安全公告详情

NS-SA-2019-0014

2019-07-17 14:54:39

简介

important: kernel/systemd security update

严重级别

important

主题

An update for kernel/systemd is now available for NewStart CGSL MAIN 5.04.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

kernel: The python-perf package contains a module that permits applications written in the Python programming language to use the interface to manipulate perf events.
systemd: systemd-journal-gatewayd serves journal events over the network using HTTP.


Security Fix(es):
kernel: A flaw was found in the Linux kernel's key management system where it was possible for an attacker to escalate privileges or crash the machine. If a user key gets negatively instantiated, an error code is cached in the payload area. A negatively instantiated key may be then be positively instantiated by updating it with valid data. However, the ->update key type method must be aware that the error code may be there.(CVE-2015-8539)
kernel: A flaw was found in the way the Linux KVM module processed the trap flag(TF) bit in EFLAGS during emulation of the syscall instruction, which leads to a debug exception(#DB) being raised in the guest stack. A user/process inside a guest could use this flaw to potentially escalate their privileges inside the guest. Linux guests are not affected by this.(CVE-2017-7518)
kernel: A vulnerability was found in the Key Management sub component of the Linux kernel, where when trying to issue a KEYTCL_READ on a negative key would lead to a NULL pointer dereference. A local attacker could use this flaw to crash the kernel.(CVE-2017-12192)
kernel: The Linux kernel built with the KVM visualization support (CONFIG_KVM), with nested visualization(nVMX) feature enabled (nested=1), was vulnerable to a stack buffer overflow issue. The vulnerability could occur while traversing guest page table entries to resolve guest virtual address(gva). An L1 guest could use this flaw to crash the host kernel resulting in denial of service (DoS) or potentially execute arbitrary code on the host to gain privileges on the system.(CVE-2017-12188)
kernel: A flaw was found in the Linux kernel's implementation of associative arrays introduced in 3.13. This functionality was backported to the 3.10 kernels in Red Hat Enterprise Linux 7. The flaw involved a null pointer dereference in assoc_array_apply_edit() due to incorrect node-splitting in assoc_array implementation. This affects the keyring key type and thus key addition and link creation operations may cause the kernel to panic.(CVE-2017-12193)
kernel: It was found that fanout_add() in 'net/packet/af_packet.c' in the Linux kernel, before version 4.13.6, allows local users to gain privileges via crafted system calls that trigger mishandling of packet_fanout data structures, because of a race condition (involving fanout_add and packet_do_bind) that leads to a use-after-free bug.(CVE-2017-15649)
kernel: A vulnerability was found in the Linux kernel where the keyctl_set_reqkey_keyring() function leaks the thread keyring. This allows an unprivileged local user to exhaust kernel memory and thus cause a DoS.(CVE-2017-7472)
kernel: bugfix
systemd: A race condition was found in systemd. This could result in automount requests not being serviced and processes using them could hang, causing denial of service.(CVE-2018-1049)
systemd: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 5.04.F3.

影响组件

  • kernel
  • systemd

影响产品

  • CGSL MAIN 5.04

更新包

{"fix":[{"product":"CGSL MAIN 5.04","pkgs":[{"binary":["kernel-3.10.0-693.21.1.el7.cgslv5u4.0.38.g13ce111.x86_64.rpm","kernel-abi-whitelists-3.10.0-693.21.1.el7.cgslv5u4.0.38.g13ce111.noarch.rpm","kernel-debug-3.10.0-693.21.1.el7.cgslv5u4.0.38.g13ce111.x86_64.rpm","kernel-debug-debuginfo-3.10.0-693.21.1.el7.cgslv5u4.0.38.g13ce111.x86_64.rpm","kernel-debug-devel-3.10.0-693.21.1.el7.cgslv5u4.0.38.g13ce111.x86_64.rpm","kernel-debuginfo-3.10.0-693.21.1.el7.cgslv5u4.0.38.g13ce111.x86_64.rpm","kernel-debuginfo-common-x86_64-3.10.0-693.21.1.el7.cgslv5u4.0.38.g13ce111.x86_64.rpm","kernel-devel-3.10.0-693.21.1.el7.cgslv5u4.0.38.g13ce111.x86_64.rpm","kernel-doc-3.10.0-693.21.1.el7.cgslv5u4.0.38.g13ce111.noarch.rpm","kernel-headers-3.10.0-693.21.1.el7.cgslv5u4.0.38.g13ce111.x86_64.rpm","kernel-tools-3.10.0-693.21.1.el7.cgslv5u4.0.38.g13ce111.x86_64.rpm","kernel-tools-debuginfo-3.10.0-693.21.1.el7.cgslv5u4.0.38.g13ce111.x86_64.rpm","kernel-tools-libs-3.10.0-693.21.1.el7.cgslv5u4.0.38.g13ce111.x86_64.rpm","kernel-tools-libs-devel-3.10.0-693.21.1.el7.cgslv5u4.0.38.g13ce111.x86_64.rpm","perf-3.10.0-693.21.1.el7.cgslv5u4.0.38.g13ce111.x86_64.rpm","perf-debuginfo-3.10.0-693.21.1.el7.cgslv5u4.0.38.g13ce111.x86_64.rpm","python-perf-3.10.0-693.21.1.el7.cgslv5u4.0.38.g13ce111.x86_64.rpm","python-perf-debuginfo-3.10.0-693.21.1.el7.cgslv5u4.0.38.g13ce111.x86_64.rpm"],"source":"kernel-3.10.0-693.21.1.el7.cgslv5u4.0.38.g13ce111.src.rpm"},{"binary":["libgudev1-219-42.el7_4.10.cgslv5.0.9.gc9b7989.x86_64.rpm","libgudev1-devel-219-42.el7_4.10.cgslv5.0.9.gc9b7989.x86_64.rpm","systemd-219-42.el7_4.10.cgslv5.0.9.gc9b7989.x86_64.rpm","systemd-debuginfo-219-42.el7_4.10.cgslv5.0.9.gc9b7989.x86_64.rpm","systemd-devel-219-42.el7_4.10.cgslv5.0.9.gc9b7989.x86_64.rpm","systemd-journal-gateway-219-42.el7_4.10.cgslv5.0.9.gc9b7989.x86_64.rpm","systemd-libs-219-42.el7_4.10.cgslv5.0.9.gc9b7989.x86_64.rpm","systemd-networkd-219-42.el7_4.10.cgslv5.0.9.gc9b7989.x86_64.rpm","systemd-python-219-42.el7_4.10.cgslv5.0.9.gc9b7989.x86_64.rpm","systemd-resolved-219-42.el7_4.10.cgslv5.0.9.gc9b7989.x86_64.rpm","systemd-sysv-219-42.el7_4.10.cgslv5.0.9.gc9b7989.x86_64.rpm"],"source":"systemd-219-42.el7_4.10.cgslv5.0.9.gc9b7989.src.rpm"}]}]}

CVE

参考