RHEL 6 : MRG (RHSA-2019:0641)
High Nessus Plugin ID 123432
SynopsisThe remote Red Hat host is missing one or more security updates.
DescriptionAn update for kernel-rt is now available for Red Hat Enterprise MRG 2.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.
Security Fix(es) :
* kernel: MIDI driver race condition leads to a double-free (CVE-2018-10902)
* kernel: net/rxrpc: overflow in decoding of krb5 principal (CVE-2017-7482)
* kernel: Missing length check of payload in net/sctp/ sm_make_chunk.c:_sctp_make_chunk() function allows denial of service (CVE-2018-5803)
* kernel: use-after-free in ntfs_read_locked_inode in the ntfs.ko (CVE-2018-12929)
* kernel: stack-based out-of-bounds write in ntfs_end_buffer_async_read in the ntfs.ko (CVE-2018-12930)
* kernel: stack-based out-of-bounds write in ntfs_attr_find in the ntfs.ko (CVE-2018-12931)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es) :
* Remove the NTFS module from the MRG 2.5.x realtime kernel (BZ#1674523)
* update the MRG 2.5.z 3.10 kernel-rt sources (BZ#1674935)
Users of kernel-rt are advised to upgrade to these updated packages, which fix these bugs.
SolutionUpdate the affected packages.