To apply patches do the following:
Systems with AUTO_UPDATE=True (DEFAULT) in /etc/sysconfig/kcare/kcare.conf will automatically update, and no action is needed for them.
You can manually update the server by running:
# /usr/bin/kcarectl --update
CHANGELOG:
ubuntu-trusty:
CVE-2018-1068: A flaw was found in the Linux 4.x kernel's implementation of 32-bit
syscall interface for bridging. This allowed a privileged user to arbitrarily
write to a limited range of kernel memory.
CVE-2018-7492: A NULL pointer dereference was found in the net/rds/rdma.c __rds_rdma_map()
function in the Linux kernel before 4.14.7 allowing local attackers to cause a
system panic and a denial-of-service, related to RDS_GET_MR and RDS_GET_MR_FOR_DEST.
CVE-2018-8781: The udl_fb_mmap function in drivers/gpu/drm/udl/udl_fb.c at the Linux
kernel version 3.4 and up to and including 4.15 has an integer-overflow vulnerability
allowing local users with access to the udldrmfb driver to obtain full read and
write permissions on kernel physical pages, resulting in a code execution in kernel
space.
cvelist: [CVE-2018-1068, CVE-2018-7492, CVE-2018-8781]
latest-version: 3.13.0-153.203
--
-- Regards,
Irina Semenova | Project Coordinator of KernelCare
Skype: iras535