ALAS2-2019-1232


Amazon Linux 2 Security Advisory: ALAS-2019-1232
Advisory Release Date: 2019-07-18 17:16 Pacific
Advisory Updated Date: 2022-09-15 04:46 Pacific
Severity: Important

Issue Overview:

An infinite loop issue was found in the vhost_net kernel module while handling incoming packets in handle_rx(). The infinite loop could occur if one end sends packets faster than the other end can process them. A guest user, maybe a remote one, could use this flaw to stall the vhost_net kernel thread, resulting in a DoS scenario. (CVE-2019-3900)

A flaw was found in the Linux kernel where the coredump implementation does not use locking or other mechanisms to prevent vma layout or vma flags changes while it runs. This allows local users to obtain sensitive information, cause a denial of service (DoS), or possibly have unspecified other impact by triggering a race condition with mmget_not_zero or get_task_mm calls. (CVE-2019-11599)


Affected Packages:

kernel


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update kernel to update your system.

New Packages:
aarch64:
    kernel-4.14.133-113.105.amzn2.aarch64
    kernel-headers-4.14.133-113.105.amzn2.aarch64
    kernel-debuginfo-common-aarch64-4.14.133-113.105.amzn2.aarch64
    perf-4.14.133-113.105.amzn2.aarch64
    perf-debuginfo-4.14.133-113.105.amzn2.aarch64
    python-perf-4.14.133-113.105.amzn2.aarch64
    python-perf-debuginfo-4.14.133-113.105.amzn2.aarch64
    kernel-tools-4.14.133-113.105.amzn2.aarch64
    kernel-tools-devel-4.14.133-113.105.amzn2.aarch64
    kernel-tools-debuginfo-4.14.133-113.105.amzn2.aarch64
    kernel-devel-4.14.133-113.105.amzn2.aarch64
    kernel-debuginfo-4.14.133-113.105.amzn2.aarch64

i686:
    kernel-headers-4.14.133-113.105.amzn2.i686

src:
    kernel-4.14.133-113.105.amzn2.src

x86_64:
    kernel-4.14.133-113.105.amzn2.x86_64
    kernel-headers-4.14.133-113.105.amzn2.x86_64
    kernel-debuginfo-common-x86_64-4.14.133-113.105.amzn2.x86_64
    perf-4.14.133-113.105.amzn2.x86_64
    perf-debuginfo-4.14.133-113.105.amzn2.x86_64
    python-perf-4.14.133-113.105.amzn2.x86_64
    python-perf-debuginfo-4.14.133-113.105.amzn2.x86_64
    kernel-tools-4.14.133-113.105.amzn2.x86_64
    kernel-tools-devel-4.14.133-113.105.amzn2.x86_64
    kernel-tools-debuginfo-4.14.133-113.105.amzn2.x86_64
    kernel-devel-4.14.133-113.105.amzn2.x86_64
    kernel-debuginfo-4.14.133-113.105.amzn2.x86_64