Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2018:0676 - Security Advisory
Issued:
2018-04-10
Updated:
2018-04-10

RHSA-2018:0676 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: kernel-rt security, bug fix, and enhancement update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for kernel-rt is now available for Red Hat Enterprise Linux 7.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.

Security Fix(es):

  • kernel: Buffer overflow in firewire driver via crafted incoming packets (CVE-2016-8633, Important)
  • kernel: Use-after-free vulnerability in DCCP socket (CVE-2017-8824, Important)
  • Kernel: kvm: nVMX: L2 guest could access hardware(L0) CR8 register (CVE-2017-12154, Important)
  • kernel: v4l2: disabled memory access protection mechanism allowing privilege escalation (CVE-2017-13166, Important)
  • kernel: media: use-after-free in [tuner-xc2028] media driver (CVE-2016-7913, Moderate)
  • kernel: drm/vmwgfx: fix integer overflow in vmw_surface_define_ioctl() (CVE-2017-7294, Moderate)
  • kernel: Incorrect type conversion for size during dma allocation (CVE-2017-9725, Moderate)
  • kernel: memory leak when merging buffers in SCSI IO vectors (CVE-2017-12190, Moderate)
  • kernel: vfs: BUG in truncate_inode_pages_range() and fuse client (CVE-2017-15121, Moderate)
  • kernel: Use-after-free in userfaultfd_event_wait_completion function in userfaultfd.c (CVE-2017-15126, Moderate)
  • kernel: net: double-free and memory corruption in get_net_ns_by_id() (CVE-2017-15129, Moderate)
  • kernel: Use-after-free in snd_seq_ioctl_create_port() (CVE-2017-15265, Moderate)
  • kernel: Incorrect handling in arch/x86/include/asm/mmu_context.h:init_new_context function allowing use-after-free (CVE-2017-17053, Moderate)
  • kernel: Missing capabilities check in net/netfilter/nfnetlink_cthelper.c allows for unprivileged access to systemwide nfnl_cthelper_list structure (CVE-2017-17448, Moderate)
  • kernel: Missing namespace check in net/netlink/af_netlink.c allows for network monitors to observe systemwide activity (CVE-2017-17449, Moderate)
  • kernel: Unallocated memory access by malicious USB device via bNumInterfaces overflow (CVE-2017-17558, Moderate)
  • kernel: netfilter: use-after-free in tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c (CVE-2017-18017, Moderate)
  • kernel: Race condition in drivers/md/dm.c:dm_get_from_kobject() allows local users to cause a denial of service (CVE-2017-18203, Moderate)
  • kernel: kvm: Reachable BUG() on out-of-bounds guest IRQ (CVE-2017-1000252, Moderate)
  • Kernel: KVM: DoS via write flood to I/O port 0x80 (CVE-2017-1000407, Moderate)
  • kernel: Stack information leak in the EFS element (CVE-2017-1000410, Moderate)
  • kernel: Kernel address information leak in drivers/acpi/sbshc.c:acpi_smbus_hc_add() function potentially allowing KASLR bypass (CVE-2018-5750, Moderate)
  • kernel: Race condition in sound system can lead to denial of service (CVE-2018-1000004, Moderate)
  • kernel: unlimiting the stack disables ASLR (CVE-2016-3672, Low)
  • kernel: Missing permission check in move_pages system call (CVE-2017-14140, Low)
  • kernel: Null pointer dereference in rngapi_reset function (CVE-2017-15116, Low)
  • kernel: Improper error handling of VM_SHARED hugetlbfs mapping in mm/hugetlb.c (CVE-2017-15127, Low)
  • kernel: Integer overflow in futex.c:futux_requeue can lead to denial of service or unspecified impact (CVE-2018-6927, Low)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Red Hat would like to thank Eyal Itkin for reporting CVE-2016-8633; Mohamed Ghannam for reporting CVE-2017-8824; Jim Mattson (Google.com) for reporting CVE-2017-12154; Vitaly Mayatskih for reporting CVE-2017-12190; Andrea Arcangeli (Engineering) for reporting CVE-2017-15126; Kirill Tkhai for reporting CVE-2017-15129; Jan H. Schönherr (Amazon) for reporting CVE-2017-1000252; and Armis Labs for reporting CVE-2017-1000410. The CVE-2017-15121 issue was discovered by Miklos Szeredi (Red Hat) and the CVE-2017-15116 issue was discovered by ChunYu Wang (Red Hat).

