com/security/cve/CVE-2020-12362 https://access.redhat.com/security/cve/CVE-2020-25211 https://access.redhat.com/security/cve/CVE-2020-25705 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYMCKC9zjgjWX9erEAQh/hQ/9G8VQKD/k3cMuAmkYURsGrjGnUayDyRLm l9pT/wc46hjuvERZA/3rQP7ZQKSEzKZKJ9RVkM/3fvNNaotdVKwcqHWUzal99r/t 5HGvD/yYbhSTe8XB34iU1SVoIQkDjSR+lyJUwabx/W4hbNsEubUg8tdTRkjwBOWE e1kvONgdpll6FnKWLiq215igcVoonwsldjuSwzz66nKBRdjSAQQMXMHiOiRcfIN8 qIZuI6AxFKu2zY0iZQe0HiqTonoOyAsBdvpA+abOLdzqC/irmE8O9PG3K3e+vcnP z3QRSu78E+S8WJ8OgH9hNSfuvmSGb946zbYz1EmAwEiygwBsP7BnzmNccbzQHufQ 2Pulm9MSTaOA/Z8TArpoDF5txsBrN0Wc9oD+0em6f73RQsl1tEvCZx3cnd79UzJc sFMBq9ikAj/egbDfpqj1ZSL8rcBWk7XPwyT/pUbnfqbbl6sveYnCgl5Ji0QdHI2q ZgE99yk2gDMCAa0MSS9WnmmImEChHZpMz0snb38cgpDM0qyL9BgNvrA09Xrpq60l 8miN5r/T1Lojn17sx+igmDTLspcBzN1NB/ptH+3mWYKLt8+xs6MtF+KFMBnEiMuH YYriUeiEBHUI33CspLblaEccgll8NuNy81YMjH1xIFdihjlDyStAvcGf87tgWJMT pbqFj/FQyII=NLS/ -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://listman.redhat.com/mailman/listinfo/rhsa-announce . The kernel upgrade for Red Hat Enterprise Linux 7.6 incorporates essential security patches along with significant bug fixes.. Red Hat Enterprise Linux, Kernel Update, Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 09, 2021 Important Red Hat
200

Scientific Linux 7: SLSA-2021-1071-1 Critical: iSCSI Buffer Overflow

kernel: out-of-bounds read in libiscsi module (CVE-2021-27364) * kernel: heap buffer overflow in the iSCSI subsystem (CVE-2021-27365) * kernel: iscsi: unrestricted access to sessions and handles (CVE-2021-27363) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * Customer testing [More...]. Synopsis: Important: kernel security and bug fix update Advisory ID: SLSA-2021:1071-1 Issue Date: 2021-04-06 CVE Numbers: CVE-2021-27365 CVE-2021-27363 CVE-2021-27364 -- Security Fix(es): * kernel: out-of-bounds read in libiscsi module (CVE-2021-27364) * kernel: heap buffer overflow in the iSCSI subsystem (CVE-2021-27365) * kernel: iscsi: unrestricted access to sessions and handles (CVE-2021-27363) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * Customer testing eMMC sees and intermittent boot problem on 7.8+, was not seen on 7.3 * tcm loopback driver causes double-start of scsi command when work is delayed * [Azure][SL-7]Mellanox Patches To Prevent Kernel Hang In MLX4 * A patch from upstream c365c292d059 causes us to end up leaving rt_nr_boosted in an inconsistent state, which causes a hard lockup. * [SL7.9.z] Add fix to update snd_wl1 in bulk receiver fast path -- - Scientific Linux Development Team . Crucial kernel security patch addressing vulnerabilities related to out-of-bounds access and buffer overflows; refer to the advisory for further information.. Kernel Security, Bug Fix Updates, iSCSI Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 12, 2021 Critical Scientific Linux
98

