Oval Definition:oval:com.redhat.rhsa:def:20162584
Revision Date:2016-11-03Version:639
Title:RHSA-2016:2584: kernel-rt security, bug fix, and enhancement update (Important)
Description:The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.

Security Fix(es):

  • It was found that the Linux kernel's IPv6 implementation mishandled socket options. A local attacker could abuse concurrent access to the socket options to escalate their privileges, or cause a denial of service (use-after-free and system crash) via a crafted sendmsg system call. (CVE-2016-3841, Important)

  • Several Moderate and Low impact security issues were found in the Linux kernel. Space precludes documenting each of these issues in this advisory. Refer to the CVE links in the References section for a description of each of these vulnerabilities. (CVE-2013-4312, CVE-2015-8374, CVE-2015-8543, CVE-2015-8812, CVE-2015-8844, CVE-2015-8845, CVE-2016-2053, CVE-2016-2069, CVE-2016-2847, CVE-2016-3156, CVE-2016-4581, CVE-2016-4794, CVE-2016-5829, CVE-2016-6136, CVE-2016-6198, CVE-2016-6327, CVE-2016-6480, CVE-2015-8746, CVE-2015-8956, CVE-2016-2117, CVE-2016-2384, CVE-2016-3070, CVE-2016-3699, CVE-2016-4569, CVE-2016-4578)

    Red Hat would like to thank Philip Pettersson (Samsung) for reporting CVE-2016-2053; Tetsuo Handa for reporting CVE-2016-2847; the Virtuozzo kernel team and Solar Designer (Openwall) for reporting CVE-2016-3156; Justin Yackoski (Cryptonite) for reporting CVE-2016-2117; and Linn Crosetto (HP) for reporting CVE-2016-3699. The CVE-2015-8812 issue was discovered by Venkatesh Pottem (Red Hat Engineering); the CVE-2015-8844 and CVE-2015-8845 issues were discovered by Miroslav Vadkerti (Red Hat Engineering); the CVE-2016-4581 issue was discovered by Eric W. Biederman (Red Hat); the CVE-2016-6198 issue was discovered by CAI Qian (Red Hat); and the CVE-2016-3070 issue was discovered by Jan Stancek (Red Hat).

    Additional Changes:

    For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.3 Release Notes linked from the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2013-4312
    CVE-2015-8374
    CVE-2015-8543
    CVE-2015-8746
    CVE-2015-8812
    CVE-2015-8844
    CVE-2015-8845
    CVE-2015-8956
    CVE-2016-2053
    CVE-2016-2069
    CVE-2016-2117
    CVE-2016-2384
    CVE-2016-2847
    CVE-2016-3070
    CVE-2016-3156
    CVE-2016-3699
    CVE-2016-3841
    CVE-2016-4569
    CVE-2016-4578
    CVE-2016-4581
    CVE-2016-4794
    CVE-2016-5829
    CVE-2016-6136
    CVE-2016-6198
    CVE-2016-6327
    CVE-2016-6480
    CVE-2017-13167
    RHSA-2016:2584
    RHSA-2016:2584-01
    RHSA-2016:2584-02
    RHSA-2016:2584-02
    Platform(s):Red Hat Enterprise Linux 7
    Red Hat Enterprise Linux 7 (please do not use for >= RHEL-7.5)
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • kernel-rt earlier than 0:3.10.0-514.rt56.420.el7 is currently running
  • OR kernel-rt earlier than 0:3.10.0-514.rt56.420.el7 is set to boot up on next boot
  • AND
  • kernel-rt is earlier than 0:3.10.0-514.rt56.420.el7
  • AND kernel-rt is signed with Red Hat redhatrelease2 key
  • kernel-rt-debug is earlier than 0:3.10.0-514.rt56.420.el7
  • AND kernel-rt-debug is signed with Red Hat redhatrelease2 key
  • kernel-rt-debug-devel is earlier than 0:3.10.0-514.rt56.420.el7
  • AND kernel-rt-debug-devel is signed with Red Hat redhatrelease2 key
  • kernel-rt-debug-kvm is earlier than 0:3.10.0-514.rt56.420.el7
  • AND kernel-rt-debug-kvm is signed with Red Hat redhatrelease2 key
  • kernel-rt-devel is earlier than 0:3.10.0-514.rt56.420.el7
  • AND kernel-rt-devel is signed with Red Hat redhatrelease2 key
  • kernel-rt-doc is earlier than 0:3.10.0-514.rt56.420.el7
  • AND kernel-rt-doc is signed with Red Hat redhatrelease2 key
  • kernel-rt-kvm is earlier than 0:3.10.0-514.rt56.420.el7
  • AND kernel-rt-kvm is signed with Red Hat redhatrelease2 key
  • kernel-rt-trace is earlier than 0:3.10.0-514.rt56.420.el7
  • AND kernel-rt-trace is signed with Red Hat redhatrelease2 key
  • kernel-rt-trace-devel is earlier than 0:3.10.0-514.rt56.420.el7
  • AND kernel-rt-trace-devel is signed with Red Hat redhatrelease2 key
  • kernel-rt-trace-kvm is earlier than 0:3.10.0-514.rt56.420.el7
  • AND kernel-rt-trace-kvm is signed with Red Hat redhatrelease2 key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 7 Client is installed
  • OR Red Hat Enterprise Linux 7 Server is installed
  • OR Red Hat Enterprise Linux 7 Workstation is installed
  • OR Red Hat Enterprise Linux 7 ComputeNode is installed
  • AND Package Information
  • kernel-rt-doc is earlier than 0:3.10.0-514.rt56.420.el7
  • AND kernel-rt-doc is signed with Red Hat redhatrelease2 key
  • OR
  • kernel-rt-trace-devel is earlier than 0:3.10.0-514.rt56.420.el7
  • AND kernel-rt-trace-devel is signed with Red Hat redhatrelease2 key
  • OR
  • kernel-rt-devel is earlier than 0:3.10.0-514.rt56.420.el7
  • AND kernel-rt-devel is signed with Red Hat redhatrelease2 key
  • OR
  • kernel-rt-debug-devel is earlier than 0:3.10.0-514.rt56.420.el7
  • AND kernel-rt-debug-devel is signed with Red Hat redhatrelease2 key
  • OR
  • kernel-rt-trace is earlier than 0:3.10.0-514.rt56.420.el7
  • AND kernel-rt-trace is signed with Red Hat redhatrelease2 key
  • OR
  • kernel-rt-debug is earlier than 0:3.10.0-514.rt56.420.el7
  • AND kernel-rt-debug is signed with Red Hat redhatrelease2 key
  • OR
  • kernel-rt is earlier than 0:3.10.0-514.rt56.420.el7
  • AND kernel-rt is signed with Red Hat redhatrelease2 key
  • OR
  • kernel-rt-kvm is earlier than 0:3.10.0-514.rt56.420.el7
  • AND kernel-rt-kvm is signed with Red Hat redhatrelease2 key
  • OR
  • kernel-rt-trace-kvm is earlier than 0:3.10.0-514.rt56.420.el7
  • AND kernel-rt-trace-kvm is signed with Red Hat redhatrelease2 key
  • OR
  • kernel-rt-debug-kvm is earlier than 0:3.10.0-514.rt56.420.el7
  • AND kernel-rt-debug-kvm is signed with Red Hat redhatrelease2 key
  • BACK