Additional Changes:

See the Red Hat Enterprise Linux 7.5 Release Notes linked from References.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

The system must be rebooted for this update to take effect.

Affected Products

  • Red Hat Enterprise Linux for Real Time 7 x86_64
  • Red Hat Enterprise Linux for Real Time for NFV 7 x86_64
  • Red Hat Enterprise Linux for Real Time for x86_64 - Extended Life Cycle Support 7 x86_64

Fixes

  • BZ - 1292927 - rcuc starvation leads to rcu stall
  • BZ - 1324749 - CVE-2016-3672 kernel: unlimiting the stack disables ASLR
  • BZ - 1391490 - CVE-2016-8633 kernel: Buffer overflow in firewire driver via crafted incoming packets
  • BZ - 1401061 - RFE: Improve RT throttling mechanism
  • BZ - 1402885 - CVE-2016-7913 kernel: media: use-after-free in [tuner-xc2028] media driver
  • BZ - 1430418 - Backport "net/Qdisc: use a seqlock instead seqcount" upstream RT patch
  • BZ - 1436798 - CVE-2017-7294 kernel: drm/vmwgfx: fix integer overflow in vmw_surface_define_ioctl()
  • BZ - 1448770 - INFO: task xfsaild/dm-2:1175 blocked for more than 600 seconds
  • BZ - 1452589 - Review our frequency scaling setup/tuning
  • BZ - 1462329 - RT: update source tree to match RHEL 7.5 tree
  • BZ - 1488329 - CVE-2017-14140 kernel: Missing permission check in move_pages system call
  • BZ - 1489088 - CVE-2017-9725 kernel: Incorrect type conversion for size during dma allocation
  • BZ - 1490781 - CVE-2017-1000252 kernel: kvm: Reachable BUG() on out-of-bounds guest IRQ
  • BZ - 1491224 - CVE-2017-12154 Kernel: kvm: nVMX: L2 guest could access hardware(L0) CR8 register
  • BZ - 1495089 - CVE-2017-12190 kernel: memory leak when merging buffers in SCSI IO vectors
  • BZ - 1500894 - sched/rt: Simplify the IPI rt balancing logic
  • BZ - 1501878 - CVE-2017-15265 kernel: Use-after-free in snd_seq_ioctl_create_port()
  • BZ - 1503749 - RT + Omnipath panic
  • BZ - 1506255 - mm: print warning when ksmd thread runs with CONFIG_PREEMPT_RT enabled
  • BZ - 1507270 - BUG: scheduling while atomic: irq/41-megasas/562/0x00000002
  • BZ - 1509264 - [RHEL-RT] Possible regression with NOHZ_FULL & rt_mutexes in IRQ (BZ1250649)
  • BZ - 1514609 - CVE-2017-15116 kernel: Null pointer dereference in rngapi_reset function
  • BZ - 1518274 - backport: c4ccd6b1ce locking/rtmutex: Prevent dequeue vs. unlock race
  • BZ - 1518638 - CVE-2017-17053 kernel: Incorrect handling in arch/x86/include/asm/mmu_context.h:init_new_context function allowing use-after-free
  • BZ - 1519160 - CVE-2017-1000410 kernel: Stack information leak in the EFS element
  • BZ - 1519591 - CVE-2017-8824 kernel: Use-after-free vulnerability in DCCP socket
  • BZ - 1520328 - CVE-2017-1000407 Kernel: KVM: DoS via write flood to I/O port 0x80
  • BZ - 1520893 - CVE-2017-15121 kernel: vfs: BUG in truncate_inode_pages_range() and fuse client
  • BZ - 1523481 - CVE-2017-15126 kernel: Use-after-free in userfaultfd_event_wait_completion function in userfaultfd.c
  • BZ - 1525218 - CVE-2017-15127 kernel: Improper error handling of VM_SHARED hugetlbfs mapping in mm/hugetlb.c
  • BZ - 1525474 - CVE-2017-17558 kernel: Unallocated memory access by malicious USB device via bNumInterfaces overflow
  • BZ - 1525762 - CVE-2017-17449 kernel: Missing namespace check in net/netlink/af_netlink.c allows for network monitors to observe systemwide activity
  • BZ - 1525768 - CVE-2017-17448 kernel: Missing capabilities check in net/netfilter/nfnetlink_cthelper.c allows for unprivileged access to systemwide nfnl_cthelper_list structure
  • BZ - 1531135 - CVE-2017-18017 kernel: netfilter: use-after-free in tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c
  • BZ - 1531174 - CVE-2017-15129 kernel: net: double-free and memory corruption in get_net_ns_by_id()
  • BZ - 1535315 - CVE-2018-1000004 kernel: Race condition in sound system can lead to denial of service
  • BZ - 1539706 - CVE-2018-5750 kernel: Kernel address information leak in drivers/acpi/sbshc.c:acpi_smbus_hc_add() function potentially allowing KASLR bypass
  • BZ - 1544612 - CVE-2018-6927 kernel: Integer overflow in futex.c:futux_requeue can lead to denial of service or unspecified impact
  • BZ - 1548412 - CVE-2017-13166 kernel: v4l2: disabled memory access protection mechanism allowing privilege escalation
  • BZ - 1550811 - CVE-2017-18203 kernel: Race condition in drivers/md/dm.c:dm_get_from_kobject() allows local users to cause a denial of service

