Rewterz

Rewterz Threat Alert – Malspam Campaigns leading to Emotet and Bot Communications

April 24, 2019
Rewterz

Rewterz Threat Advisory – Google Chrome Multiple Vulnerabilities

April 25, 2019

Rewterz Threat Advisory – Oracle Linux update for kernel Denial of Service Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2019-6974
In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.

CVE-2019-7221
The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free.

Impact

  • Denial of Service
  • Privilege escalation

Affected Vendors

Oracle

Affected Products

Oracle Linux 7

Remediation

Apply updated packages via the yum or rpm utility

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.