RHSA-2019:0514

Affecting kernel-rt-devel package, versions centos:7: <0:3.10.0-957.10.1.rt56.921.el7

high severity
Do your applications use this vulnerable package? Test your applications

Overview

The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: Memory corruption due to incorrect socket cloning (CVE-2018-9568) * kernel: Unprivileged users able to inspect kernel stacks of arbitrary tasks (CVE-2018-17972) * kernel: Faulty computation of numberic bounds in the BPF verifier (CVE-2018-18445) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * kernel-rt: update to the RHEL7.6.z batch#3 source tree (BZ#1672406) Users of kernel-rt are advised to upgrade to these updated packages, which fix this bug.

CVE
RHSA-2019:0514
Snyk ID
SNYK-LINUX-KERNELRTDEVEL-440450
Published
14 Mar, 2019