Please update CentOS 7 users: Important Linux Kernel patch released
Based on the free release source of Red Hat Enterprise Linux 7, the CentOS 7 branch inherits the latest kernel security update features. Today, the system team released a very important patch, the recent discovery of four vulnerabilities in a timely manner to fix, and recommend users Install patches as soon as possible, upgrade to kernel-3.10.0-514.10.2.el7.
One of the vulnerabilities that this Kernel patch fixes, according to RHSA-2017: 02.16-1 Security Bulletin, is the Linux Kernel KVM (Kernel-based Virtual Machine) Deployment (CVE-2016-8630 ), when undefined commands are simulated, the 32-bit (x86) application crashes, allowing attackers to impact the host kernel.
The second Security Vulnerability (CVE-2016-8655) I is a Linux Kernel network subsystem that allows local attackers to use CAP_NET_RAW to open raw packet socket to obtain root privileges. The third Security Vulnerability (CVE-2016-9083) is a Linux Kernel VFIO deployment that allows attackers to cause memory overflow errors. The last (CVE-2016-9084) is the ability to combine with the third system to attack victims.