Red Hat Enterprise Linux 7.6: RHSA-2021:0878-01 Important Security Fix

An update for kernel is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel security, bug fix, and enhancement update Advisory ID: RHSA-2021:0878-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:0878 Issue date: 2021-03-16 CVE Names: CVE-2020-14351 CVE-2020-24394 CVE-2020-25212 CVE-2020-29661 ==================================================================== 1. Summary: An update for kernel is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode EUS (v. 7.6) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6) - x86_64 Red Hat Enterprise Linux Server EUS (v. 7.6) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional EUS (v. 7.6) - ppc64, ppc64le, x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: locking issue in drivers/tty/tty_jobctrl.c can lead to an use-after-free (CVE-2020-29661) * kernel: performance counters race condition use-after-free (CVE-2020-14351) * kernel: umask not applied on filesystem without ACL support (CVE-2020-24394) * kernel: TOCTOU mismatch in the NFS client code (CVE-2020-25212) For more details about the security issue(s),including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * Security patch for CVE-2020-25212 breaks directory listings via 'ls' on NFS V4.2 shares mounted with selinux enabled labels (BZ#1919144) * Enable CI and changelog for GitLab workflow (BZ#1930931) Enhancement(s): * [Cavium 7.7 Feat] qla2xxx: Update to latest upstream. (BZ#1918534) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1862849 - CVE-2020-14351 kernel: performance counters race condition use-after-free 1869141 - CVE-2020-24394 kernel: umask not applied on filesystem without ACL support 1877575 - CVE-2020-25212 kernel: TOCTOU mismatch in the NFS client code 1906525 - CVE-2020-29661 kernel: locking issue in drivers/tty/tty_jobctrl.c can lead to an use-after-free 6. Package List: Red Hat Enterprise Linux ComputeNode EUS (v. 7.6): Source: kernel-3.10.0-957.70.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-957.70.1.el7.noarch.rpm kernel-doc-3.10.0-957.70.1.el7.noarch.rpm x86_64: bpftool-3.10.0-957.70.1.el7.x86_64.rpm kernel-3.10.0-957.70.1.el7.x86_64.rpm kernel-debug-3.10.0-957.70.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-957.70.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-957.70.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-957.70.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-957.70.1.el7.x86_64.rpm kernel-devel-3.10.0-957.70.1.el7.x86_64.rpm kernel-headers-3.10.0-957.70.1.el7.x86_64.rpm kernel-tools-3.10.0-957.70.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-957.70.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-957.70.1.el7.x86_64.rpm perf-3.10.0-957.70.1.el7.x86_64.rpm perf-debuginfo-3.10.0-957.70.1.el7.x86_64.rpm python-perf-3.10.0-957.70.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-957.70.1.el7.x86_64.rpm RedHat Enterprise Linux ComputeNode Optional EUS (v. 7.6): x86_64: kernel-debug-debuginfo-3.10.0-957.70.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-957.70.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-957.70.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-957.70.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-957.70.1.el7.x86_64.rpm perf-debuginfo-3.10.0-957.70.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-957.70.1.el7.x86_64.rpm Red Hat Enterprise Linux Server EUS (v.7.6): Source: kernel-3.10.0-957.70.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-957.70.1.el7.noarch.rpm kernel-doc-3.10.0-957.70.1.el7.noarch.rpm ppc64: kernel-3.10.0-957.70.1.el7.ppc64.rpm kernel-bootwrapper-3.10.0-957.70.1.el7.ppc64.rpm kernel-debug-3.10.0-957.70.1.el7.ppc64.rpm kernel-debug-debuginfo-3.10.0-957.70.1.el7.ppc64.rpm kernel-debug-devel-3.10.0-957.70.1.el7.ppc64.rpm kernel-debuginfo-3.10.0-957.70.1.el7.ppc64.rpm kernel-debuginfo-common-ppc64-3.10.0-957.70.1.el7.ppc64.rpm kernel-devel-3.10.0-957.70.1.el7.ppc64.rpm kernel-headers-3.10.0-957.70.1.el7.ppc64.rpm kernel-tools-3.10.0-957.70.1.el7.ppc64.rpm kernel-tools-debuginfo-3.10.0-957.70.1.el7.ppc64.rpm kernel-tools-libs-3.10.0-957.70.1.el7.ppc64.rpm perf-3.10.0-957.70.1.el7.ppc64.rpm perf-debuginfo-3.10.0-957.70.1.el7.ppc64.rpm python-perf-3.10.0-957.70.1.el7.ppc64.rpm python-perf-debuginfo-3.10.0-957.70.1.el7.ppc64.rpm ppc64le: kernel-3.10.0-957.70.1.el7.ppc64le.rpm kernel-bootwrapper-3.10.0-957.70.1.el7.ppc64le.rpm kernel-debug-3.10.0-957.70.1.el7.ppc64le.rpm kernel-debug-debuginfo-3.10.0-957.70.1.el7.ppc64le.rpm kernel-debuginfo-3.10.0-957.70.1.el7.