RHSA-2020:4060 Important: kernel security, bug fix, and enhancement update
The kernel packages contain the Linux kernel, the core of any Linux operating system.
Initial Security Fixes are described in RHSA-2020:4060.
This update also fixes these remaining security issues:
Security Fix(es):
-
kernel: use-after-free in drivers/bluetooth/hci_ldisc.c (CVE-2019-15917)
-
kernel: unprivileged users able to create RAW sockets in AF_IEEE802154 network protocol (CVE-2019-17053)
-
kernel: unprivileged users able to create RAW sockets in AF_ISDN network protocol (CVE-2019-17055)
-
kernel: memory leak in ccp_run_sha_cmd() function in drivers/crypto/ccp/ccp-ops.c (CVE-2019-18808)
-
kernel: Denial Of Service in the __ipmi_bmc_register() function in drivers/char/ipmi/ipmi_msghandler.c (CVE-2019-19046)
-
kernel: memory leak in the nl80211_get_ftm_responder_stats() function in net/wireless/nl80211.c allows DoS (CVE-2019-19055)
-
Kernel: kvm: OOB memory write via kvm_dev_ioctl_get_cpuid (CVE-2019-19332)
-
kernel: mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use-after-free in ext4_put_super in fs/ext4/super.c (CVE-2019-19447)
-
kernel: use-after-free caused by a malicious USB device in the drivers/usb/misc/adutux.c driver (CVE-2019-19523)
-
kernel: a malicious USB device in the drivers/input/ff-memless.c leads to use-after-free (CVE-2019-19524)
-
kernel: use-after-free caused by a malicious USB device in the drivers/usb/class/cdc-acm.c driver (CVE-2019-19530)
-
kernel: information leak bug caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c driver (CVE-2019-19534)
-
kernel: race condition caused by a malicious USB device in the USB character device driver layer (CVE-2019-19537)
-
kernel: use-after-free in __ext4_expand_extra_isize and ext4_xattr_set_entry related to fs/ext4/inode.c and fs/ext4/super.c (CVE-2019-19767)
-
kernel: out-of-bounds write via crafted keycode table (CVE-2019-20636)
-
kernel: some ipv6 protocols not encrypted over ipsec tunnel (CVE-2020-1749)
-
Kernel: kvm: nVMX: L2 guest may trick the L0 hypervisor to access sensitive L1 resources (CVE-2020-2732)
-
kernel: out-of-bounds read in in vc_do_resize function in drivers/tty/vt/vt.c (CVE-2020-8647)
-
kernel: invalid read location in vgacon_invert_region function in drivers/video/console/vgacon.c (CVE-2020-8649)
-
kernel: out-of-bounds read in set_fdc in drivers/block/floppy.c (CVE-2020-9383)
-
kernel: uninitialized kernel data leak in userspace coredumps (CVE-2020-10732)
-
kernel: NFS client crash due to index buffer overflow during Direct IO write causing kernel panic (CVE-2020-10742)
-
kernel: SELinux netlink permission check bypass (CVE-2020-10751)
-
kernel: out-of-bounds write in mpol_parse_str function in mm/mempolicy.c (CVE-2020-11565)
-
kernel: sg_write function lacks an sg_remove_request call in a certain failure case (CVE-2020-12770)
-
kernel: possible to send arbitrary signals to a privileged (suidroot) parent process (CVE-2020-12826)
-
kernel: memory corruption in Voice over IP nf_conntrack_h323 module (CVE-2020-14305)
-
kernel: null pointer dereference in dlpar_parse_cc_property in arch/powerrc/platforms/pseries/dlpar.c causing denial of service (CVE-2019-12614)
-
kernel: null pointer dereference in drivers/media/usb/zr364xx/zr364xx.c driver (CVE-2019-15217)
-
kernel: Memory leak in drivers/scsi/libsas/sas_expander.c (CVE-2019-15807)
-
kernel: null-pointer dereference in drivers/net/fjes/fjes_main.c (CVE-2019-16231)
-
kernel: null pointer dereference in drivers/scsi/qla2xxx/qla_os.c (CVE-2019-16233)
-
kernel: Memory leak in sit_init_net() in net/ipv6/sit.c (CVE-2019-16994)
-
kernel: A memory leak in the alloc_sgtable() function in drivers/net/wireless/intel/iwlwifi/fw/dbg.c allows for a DoS (CVE-2019-19058)
-
kernel: Multiple memory leaks in the iwl_pcie_ctxt_info_gen3_init() function in drivers/net/wireless/intel/iwlwifi/pcie/ctxt-info-gen3.c allows for a DoS (CVE-2019-19059)
-
kernel: memory leak in the crypto_report() function in crypto/crypto_user_base.c allows for DoS (CVE-2019-19062)
-
kernel: Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c allow for a DoS (CVE-2019-19063)
-
kernel: Null pointer dereference in drop_sysctl_table() in fs/proc/proc_sysctl.c (CVE-2019-20054)
-
kernel: memory leak in mwifiex_tm_cmd in drivers/net/wireless/marvell/mwifiex/cfg80211.c (CVE-2019-20095)
-
kernel: use-after-free in cdev_put() when a PTP device is removed while it's chardev is open (CVE-2020-10690)
-
kernel: vhost-net: stack overflow in get_raw_socket while checking sk_family field (CVE-2020-10942)