Synopsis: Important: kernel security, bug fix, and enhancement update
Advisory ID:       SLSA-2019:1873-1
Issue Date:        2019-07-29
CVE Numbers:       CVE-2018-16871
                   CVE-2018-16884
                   CVE-2019-11811
                   CVE-2019-11085
--

Security Fix(es):

* kernel: nfs: use-after-free in svc_process_common() (CVE-2018-16884)

* kernel: insufficient input validation in kernel mode driver in Intel
i915 graphics leads to privilege escalation (CVE-2019-11085)

* kernel: nfs: NULL pointer dereference due to an anomalized NFS message
sequence (CVE-2018-16871)

* kernel: use-after-free in drivers/char/ipmi/ipmi_si_intf.c,
ipmi_si_mem_io.c, ipmi_si_port_io.c (CVE-2019-11811)
--

SL7
  x86_64
    bpftool-3.10.0-957.27.2.el7.x86_64.rpm
    kernel-3.10.0-957.27.2.el7.x86_64.rpm
    kernel-debug-3.10.0-957.27.2.el7.x86_64.rpm
    kernel-debug-debuginfo-3.10.0-957.27.2.el7.x86_64.rpm
    kernel-debug-devel-3.10.0-957.27.2.el7.x86_64.rpm
    kernel-debuginfo-3.10.0-957.27.2.el7.x86_64.rpm
    kernel-debuginfo-common-x86_64-3.10.0-957.27.2.el7.x86_64.rpm
    kernel-devel-3.10.0-957.27.2.el7.x86_64.rpm
    kernel-headers-3.10.0-957.27.2.el7.x86_64.rpm
    kernel-tools-3.10.0-957.27.2.el7.x86_64.rpm
    kernel-tools-debuginfo-3.10.0-957.27.2.el7.x86_64.rpm
    kernel-tools-libs-3.10.0-957.27.2.el7.x86_64.rpm
    perf-3.10.0-957.27.2.el7.x86_64.rpm
    perf-debuginfo-3.10.0-957.27.2.el7.x86_64.rpm
    python-perf-3.10.0-957.27.2.el7.x86_64.rpm
    python-perf-debuginfo-3.10.0-957.27.2.el7.x86_64.rpm
    kernel-tools-libs-devel-3.10.0-957.27.2.el7.x86_64.rpm
  noarch
    kernel-abi-whitelists-3.10.0-957.27.2.el7.noarch.rpm
    kernel-doc-3.10.0-957.27.2.el7.noarch.rpm

- Scientific Linux Development Team

SciLinux: SLSA-2019-1873-1 Important: kernel on SL7.x x86_64

kernel: nfs: use-after-free in svc_process_common() (CVE-2018-16884) * kernel: insufficient input validation in kernel mode driver in Intel i915 graphics leads to privilege escalat...

Summary

Important: kernel security, bug fix, and enhancement update



Security Fixes

* kernel: nfs: use-after-free in svc_process_common() (CVE-2018-16884)
* kernel: insufficient input validation in kernel mode driver in Intel i915 graphics leads to privilege escalation (CVE-2019-11085)
* kernel: nfs: NULL pointer dereference due to an anomalized NFS message sequence (CVE-2018-16871)
* kernel: use-after-free in drivers/char/ipmi/ipmi_si_intf.c, ipmi_si_mem_io.c, ipmi_si_port_io.c (CVE-2019-11811)
SL7 x86_64 bpftool-3.10.0-957.27.2.el7.x86_64.rpm kernel-3.10.0-957.27.2.el7.x86_64.rpm kernel-debug-3.10.0-957.27.2.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-957.27.2.el7.x86_64.rpm kernel-debug-devel-3.10.0-957.27.2.el7.x86_64.rpm kernel-debuginfo-3.10.0-957.27.2.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-957.27.2.el7.x86_64.rpm kernel-devel-3.10.0-957.27.2.el7.x86_64.rpm kernel-headers-3.10.0-957.27.2.el7.x86_64.rpm kernel-tools-3.10.0-957.27.2.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-957.27.2.el7.x86_64.rpm kernel-tools-libs-3.10.0-957.27.2.el7.x86_64.rpm perf-3.10.0-957.27.2.el7.x86_64.rpm perf-debuginfo-3.10.0-957.27.2.el7.x86_64.rpm python-perf-3.10.0-957.27.2.el7.x86_64.rpm python-perf-debuginfo-3.10.0-957.27.2.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-957.27.2.el7.x86_64.rpm noarch kernel-abi-whitelists-3.10.0-957.27.2.el7.noarch.rpm kernel-doc-3.10.0-957.27.2.el7.noarch.rpm
- Scientific Linux Development Team

Severity
Advisory ID: SLSA-2019:1873-1
Issued Date: : 2019-07-29
CVE Numbers: CVE-2018-16871
CVE-2018-16884
CVE-2019-11811

Related News