RHSA-2019:2854-01 -- Redhat kpatch-patchID: oval:org.secpod.oval:def:503348 | Date: (C)2020-11-06 (M)2024-04-17 |
Class: PATCH | Family: unix |
This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. Security Fix: * A buffer overflow flaw was found in the way Linux kernel"s vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host. For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section.
Platform: |
Red Hat Enterprise Linux 7 |