- Kernel Update Version:
- Release Date:
- 2019-03-20 10:08:02
Kernel crash (BUG_ON) ploop_relocblks_ioc().
/proc/sys/net/core/somaxconn was not available in the containers.
userfaultfd bypasses tmpfs file permissions.A flaw was found in the implementation of userfaultfd. An attacker is able to bypass file permissions on filesystems mounted with tmpfs/hugetlbs to modify a file and possibly disrupt normal system behaviour. At this time there is an understanding there is no crash or priviledge escalation but the impact of modifications on these filesystems of files in production systems may have adverse affects.https://bugzilla.redhat.com/show_bug.cgi?id=1641548
ipvs: an unneeded debug message is output when a network namespace is initialized.Debug message 'IPVS: Creating netns size=... id=...' could be output many times to the system log when the network namespaces are initialized, making the log less readable.
'perf record -a' causes segfaults in applications executing vsyscalls.
Some operations with ebtables could consume large amounts of memory, resulting in DoS.A flaw was found in the implementation of ebtables in the Linux kernel. A local attacker in a container could exploit it to consume large amounts of memory, eventually causing denial of service on the host.
Kernel crash (access out of bounds) in SyS_mincore().
(enhancement) FUSE: backported immediate-write support for the fast path.