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-957.70.1.el7.ppc64le.rpm kernel-devel-3.10.0-957.70.1.el7.ppc64le.rpm kernel-headers-3.10.0-957.70.1.el7.ppc64le.rpm kernel-tools-3.10.0-957.70.1.el7.ppc64le.rpm kernel-tools-debuginfo-3.10.0-957.70.1.el7.ppc64le.rpm kernel-tools-libs-3.10.0-957.70.1.el7.ppc64le.rpm perf-3.10.0-957.70.1.el7.ppc64le.rpm perf-debuginfo-3.10.0-957.70.1.el7.ppc64le.rpm python-perf-3.10.0-957.70.1.el7.ppc64le.rpm python-perf-debuginfo-3.10.0-957.70.1.el7.ppc64le.rpm s390x: kernel-3.10.0-957.70.1.el7.s390x.rpm kernel-debug-3.10.0-957.70.1.el7.s390x.rpm kernel-debug-debuginfo-3.10.0-957.70.1.el7.s390x.rpm kernel-debug-devel-3.10.0-957.70.1.el7.s390x.rpm kernel-debuginfo-3.10.0-957.70.1.el7.s390x.rpm kernel-debuginfo-common-s390x-3.10.0-957.70.1.el7.s390x.rpm kernel-devel-3.10.0-957.70.1.el7.s390x.rpm kernel-headers-3.10.0-957.70.1.el7.s390x.rpm kernel-kdump-3.10.0-957.70.1.el7.s390x.rpm kernel-kdump-debuginfo-3.10.0-957.70.1.el7.s390x.rpm kernel-kdump-devel-3.10.0-957.70.1.el7.s390x.rpm perf-3.10.0-957.70.1.el7.s390x.rpm perf-debuginfo-3.10.0-957.70.1.el7.s390x.rpm python-perf-3.10.0-957.70.1.el7.s390x.rpm python-perf-debuginfo-3.10.0-957.70.1.el7.s390x.rpm x86_64: bpftool-3.10.0-957.70.1.el7.x86_64.rpm kernel-3.10.0-957.70.1.el7.x86_64.rpm kernel-debug-3.10.0-957.70.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-957.70.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-957.70.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-957.70.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-957.70.1.el7.x86_64.rpm kernel-devel-3.10.0-957.70.1.el7.x86_64.rpm kernel-headers-3.10.0-957.70.1.el7.x86_64.rpm kernel-tools-3.10.0-957.70.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-957.70.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-957.70.1.el7.x86_64.rpm perf-3.10.0-957.70.1.el7.x86_64.rpm perf-debuginfo-3.10.0-957.70.1.el7.x86_64.rpm python-perf-3.10.0-957.70.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-957.70.1.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional EUS (v.7.6): ppc64: kernel-debug-debuginfo-3.10.0-957.70.1.el7.ppc64.rpm kernel-debuginfo-3.10.0-957.70.1.el7.ppc64.rpm kernel-debuginfo-common-ppc64-3.10.0-957.70.1.el7.ppc64.rpm kernel-tools-debuginfo-3.10.0-957.70.1.el7.ppc64.rpm kernel-tools-libs-devel-3.10.0-957.70.1.el7.ppc64.rpm perf-debuginfo-3.10.0-957.70.1.el7.ppc64.rpm python-perf-debuginfo-3.10.0-957.70.1.el7.ppc64.rpm ppc64le: kernel-debug-debuginfo-3.10.0-957.70.1.el7.ppc64le.rpm kernel-debug-devel-3.10.0-957.70.1.el7.ppc64le.rpm kernel-debuginfo-3.10.0-957.70.1.el7.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-957.70.1.el7.ppc64le.rpm kernel-tools-debuginfo-3.10.0-957.70.1.el7.ppc64le.rpm kernel-tools-libs-devel-3.10.0-957.70.1.el7.ppc64le.rpm perf-debuginfo-3.10.0-957.70.1.el7.ppc64le.rpm python-perf-debuginfo-3.10.0-957.70.1.el7.ppc64le.rpm x86_64: kernel-debug-debuginfo-3.10.0-957.70.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-957.70.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-957.70.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-957.70.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-957.70.1.el7.x86_64.rpm perf-debuginfo-3.10.0-957.70.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-957.70.1.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2020-14351 https://access.redhat.com/security/cve/CVE-2020-24394 https://access.redhat.com/security/cve/CVE-2020-25212 https://access.redhat.com/security/cve/CVE-2020-29661 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYFDHTtzjgjWX9erEAQgMwRAAmciGnGTaC97k1bJgX42n8dc4yATy5Arr rkG9GV0fuZyA0K3NTQHzXzUxmUZmqpIw08g3hvnzsUCkaHcLCcfby7EvIS4MPASE flN5JCjKqHBqIEVrXW+s+shnjiUU3TP0QyN3t5TzuosxAwfq8tW0YDpfY/0o/v32 bdlRxBOX5dakNO6mj40tAEmGHZmHglJqYpGFSnGavE0Y2KQHJPHpsNFYBa77Cb9I /EzJfdLcXLgJGroMcWLaY3G2qCbI47cJI/Mln5spEzPd3ZuZfagCIPiBNtlNJngx QXgRaN3KdzGrMDjS0EJTdOVhUn65jLinYiNh6XSShpzRCtKKRPeeTKKetj5pt4J6 cKvAP4bGmri+F+tHJskP/zOTda2TPOXx8a/nzUlsXz1WjC74wN+emcoZuQZelZqd 5Eqr5lsQieTOBkQj7l4nIemwalrFi9l5RUhQNHZ44D85oAKgrqa8xxsvH5Hh9N3z TCavuEWFSl7ThIJsjgff8D8poJgs1wfOzBadzam3scZiTOFN5HG6aUNntInqGQSp dsTmaSTp8aE41Qrk9+J5X//CN2t815LMVhcqn33gn3kIWSBBdrVA5/jQuF/gzGN0 zAF7YoQYnJv8+JjKKF8SyR7gkH1irgXoT/K0SLELJzzDYzaLNqab+5/iPhMiW0Cx yxBTk0suqaE=c0qF -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://listman.redhat.com/mailman/listinfo/rhsa-announce . Kernel enhancement for Red Hat Enterprise Linux 7.6 targeting significant security vulnerabilities and solutions for various bugs.. Red Hat Enterprise Linux, Kernel Update, Security Patch, Linux Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 16, 2021 Important Red Hat
98

Red Hat Enterprise Linux 7.5: RHSA-2020-0036-01 Moderate Kernel Patch

An update for kernel is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: kernel security and bug fix update Advisory ID: RHSA-2020:0036-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:0036 Issue date: 2020-01-07 CVE Names: CVE-2017-0861 CVE-2017-10661 CVE-2018-10853 CVE-2018-18281 CVE-2019-11810 CVE-2019-11811 ==================================================================== 1. Summary: An update for kernel is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode EUS (v. 7.5) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.5) - x86_64 Red Hat Enterprise Linux Server EUS (v. 7.5) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional EUS (v. 7.5) - ppc64, ppc64le, x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: Use-after-free in snd_pcm_info function in ALSA subsystem potentially leads to privilege escalation (CVE-2017-0861) * kernel: Handling of might_cancel queueing is not properly pretected against race (CVE-2017-10661) * kernel: kvm: guest userspace to guest kernel write (CVE-2018-10853) * kernel: TLB flush happens too late on mremap(CVE-2018-18281) * kernel: a NULL pointer dereference in drivers/scsi/megaraid/megaraid_sas_base.c leading to DoS (CVE-2019-11810) * kernel: use-after-free in drivers/char/ipmi/ipmi_si_intf.c, ipmi_si_mem_io.c, ipmi_si_port_io.c (CVE-2019-11811) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * Hard lockup in free_one_page()-> _raw_spin_lock() because sosreport command is reading from /proc/pagetypeinfo (BZ#1770730) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1481136 - CVE-2017-10661 kernel: Handling of might_cancel queueing is not properly pretected against race 1563994 - CVE-2017-0861 kernel: Use-after-free in snd_pcm_info function in ALSA subsystem potentially leads to privilege escalation 1589890 - CVE-2018-10853 kernel: kvm: guest userspace to guest kernel write 1645121 - CVE-2018-18281 kernel: TLB flush happens too late on mremap 1709164 - CVE-2019-11810 kernel: a NULL pointer dereference in drivers/scsi/megaraid/megaraid_sas_base.c leading to DoS 1709180 - CVE-2019-11811 kernel: use-after-free in drivers/char/ipmi/ipmi_si_intf.c, ipmi_si_mem_io.c, ipmi_si_port_io.c 6. Package List: Red Hat Enterprise Linux ComputeNode EUS (v.7.5): Source: kernel-3.10.0-862.46.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-862.46.1.el7.noarch.rpm kernel-doc-3.10.0-862.46.1.el7.noarch.rpm x86_64: kernel-3.10.0-862.46.1.el7.x86_64.rpm kernel-debug-3.10.0-862.46.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-862.46.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-862.46.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-862.46.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-862.46.1.el7.x86_64.rpm kernel-devel-3.10.0-862.46.1.el7.x86_64.rpm kernel-headers-3.10.0-862.46.1.el7.x86_64.rpm kernel-tools-3.10.0-862.46.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-862.46.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-862.46.1.el7.x86_64.rpm perf-3.10.0-862.46.1.el7.x86_64.rpm perf-debuginfo-3.10.0-862.46.1.el7.x86_64.rpm python-perf-3.10.0-862.46.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-862.46.1.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.5): x86_64: kernel-debug-debuginfo-3.10.0-862.46.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-862.46.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-862.46.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-862.46.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-862.46.1.el7.x86_64.rpm perf-debuginfo-3.10.0-862.46.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-862.46.1.el7.x86_64.rpm Red Hat Enterprise Linux Server EUS (v.7.5): Source: kernel-3.10.0-862.46.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-862.46.1.el7.noarch.rpm kernel-doc-3.10.0-862.46.1.el7.noarch.rpm ppc64: kernel-3.10.0-862.46.1.el7.ppc64.rpm kernel-bootwrapper-3.10.0-862.46.1.el7.ppc64.rpm kernel-debug-3.10.0-862.46.1.el7.ppc64.rpm kernel-debug-debuginfo-3.10.0-862.46.1.el7.ppc64.rpm kernel-debug-devel-3.10.0-862.46.1.el7.ppc64.rpm kernel-debuginfo-3.10.0-862.46.1.el7.ppc64.rpm kernel-debuginfo-common-ppc64-3.10.0-862.46.1.el7.ppc64.rpm kernel-devel-3.10.0-862.46.1.el7.ppc64.rpm kernel-headers-3.10.0-862.46.1.el7.ppc64.rpm kernel-tools-3.10.0-862.46.1.el7.ppc64.rpm kernel-tools-debuginfo-3.10.0-862.46.1.el7.ppc64.rpm kernel-tools-libs-3.10.0-862.46.1.el7.ppc64.rpm perf-3.10.0-862.46.1.el7.ppc64.rpm perf-debuginfo-3.10.0-862.46.1.el7.ppc64.rpm python-perf-3.10.0-862.46.1.el7.ppc64.rpm python-perf-debuginfo-3.10.0-862.46.1.el7.ppc64.rpm ppc64le: kernel-3.10.0-862.46.1.el7.ppc64le.rpm kernel-bootwrapper-3.10.0-862.46.1.el7.ppc64le.rpm kernel-debug-3.10.0-862.46.1.el7.ppc64le.rpm kernel-debug-debuginfo-3.10.0-862.46.1.el7.ppc64le.rpm kernel-debuginfo-3.10.0-862.46.1.el7.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-862.46.1.el7.ppc64le.rpm kernel-devel-3.10.0-862.46.1.el7.ppc64le.rpm kernel-headers-3.10.0-862.46.1.el7.ppc64le.rpm kernel-tools-3.10.0-862.46.1.el7.ppc64le.rpm kernel-tools-debuginfo-3.10.0-862.46.1.el7.ppc64le.rpm kernel-tools-libs-3.10.0-862.46.1.el7.ppc64le.rpm perf-3.10.0-862.46.1.el7.ppc64le.rpm perf-debuginfo-3.10.0-862.46.1.el7.ppc64le.rpm python-perf-3.10.0-862.46.1.el7.ppc64le.rpm python-perf-debuginfo-3.10.0-862.46.1.el7.ppc64le.rpm s390x: kernel-3.10.0-862.46.1.el7.s390x.rpm kernel-debug-3.10.0-862.46.1.el7.s390x.rpm kernel-debug-debuginfo-3.10.0-862.46.1.el7.s390x.rpm kernel-debug-devel-3.10.0-862.46.1.el7.s390x.rpm kernel-debuginfo-3.10.0-862.46.1.el7.s390x.rpm kernel-debuginfo-common-s390x-3.10.0-862.46.1.el7.s390x.rpm kernel-devel-3.10.0-862.46.1.el7.s390x.rpm kernel-headers-3.10.0-862.46.1.el7.s390x.rpm kernel-kdump-3.10.0-862.46.1.el7.s390x.rpm kernel-kdump-debuginfo-3.10.0-862.46.1.el7.s390x.rpm kernel-kdump-devel-3.10.0-862.46.1.el7.s390x.rpm perf-3.10.0-862.46.1.el7.s390x.rpm perf-debuginfo-3.10.0-862.46.1.el7.s390x.rpm python-perf-3.10.0-862.46.1.el7.s390x.rpm python-perf-debuginfo-3.10.0-862.46.1.el7.s390x.rpm x86_64: kernel-3.10.0-862.46.1.el7.x86_64.rpm kernel-debug-3.10.0-862.46.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-862.46.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-862.46.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-862.46.