RHSA-2018:1062
Vulnerability Summary
Timeline
Description
Red Hat Security Advisory: kernel security, bug fix, and enhancement update
CVSS Metrics
- v3.0•HIGH•Score: 7.8CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Systems
- redhat•kernel
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
- redhat•kernel-abi-whitelists
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
- redhat•kernel-bootwrapper
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
- redhat•kernel-debug
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
- redhat•kernel-debug-debuginfo
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
- redhat•kernel-debug-devel
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
- redhat•kernel-debuginfo
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
- redhat•kernel-debuginfo-common-ppc64
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
- redhat•kernel-debuginfo-common-ppc64le
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
- redhat•kernel-debuginfo-common-s390x
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
- redhat•kernel-debuginfo-common-x86_64
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
- redhat•kernel-devel
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
- redhat•kernel-doc
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
- redhat•kernel-headers
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
- redhat•kernel-kdump
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
- redhat•kernel-kdump-debuginfo
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
- redhat•kernel-kdump-devel
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
- redhat•kernel-tools
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
- redhat•kernel-tools-debuginfo
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
- redhat•kernel-tools-libs
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
- redhat•kernel-tools-libs-devel
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
- redhat•perf
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
- redhat•perf-debuginfo
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
- redhat•python-perf
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
- redhat•python-perf-debuginfo
< 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7 | < 0:3.10.0-862.el7
References (165)
- https://access.redhat.com/errata/RHSA-2018:1062
- https://access.redhat.com/security/updates/classification/#important
- https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/7.5_Release_Notes/index.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1132610
- https://bugzilla.redhat.com/show_bug.cgi?id=1324749
- https://bugzilla.redhat.com/show_bug.cgi?id=1334439
- https://bugzilla.redhat.com/show_bug.cgi?id=1372079
- https://bugzilla.redhat.com/show_bug.cgi?id=1391490
- https://bugzilla.redhat.com/show_bug.cgi?id=1402885
- https://bugzilla.redhat.com/show_bug.cgi?id=1436798
- https://bugzilla.redhat.com/show_bug.cgi?id=1450205
- https://bugzilla.redhat.com/show_bug.cgi?id=1458032
- https://bugzilla.redhat.com/show_bug.cgi?id=1460213
- https://bugzilla.redhat.com/show_bug.cgi?id=1461282
- https://bugzilla.redhat.com/show_bug.cgi?id=1471875
- https://bugzilla.redhat.com/show_bug.cgi?id=1487352
- https://bugzilla.redhat.com/show_bug.cgi?id=1488329
- https://bugzilla.redhat.com/show_bug.cgi?id=1489088
- https://bugzilla.redhat.com/show_bug.cgi?id=1489542
- https://bugzilla.redhat.com/show_bug.cgi?id=1490673
- https://bugzilla.redhat.com/show_bug.cgi?id=1490781
- https://bugzilla.redhat.com/show_bug.cgi?id=1491224
- https://bugzilla.redhat.com/show_bug.cgi?id=1493125
- https://bugzilla.redhat.com/show_bug.cgi?id=1495089
- https://bugzilla.redhat.com/show_bug.cgi?id=1496836