CVEs

  • CVE-2016-3672
  • CVE-2016-7913
  • CVE-2016-8633
  • CVE-2017-7294
  • CVE-2017-8824
  • CVE-2017-9725
  • CVE-2017-12154
  • CVE-2017-12190
  • CVE-2017-13166
  • CVE-2017-13305
  • CVE-2017-14140
  • CVE-2017-15116
  • CVE-2017-15121
  • CVE-2017-15126
  • CVE-2017-15127
  • CVE-2017-15129
  • CVE-2017-15265
  • CVE-2017-15274
  • CVE-2017-17448
  • CVE-2017-17449
  • CVE-2017-17558
  • CVE-2017-18017
  • CVE-2017-18203
  • CVE-2017-1000252
  • CVE-2017-1000407
  • CVE-2017-1000410
  • CVE-2018-5750
  • CVE-2018-6927
  • CVE-2018-1000004

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/7.5_Release_Notes/index.html
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for Real Time 7

SRPM
kernel-rt-3.10.0-862.rt56.804.el7.src.rpm SHA-256: 895133deb67f61e5edd48dea396980fa98334743e1978a87a9948fb382604a71
x86_64
kernel-rt-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: 38a3204da22ce5ca1b3608e332a3590f29920ccc263761c77850f684932d90ca
kernel-rt-debug-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: af0cdd53373fd34fcc496ca19665a0196122067f3e825fdd435a4574bc7c50e0
kernel-rt-debug-debuginfo-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: afe7540f06687eeec5741c25bc328869ca6f5de79c9f205bd3255488d7fff790
kernel-rt-debug-devel-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: acaa8b8c6a1071fc330bb0992b4d7585a18dfaa1b7d22173c8fdf56a1d7350ab
kernel-rt-debuginfo-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: e7398037d11db73a9ce018e7856327b45a25b4fe1b5734f2b04ef420a2bce3d9
kernel-rt-debuginfo-common-x86_64-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: 730139375ede055ce588cc4fd2f4328c5f41a6c47099f317fa77ee25b5f62725
kernel-rt-devel-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: f20bb427fedad16949e61e7d0120a6fa2724b6f889037ed5ae4f40d86793f38e
kernel-rt-doc-3.10.0-862.rt56.804.el7.noarch.rpm SHA-256: 02b8e6e5d65623c489fe66b7501a298ae14012cdb5bd10520075a15ee2cf265a
kernel-rt-trace-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: edf16b5abc36a06beefcf2329cd5d7ad780a2fb860df3b8b998f4d9e57a2c8ac
kernel-rt-trace-debuginfo-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: 0856449781ad09fa250fece48f643a682276cea10e883e2a08207aaab48f4c4f
kernel-rt-trace-devel-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: 7ccf78285ced229d6e0bc22ba61de1f2facf58d0e1bf8c632b1df6b1e48854b9