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-862.46.1.el7.x86_64.rpm kernel-devel-3.10.0-862.46.1.el7.x86_64.rpm kernel-headers-3.10.0-862.46.1.el7.x86_64.rpm kernel-tools-3.10.0-862.46.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-862.46.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-862.46.1.el7.x86_64.rpm perf-3.10.0-862.46.1.el7.x86_64.rpm perf-debuginfo-3.10.0-862.46.1.el7.x86_64.rpm python-perf-3.10.0-862.46.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-862.46.1.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional EUS (v.7.5): ppc64: kernel-debug-debuginfo-3.10.0-862.46.1.el7.ppc64.rpm kernel-debuginfo-3.10.0-862.46.1.el7.ppc64.rpm kernel-debuginfo-common-ppc64-3.10.0-862.46.1.el7.ppc64.rpm kernel-tools-debuginfo-3.10.0-862.46.1.el7.ppc64.rpm kernel-tools-libs-devel-3.10.0-862.46.1.el7.ppc64.rpm perf-debuginfo-3.10.0-862.46.1.el7.ppc64.rpm python-perf-debuginfo-3.10.0-862.46.1.el7.ppc64.rpm ppc64le: kernel-debug-debuginfo-3.10.0-862.46.1.el7.ppc64le.rpm kernel-debug-devel-3.10.0-862.46.1.el7.ppc64le.rpm kernel-debuginfo-3.10.0-862.46.1.el7.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-862.46.1.el7.ppc64le.rpm kernel-tools-debuginfo-3.10.0-862.46.1.el7.ppc64le.rpm kernel-tools-libs-devel-3.10.0-862.46.1.el7.ppc64le.rpm perf-debuginfo-3.10.0-862.46.1.el7.ppc64le.rpm python-perf-debuginfo-3.10.0-862.46.1.el7.ppc64le.rpm x86_64: kernel-debug-debuginfo-3.10.0-862.46.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-862.46.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-862.46.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-862.46.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-862.46.1.el7.x86_64.rpm perf-debuginfo-3.10.0-862.46.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-862.46.1.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2017-0861 https://access.redhat.com/security/cve/CVE-2017-10661 https://access.redhat.com/security/cve/CVE-2018-10853 https://access.redhat.com/security/cve/CVE-2018-18281 https://access.redhat.com/security/cve/CVE-2019-11810 https://access.redhat.com/security/cve/CVE-2019-11811 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXhR5G9zjgjWX9erEAQiv9A/8COGR9UumlJp9I/Z9BEroJqnYXELC/b4q gSFt321bTrMbPeSdDXqMiEFc1fnpfFJogPgS1/9e5H0t9mVQf9Glfd94129MsWfv AQSlPr+pdwyiBYFPr/5zJJ31zf4qjTJKA/tIT++kqtBnYeawSlfE0kUBBiyNb560 5Hk5caWDX84Y2g5QFQ9Beu9XBJoMylKkxvjfWyQY5u7JCIar0oxIkiG74yhwfcrB D8nch58bb9Nq+SjGzFgtqlfjcFJKPyQRmZO8O6FKRFU02z0mRg6SdiJ1NkR1RVEL Skr13aQ0hYpTL/PjXCMW34OgHhRr37Dq2pB0EX5TI2SUFD/daOpFPUkm4zNxKTo6 M4XnSsd0YFr/8s+0NVtMnbP/qlwVRefzS4KPfVqKz0qZJDSLnIHt5IXdASmkSByw EKo3hnLTjvVg0g1qDcRHk/lBKyualrsHRhEYNFSLgdddrLVMxTmse2xov+YlP5SU E0TziI5/VRxKiylTtV4CL7TOaUm6bm6Yxjb7MXEVCNgRCP+AMTHrC6b9U5Png/dP ThaJtn+sRyscsUN1BsrqN6y3BIHPAa7IG1YH1Zd/JGhL+80jneDyV+851/ZkId+V /liSDuZ6lonCNUGvf7gVhykAcD3ue6rUyaefb9oAjNgGqTYZ3LH1rjUsTa4EpgFR X+Rd9aVJ/Cc=KNZc -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu recommends a critical package update containing fixes for vulnerabilities linked to unauthorized access and service interruptions.. kernel update, bug fixes, Red Hat Enterprise Linux, security advisory. . LinuxSecurity.com Team

