Korean
<< Back
VID 14245
Severity 40
Port 22
Protocol TCP
Class LSC
Detailed Description The remote system does not apply RHSA-2019:2411 which is kernel security update. The system which does not apply the update is affected by the following vulnerabilities:

- broken permission and object lifetime handling for PTRACE_TRACEME (CVE-2019-13272)

- Spectre SWAPGS gadget vulnerability (CVE-2019-1125)

Note: This check solely relied on the kernel RPM version of the remote system to assess this vulnerability, so this might be a false positive.

* References:
https://access.redhat.com/articles/4329821
https://access.redhat.com/errata/RHSA-2019:2411
https://access.redhat.com/security/cve/cve-2019-1125
https://access.redhat.com/security/cve/cve-2019-13272

* Platforms Affected:
Red Hat Enterprise Linux Server (v. 8)
Recommendation Update the affected packages.
Launch the graphical update tool through
Applications -> System Tools -> Software Update

For a command line interface, use the following command to update the operating system:
# yum update
Related URL CVE-2019-1125,CVE-2019-13272 (CVE)
Related URL (SecurityFocus)
Related URL (ISS)