- https://bugzilla.redhat.com/show_bug.cgi?id=1501878
- https://bugzilla.redhat.com/show_bug.cgi?id=1502601
- https://bugzilla.redhat.com/show_bug.cgi?id=1506382
- https://bugzilla.redhat.com/show_bug.cgi?id=1507025
- https://bugzilla.redhat.com/show_bug.cgi?id=1507026
- https://bugzilla.redhat.com/show_bug.cgi?id=1514609
- https://bugzilla.redhat.com/show_bug.cgi?id=1519160
- https://bugzilla.redhat.com/show_bug.cgi?id=1519591
- https://bugzilla.redhat.com/show_bug.cgi?id=1519781
- https://bugzilla.redhat.com/show_bug.cgi?id=1520328
- https://bugzilla.redhat.com/show_bug.cgi?id=1520893
- https://bugzilla.redhat.com/show_bug.cgi?id=1523481
- https://bugzilla.redhat.com/show_bug.cgi?id=1525218
- https://bugzilla.redhat.com/show_bug.cgi?id=1525474
- https://bugzilla.redhat.com/show_bug.cgi?id=1525762
- https://bugzilla.redhat.com/show_bug.cgi?id=1525768
- https://bugzilla.redhat.com/show_bug.cgi?id=1531135
- https://bugzilla.redhat.com/show_bug.cgi?id=1531174
- https://bugzilla.redhat.com/show_bug.cgi?id=1531680
- https://bugzilla.redhat.com/show_bug.cgi?id=1534272
- https://bugzilla.redhat.com/show_bug.cgi?id=1535315
- https://bugzilla.redhat.com/show_bug.cgi?id=1539706
- https://bugzilla.redhat.com/show_bug.cgi?id=1542013
- https://bugzilla.redhat.com/show_bug.cgi?id=1544612
- https://bugzilla.redhat.com/show_bug.cgi?id=1548412
- https://bugzilla.redhat.com/show_bug.cgi?id=1550811
- https://security.access.redhat.com/data/csaf/v2/advisories/2018/rhsa-2018_1062.json
- https://access.redhat.com/security/cve/CVE-2016-3672
- https://www.cve.org/CVERecord?id=CVE-2016-3672
- https://nvd.nist.gov/vuln/detail/CVE-2016-3672
- http://hmarco.org/bugs/CVE-2016-3672-Unlimiting-the-stack-not-longer-disables-ASLR.html
- http://seclists.org/bugtraq/2016/Apr/34
- https://access.redhat.com/security/cve/CVE-2016-7913
- https://www.cve.org/CVERecord?id=CVE-2016-7913
- https://nvd.nist.gov/vuln/detail/CVE-2016-7913
- https://access.redhat.com/security/cve/CVE-2016-8633
- https://www.cve.org/CVERecord?id=CVE-2016-8633
- https://nvd.nist.gov/vuln/detail/CVE-2016-8633
- https://access.redhat.com/security/cve/CVE-2017-5715
- https://bugzilla.redhat.com/show_bug.cgi?id=1519780
- https://access.redhat.com/security/vulnerabilities/speculativeexecution
- https://www.cve.org/CVERecord?id=CVE-2017-5715
- https://nvd.nist.gov/vuln/detail/CVE-2017-5715
- https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html
- https://meltdownattack.com
- https://spectreattack.com/
- https://access.redhat.com/security/cve/CVE-2017-5754
- https://www.cve.org/CVERecord?id=CVE-2017-5754
- https://nvd.nist.gov/vuln/detail/CVE-2017-5754
- https://access.redhat.com/security/cve/CVE-2017-7294
- https://www.cve.org/CVERecord?id=CVE-2017-7294
- https://nvd.nist.gov/vuln/detail/CVE-2017-7294
- https://access.redhat.com/security/cve/CVE-2017-8824
- https://www.cve.org/CVERecord?id=CVE-2017-8824
- https://nvd.nist.gov/vuln/detail/CVE-2017-8824
- https://access.redhat.com/security/cve/CVE-2017-9725
- https://www.cve.org/CVERecord?id=CVE-2017-9725
- https://nvd.nist.gov/vuln/detail/CVE-2017-9725
- https://source.android.com/security/bulletin/2017-09-01
- https://access.redhat.com/security/cve/CVE-2017-12154
- https://www.cve.org/CVERecord?id=CVE-2017-12154
- https://nvd.nist.gov/vuln/detail/CVE-2017-12154
- https://access.redhat.com/security/cve/CVE-2017-12190
- https://www.cve.org/CVERecord?id=CVE-2017-12190
- https://nvd.nist.gov/vuln/detail/CVE-2017-12190
- https://access.redhat.com/security/cve/CVE-2017-13166
- https://www.cve.org/CVERecord?id=CVE-2017-13166
- https://nvd.nist.gov/vuln/detail/CVE-2017-13166
- https://access.redhat.com/security/cve/CVE-2017-13305
- https://bugzilla.redhat.com/show_bug.cgi?id=1581637
