MGASA-2019-0107

Advisory lineage Upstream: 1 Downstream: 0
Published: 13 Mar 2019, 20:41
Last modified:16 Apr 2026, 04:26

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

13 Mar 2019, 20:41
Published
Vulnerability first disclosed
16 Apr 2026, 04:26
Last Modified
Vulnerability information updated

Description

Updated kernel packages fix security vulnerability This kernel update is based on the upstream 4.14.104 and fixes at least the following security issue: Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes card off-line. This attack appear to be exploitable via An attacker on a must pass a very large, specially crafted packet to the bnx2x card. This can be done from an untrusted guest VM (CVE-2018-1000026). It also fixes signal handling issues causing powertop to crash and some tracing tools to fail on execve tests. For other uptstream fixes in this update, see the referenced changelogs.

Affected Systems

  • mageiakernel

    < 4.14.104-2.mga6

  • mageiakernel-userspace-headers

    < 4.14.104-2.mga6

  • mageiakmod-vboxadditions

    < 5.2.24-8.mga6

  • mageiakmod-virtualbox

    < 5.2.24-8.mga6

  • mageiakmod-xtables-addons

    < 2.13-82.mga6

References (6)