Red Hat Enterprise Linux for Real Time for NFV 7

SRPM
kernel-rt-3.10.0-862.rt56.804.el7.src.rpm SHA-256: 895133deb67f61e5edd48dea396980fa98334743e1978a87a9948fb382604a71
x86_64
kernel-rt-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: 38a3204da22ce5ca1b3608e332a3590f29920ccc263761c77850f684932d90ca
kernel-rt-debug-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: af0cdd53373fd34fcc496ca19665a0196122067f3e825fdd435a4574bc7c50e0
kernel-rt-debug-debuginfo-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: afe7540f06687eeec5741c25bc328869ca6f5de79c9f205bd3255488d7fff790
kernel-rt-debug-devel-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: acaa8b8c6a1071fc330bb0992b4d7585a18dfaa1b7d22173c8fdf56a1d7350ab
kernel-rt-debug-kvm-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: 7083eeacb2f31bbb0ec78b7c9b400de8709df2d9375b60d516afffd41837e171
kernel-rt-debug-kvm-debuginfo-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: a9aa9db3882c5b0b6f0dcba3bc6913cbcc01b2bbb6740475497265cd3916496d
kernel-rt-debuginfo-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: e7398037d11db73a9ce018e7856327b45a25b4fe1b5734f2b04ef420a2bce3d9
kernel-rt-debuginfo-common-x86_64-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: 730139375ede055ce588cc4fd2f4328c5f41a6c47099f317fa77ee25b5f62725
kernel-rt-devel-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: f20bb427fedad16949e61e7d0120a6fa2724b6f889037ed5ae4f40d86793f38e
kernel-rt-doc-3.10.0-862.rt56.804.el7.noarch.rpm SHA-256: 02b8e6e5d65623c489fe66b7501a298ae14012cdb5bd10520075a15ee2cf265a
kernel-rt-kvm-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: d761f358f79cba3fd8260d2fa2e67494f4605e4765c0c558845c07c197f72924
kernel-rt-kvm-debuginfo-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: 7cc5a274b75872f20d724310461508d24fd389e98d9dc67b62b794d45adb883a
kernel-rt-trace-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: edf16b5abc36a06beefcf2329cd5d7ad780a2fb860df3b8b998f4d9e57a2c8ac
kernel-rt-trace-debuginfo-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: 0856449781ad09fa250fece48f643a682276cea10e883e2a08207aaab48f4c4f
kernel-rt-trace-devel-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: 7ccf78285ced229d6e0bc22ba61de1f2facf58d0e1bf8c632b1df6b1e48854b9
kernel-rt-trace-kvm-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: 07bb50dae380ec44f477d5730cebdca94afc08dc1896e2bc378cbffa7b0a8792
kernel-rt-trace-kvm-debuginfo-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: a3970b9cfe300b499e55acf095046e7992a24d36a50add767ed61c74fba49c6e

Red Hat Enterprise Linux for Real Time for x86_64 - Extended Life Cycle Support 7

SRPM
kernel-rt-3.10.0-862.rt56.804.el7.src.rpm SHA-256: 895133deb67f61e5edd48dea396980fa98334743e1978a87a9948fb382604a71
x86_64
kernel-rt-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: 38a3204da22ce5ca1b3608e332a3590f29920ccc263761c77850f684932d90ca
kernel-rt-debug-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: af0cdd53373fd34fcc496ca19665a0196122067f3e825fdd435a4574bc7c50e0
kernel-rt-debug-debuginfo-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: afe7540f06687eeec5741c25bc328869ca6f5de79c9f205bd3255488d7fff790
kernel-rt-debug-devel-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: acaa8b8c6a1071fc330bb0992b4d7585a18dfaa1b7d22173c8fdf56a1d7350ab
kernel-rt-debuginfo-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: e7398037d11db73a9ce018e7856327b45a25b4fe1b5734f2b04ef420a2bce3d9
kernel-rt-debuginfo-common-x86_64-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: 730139375ede055ce588cc4fd2f4328c5f41a6c47099f317fa77ee25b5f62725
kernel-rt-devel-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: f20bb427fedad16949e61e7d0120a6fa2724b6f889037ed5ae4f40d86793f38e
kernel-rt-doc-3.10.0-862.rt56.804.el7.noarch.rpm SHA-256: 02b8e6e5d65623c489fe66b7501a298ae14012cdb5bd10520075a15ee2cf265a
kernel-rt-trace-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: edf16b5abc36a06beefcf2329cd5d7ad780a2fb860df3b8b998f4d9e57a2c8ac
kernel-rt-trace-debuginfo-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: 0856449781ad09fa250fece48f643a682276cea10e883e2a08207aaab48f4c4f
kernel-rt-trace-devel-3.10.0-862.rt56.804.el7.x86_64.rpm SHA-256: 7ccf78285ced229d6e0bc22ba61de1f2facf58d0e1bf8c632b1df6b1e48854b9

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat X (formerly Twitter)

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility