SynopsisThe remote Red Hat host is missing one or more security updates.
DescriptionAn update for kernel-alt is now available for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
The kernel-alt packages provide the Linux kernel version 4.x.
Security Fix(es) :
* kernel: MIDI driver race condition leads to a double-free (CVE-2018-10902)
* kernel: Use-after-free in __blk_drain_queue() function in block/blk-core.c (CVE-2018-20856)
* kernel: brcmfmac heap buffer overflow in brcmf_wowl_nd_results (CVE-2019-9500)
* hardware: bluetooth: BR/EDR encryption key negotiation attacks (KNOB) (CVE-2019-9506)
* kernel: a NULL pointer dereference in drivers/scsi/megaraid/ megaraid_sas_base.c leading to DoS (CVE-2019-11810)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es) :
* kernel modules pkey and paes_s390 are not available (BZ#1719192)
* pkey: Indicate old mkvp only if old and curr. mkvp are different (BZ# 1720621)
* System dropped into Mon running softboots Exception: 501 (Hardware Interrupt) at c00000000000a814 replay_interrupt_return+0x0/0x4 (ipmi) (BZ# 1737563)
* kernel: jump label transformation performance (BZ#1739143)
* Backport i40e MDD detection removal for PFs (BZ#1747618)
SolutionUpdate the affected packages.