- https://www.cve.org/CVERecord?id=CVE-2017-13305
- https://nvd.nist.gov/vuln/detail/CVE-2017-13305
- https://access.redhat.com/security/cve/CVE-2017-14140
- https://www.cve.org/CVERecord?id=CVE-2017-14140
- https://nvd.nist.gov/vuln/detail/CVE-2017-14140
- https://access.redhat.com/security/cve/CVE-2017-15116
- https://www.cve.org/CVERecord?id=CVE-2017-15116
- https://nvd.nist.gov/vuln/detail/CVE-2017-15116
- https://access.redhat.com/security/cve/CVE-2017-15121
- https://www.cve.org/CVERecord?id=CVE-2017-15121
- https://nvd.nist.gov/vuln/detail/CVE-2017-15121
- https://access.redhat.com/security/cve/CVE-2017-15126
- https://www.cve.org/CVERecord?id=CVE-2017-15126
- https://nvd.nist.gov/vuln/detail/CVE-2017-15126
- https://access.redhat.com/security/cve/CVE-2017-15127
- https://www.cve.org/CVERecord?id=CVE-2017-15127
- https://nvd.nist.gov/vuln/detail/CVE-2017-15127
- https://access.redhat.com/security/cve/CVE-2017-15129
- https://www.cve.org/CVERecord?id=CVE-2017-15129
- https://nvd.nist.gov/vuln/detail/CVE-2017-15129
- https://access.redhat.com/security/cve/CVE-2017-15265
- https://www.cve.org/CVERecord?id=CVE-2017-15265
- https://nvd.nist.gov/vuln/detail/CVE-2017-15265
- https://access.redhat.com/security/cve/CVE-2017-15274
- https://bugzilla.redhat.com/show_bug.cgi?id=1500391
- https://www.cve.org/CVERecord?id=CVE-2017-15274
- https://nvd.nist.gov/vuln/detail/CVE-2017-15274
- https://access.redhat.com/security/cve/CVE-2017-17448
- https://www.cve.org/CVERecord?id=CVE-2017-17448
- https://nvd.nist.gov/vuln/detail/CVE-2017-17448
- https://access.redhat.com/security/cve/CVE-2017-17449
- https://www.cve.org/CVERecord?id=CVE-2017-17449
- https://nvd.nist.gov/vuln/detail/CVE-2017-17449
- https://access.redhat.com/security/cve/CVE-2017-17558
- https://www.cve.org/CVERecord?id=CVE-2017-17558
- https://nvd.nist.gov/vuln/detail/CVE-2017-17558
- https://access.redhat.com/security/cve/CVE-2017-18017
- https://www.cve.org/CVERecord?id=CVE-2017-18017
- https://nvd.nist.gov/vuln/detail/CVE-2017-18017
- https://access.redhat.com/security/cve/CVE-2017-18203
- https://www.cve.org/CVERecord?id=CVE-2017-18203
- https://nvd.nist.gov/vuln/detail/CVE-2017-18203
- https://access.redhat.com/security/cve/CVE-2017-18270
- https://bugzilla.redhat.com/show_bug.cgi?id=1580979
- https://www.cve.org/CVERecord?id=CVE-2017-18270
- https://nvd.nist.gov/vuln/detail/CVE-2017-18270
- http://kernsec.org/pipermail/linux-security-module-archive/2017-September/003318.html
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=237bbd29f7a049d310d907f4b2716a7feef9abf3
- https://access.redhat.com/security/cve/CVE-2017-1000252
- https://www.cve.org/CVERecord?id=CVE-2017-1000252
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000252
- https://access.redhat.com/security/cve/CVE-2017-1000407
- https://www.cve.org/CVERecord?id=CVE-2017-1000407
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000407
- https://access.redhat.com/security/cve/CVE-2017-1000410
- https://www.cve.org/CVERecord?id=CVE-2017-1000410
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000410
- https://access.redhat.com/security/cve/CVE-2018-1066
- https://bugzilla.redhat.com/show_bug.cgi?id=1539599
- https://www.cve.org/CVERecord?id=CVE-2018-1066
- https://nvd.nist.gov/vuln/detail/CVE-2018-1066
- https://access.redhat.com/security/cve/CVE-2018-5750
- https://www.cve.org/CVERecord?id=CVE-2018-5750
- https://nvd.nist.gov/vuln/detail/CVE-2018-5750
- https://access.redhat.com/security/cve/CVE-2018-6927
- https://www.cve.org/CVERecord?id=CVE-2018-6927
- https://nvd.nist.gov/vuln/detail/CVE-2018-6927
- https://access.redhat.com/security/cve/CVE-2018-1000004
- https://www.cve.org/CVERecord?id=CVE-2018-1000004
- https://nvd.nist.gov/vuln/detail/CVE-2018-1000004