RHEL 7 : kernel-alt (RHSA-2019:0525)

medium Nessus Plugin ID 122807

Synopsis

The remote Red Hat host is missing one or more security updates.

Description

An update for kernel-alt is now available for Red Hat Enterprise Linux 7.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

The kernel-alt packages provide the Linux kernel version 4.x.

Security Fix(es) :

* kernel: out-of-bounds memcpy in fs/ext4/inline.c:ext4_read_inline_data() with crafted ext4 image (CVE-2018-11412)

* kernel: use-after-free in jbd2_journal_commit_transaction funtion (CVE-2018-10876)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es) :

* blk-mq IO hang in null_blk test (BZ#1581223)

* lpfc remove lpfc_enable_pbde module parameter. (BZ#1615875)

* RHEL-Alt-7.6 - [Power9][DD2.2][4.14.0-109]package installation segfaults inside debian chroot env in P9 KVM guest with HTM enabled (kvm) (BZ# 1628817)

* Pegas1.1 - [P9] 'threads=2' or higher is required to boot up VM with above 256 vcpu [rhel-alt-7.6.z] (BZ#1634653)

* RHEL-Alt-7.6 Snapshot5 - System crashed under stress-ng & HTX on the mix mode guest (kvm) (BZ#1637890)

* RHEL-Alt-7.6 - BostonESS:P9:DD2.01 - Testing Ethtool options 'r' and 'p' for the i40e driver causes the kernel to crash and reboots the server (i40e) (CORAL) (BZ#1644606)

* RHEL-Alt-7.6 Host/RHV4.2: system crashed and kdump failed to collect CPUs in KVM guests (BZ#1649196)

* RHEL-Alt-7.6 Host:BostonLC:P9:boslcp1: system crashed in
__find_linux_pte+0xac (kvm) (BZ#1651065)

* [LLNL 7.7 Bug] Rasdaemon doesn't seem to collect APEI errors (BZ#1664495)

Users of kernel are advised to upgrade to these updated packages, which fix these bugs.

Solution

Update the affected packages.

See Also

https://access.redhat.com/errata/RHSA-2019:0525

https://access.redhat.com/security/cve/cve-2018-10876

https://access.redhat.com/security/cve/cve-2018-11412

Plugin Details

Severity: Medium

ID: 122807

File Name: redhat-RHSA-2019-0525.nasl

Version: 1.9

Type: local

Agent: unix

Published: 3/13/2019

Updated: 5/23/2022

Supported Sensors: Agentless Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: Medium

Base Score: 4.9

Temporal Score: 3.8

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

Temporal Vector: CVSS2#E:POC/RL:OF/RC:C

CVSS Score Source: CVE-2018-10876

CVSS v3

Risk Factor: Medium

Base Score: 5.9

Temporal Score: 5.3

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2018-11412

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:kernel-abi-whitelists, p-cpe:/a:redhat:enterprise_linux:kernel-debug, p-cpe:/a:redhat:enterprise_linux:kernel-debug-debuginfo, p-cpe:/a:redhat:enterprise_linux:kernel-debug-devel, p-cpe:/a:redhat:enterprise_linux:kernel-debuginfo, p-cpe:/a:redhat:enterprise_linux:kernel-debuginfo-common-s390x, p-cpe:/a:redhat:enterprise_linux:kernel-devel, p-cpe:/a:redhat:enterprise_linux:kernel-doc, p-cpe:/a:redhat:enterprise_linux:kernel-headers, p-cpe:/a:redhat:enterprise_linux:kernel-kdump, p-cpe:/a:redhat:enterprise_linux:kernel-kdump-debuginfo, p-cpe:/a:redhat:enterprise_linux:kernel-kdump-devel, p-cpe:/a:redhat:enterprise_linux:perf, p-cpe:/a:redhat:enterprise_linux:perf-debuginfo, p-cpe:/a:redhat:enterprise_linux:python-perf, p-cpe:/a:redhat:enterprise_linux:python-perf-debuginfo, cpe:/o:redhat:enterprise_linux:7, p-cpe:/a:redhat:enterprise_linux:kernel

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/12/2019

Vulnerability Publication Date: 5/24/2018

Reference Information

CVE: CVE-2018-10876, CVE-2018-11412

RHSA: 2019:0525