Calendar%202 Jan 07, 2020 Red Hat
200

Scientific Linux: SLSA-2019-2736-1 Important Kernel Security Fix

kernel: Memory corruption due to incorrect socket cloning (CVE-2018-9568) * kernel: a NULL pointer dereference in drivers/scsi/megaraid/megaraid_sas_base.c leading to DoS (CVE-2019-11810) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the R [More...]. Synopsis: Important: kernel security and bug fix update Advisory ID: SLSA-2019:2736-1 Issue Date: 2019-09-12 CVE Numbers: None -- Security Fix(es): * kernel: Memory corruption due to incorrect socket cloning (CVE-2018-9568) * kernel: a NULL pointer dereference in drivers/scsi/megaraid/megaraid_sas_base.c leading to DoS (CVE-2019-11810) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * fragmented packets timing out (BZ#1728931) * Backport TCP follow-up for small buffers (BZ#1732107) -- SL6 x86_64 kernel-2.6.32-754.22.1.el6.x86_64.rpm kernel-debug-2.6.32-754.22.1.el6.x86_64.rpm kernel-debug-debuginfo-2.6.32-754.22.1.el6.i686.rpm kernel-debug-debuginfo-2.6.32-754.22.1.el6.x86_64.rpm kernel-debug-devel-2.6.32-754.22.1.el6.i686.rpm kernel-debug-devel-2.6.32-754.22.1.el6.x86_64.rpm kernel-debuginfo-2.6.32-754.22.1.el6.i686.rpm kernel-debuginfo-2.6.32-754.22.1.el6.x86_64.rpm kernel-debuginfo-common-i686-2.6.32-754.22.1.el6.i686.rpm kernel-debuginfo-common-x86_64-2.6.32-754.22.1.el6.x86_64.rpm kernel-devel-2.6.32-754.22.1.el6.x86_64.rpm kernel-headers-2.6.32-754.22.1.el6.x86_64.rpm perf-2.6.32-754.22.1.el6.x86_64.rpm perf-debuginfo-2.6.32-754.22.1.el6.i686.rpm perf-debuginfo-2.6.32-754.22.1.el6.x86_64.rpm python-perf-debuginfo-2.6.32-754.22.1.el6.i686.rpm python-perf-debuginfo-2.6.32-754.22.1.el6.x86_64.rpm python-perf-2.6.32-754.22.1.el6.x86_64.rpm i386 kernel-2.6.32-754.22.1.el6.i686.rpm kernel-debug-2.6.32-754.22.1.el6.i686.rpm kernel-debug-debuginfo-2.6.32-754.22.1.el6.i686.rpm kernel-debug-devel-2.6.32-754.22.1.el6.i686.rpm kernel-debuginfo-2.6.32-754.22.1.el6.i686.rpm kernel-debuginfo-common-i686-2.6.32-754.22.1.el6.i686.rpm kernel-devel-2.6.32-754.22.1.el6.i686.rpm kernel-headers-2.6.32-754.22.1.el6.i686.rpm perf-2.6.32-754.22.1.el6.i686.rpm perf-debuginfo-2.6.32-754.22.1.el6.i686.rpm python-perf-debuginfo-2.6.32-754.22.1.el6.i686.rpm python-perf-2.6.32-754.22.1.el6.i686.rpm noarch kernel-abi-whitelists-2.6.32-754.22.1.el6.noarch.rpm kernel-doc-2.6.32-754.22.1.el6.noarch.rpm kernel-firmware-2.6.32-754.22.1.el6.noarch.rpm - Scientific Linux Development Team . The recent release of Scientific Linux features important patches and upgrades addressing memory corruption and denial of service (DoS) vulnerabilities for enhanced stability and security. kernel security update, Scientific Linux advisory, memory corruption fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 12, 2019 Important Scientific Linux
200

SciLinux: SLSA-2018:3651-1 Moderate Kernel Bug Fix for DoS

kernel: stack-based buffer overflow in chap_server_compute_md5() in iscsi target (CVE-2018-14633) * kernel: NULL pointer dereference in af_netlink.c:__netlink_ns_capable() allows for denial of service (CVE-2018-14646) Bug Fix(es): See the descriptions in the related Knowledge Article: SL7 x86_64 bpftool-3.10.0-957.1.3.el7.x86_64.rpm kernel-3.10.0-957.1.3.el7.x86_64.rpm kernel [More...]. Synopsis: Moderate: kernel security, bug fix, and enhancement update Advisory ID: SLSA-2018:3651-1 Issue Date: 2018-11-27 CVE Numbers: CVE-2018-14633 CVE-2018-14646 -- Security Fix(es): * kernel: stack-based buffer overflow in chap_server_compute_md5() in iscsi target (CVE-2018-14633) * kernel: NULL pointer dereference in af_netlink.c:__netlink_ns_capable() allows for denial of service (CVE-2018-14646) Bug Fix(es): See the descriptions in the related Knowledge Article: -- SL7 x86_64 bpftool-3.10.0-957.1.3.el7.x86_64.rpm kernel-3.10.0-957.1.3.el7.x86_64.rpm kernel-debug-3.10.0-957.1.3.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-957.1.3.el7.x86_64.rpm kernel-debug-devel-3.10.0-957.1.3.el7.x86_64.rpm kernel-debuginfo-3.10.0-957.1.3.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-957.1.3.el7.x86_64.rpm kernel-devel-3.10.0-957.1.3.el7.x86_64.rpm kernel-headers-3.10.0-957.1.3.el7.x86_64.rpm kernel-tools-3.10.0-957.1.3.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-957.1.3.el7.x86_64.rpm kernel-tools-libs-3.10.0-957.1.3.el7.x86_64.rpm perf-3.10.0-957.1.3.el7.x86_64.rpm perf-debuginfo-3.10.0-957.1.3.el7.x86_64.rpm python-perf-3.10.0-957.1.3.el7.x86_64.rpm python-perf-debuginfo-3.10.0-957.1.3.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-957.1.3.el7.x86_64.rpm noarch kernel-abi-whitelists-3.10.0-957.1.3.el7.noarch.rpm kernel-doc-3.10.0-957.1.3.el7.noarch.rpm - Scientific Linux Development Team . A nominal revision for Scientific Linux kernel resolves several bugs and security vulnerabilities. Refer to theadvisory for comprehensive information.. Kernel Bug Fix, Denial of Service, Security Update. . LinuxSecurity.com Team

Calendar%202 Nov 27, 2018 Scientific Linux
98

Red Hat Enterprise MRG: RHSA-2017-3295-01 Moderate: Memory Disclosure Issue

An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: kernel-rt security and bug fix update Advisory ID: RHSA-2017:3295-01 Product: Red Hat Enterprise MRG for RHEL-6 Advisory URL: https://access.redhat.com/errata/RHSA-2017:3295 Issue date: 2017-11-30 CVE Names: CVE-2017-1000380 ==================================================================== 1. Summary: An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: MRG Realtime for RHEL 6 Server v.2 - noarch, x86_64 3. Description: The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * It was found that the timer functionality in the Linux kernel ALSA subsystem is prone to a race condition between read and ioctl system call handlers, resulting in an uninitialized memory disclosure to user space. A local user could use this flaw to read information belonging to other users. (CVE-2017-1000380, Moderate) Red Hat would like to thank Alexander Potapenko (Google) for reporting this issue. Bug Fix(es): * The current realtime throttling mechanism prevents the starvation of non-realtime tasks by CPU-intensive realtime tasks. When a realtime run queue is throttled, it allowsnon-realtime tasks to run. If there are not non-realtime tasks, the CPU goes idle. To safely maximize CPU usage by decreasing the CPU idle time, the RT_RUNTIME_GREED scheduler feature has been implemented. When enabled, this feature checks if non-realtime tasks are starving before throttling the realtime task. The RT_RUNTIME_GREED scheduler option guarantees some run time on all CPUs for the non-realtime tasks, while keeping the realtime tasks running as much as possible. (BZ#1459275) * The kernel-rt packages have been upgraded to version 3.10.0-693.11.1.rt56.595, which provides a number of security and bug fixes over the previous version. (BZ#1500036) * In the realtime kernel, if the rt_mutex locking mechanism was taken in the interrupt context, the normal priority inheritance protocol incorrectly identified a deadlock, and a kernel panic occurred. This update reverts the patch that added rt_mutex in the interrupt context, and the kernel no longer panics due to this behavior. (BZ#1509021) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1463311 - CVE-2017-1000380 kernel: information leak due to a data race in ALSA timer 1500036 - update the MRG 2.5.z 3.10 kernel-rt sources 1509021 - [MRG-RT] Possible regression with NOHZ_FULL & rt_mutexes in IRQ (BZ1250649) 6. Package List: MRG Realtime for RHEL 6 Serverv.2: Source: kernel-rt-3.10.0-693.11.1.rt56.597.el6rt.src.rpm noarch: kernel-rt-doc-3.10.0-693.11.1.rt56.597.el6rt.noarch.rpm kernel-rt-firmware-3.10.0-693.11.1.rt56.597.el6rt.noarch.rpm x86_64: kernel-rt-3.10.0-693.11.1.rt56.597.el6rt.x86_64.rpm kernel-rt-debug-3.10.0-693.11.1.rt56.597.el6rt.x86_64.rpm kernel-rt-debug-debuginfo-3.10.0-693.11.1.rt56.597.el6rt.x86_64.rpm kernel-rt-debug-devel-3.10.0-693.11.1.rt56.597.el6rt.x86_64.rpm kernel-rt-debuginfo-3.10.0-693.11.1.rt56.597.el6rt.x86_64.rpm kernel-rt-debuginfo-common-x86_64-3.10.0-693.11.1.rt56.597.el6rt.x86_64.rpm kernel-rt-devel-3.10.0-693.11.1.rt56.597.el6rt.x86_64.rpm kernel-rt-trace-3.10.0-693.11.1.rt56.597.el6rt.x86_64.rpm kernel-rt-trace-debuginfo-3.10.0-693.11.1.rt56.597.el6rt.x86_64.rpm kernel-rt-trace-devel-3.10.0-693.11.1.rt56.597.el6rt.x86_64.rpm kernel-rt-vanilla-3.10.0-693.11.1.rt56.597.el6rt.x86_64.rpm kernel-rt-vanilla-debuginfo-3.10.0-693.11.1.rt56.597.el6rt.x86_64.rpm kernel-rt-vanilla-devel-3.10.0-693.11.1.rt56.597.el6rt.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2017-1000380 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2017 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFaIDvCXlSAg2UNWIIRAqNlAKCgvv0MD+8c8tUZ6PWtyo5G4VBIyQCgww6S V5ptWOp9rkSfJ6aQ/qWNjMM=vLDd -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Red Hat has released a vital kernel-rt security patch to address a significant memory exposure vulnerability. Urgent response needed!. Kernel Security, Red Hat Update, Memory Leak, Bug Fix, Enterprise Software. . LinuxSecurity.com Team

Calendar%202 Nov 30, 2017 Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200