RHSA-2020:0375: Important: kernel-rt security and bug fix update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): kernel: heap overflow in mwifiexupdatevsie() function of Marvell WiFi driver (CVE-2019-14816) kernel: heap-based buffer overflow in mwifiexprocesscountryie() function in drivers/net/wireless/marvell/mwifiex/staioctl.c (CVE-2019-14895) kernel: heap overflow in marvell/mwifiex/tdls.c (CVE-2019-14901) kernel: buffer overflow in cfg80211mgdwextgiwessid in net/wireless/wext-sme.c (CVE-2019-17133) kernel: incomplete fix for race condition between mmgetnotzero()/gettaskmm() and core dumping in CVE-2019-11599 (CVE-2019-14898) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): patchset for x86/atomic: Fix smpmb{before,after}atomic() [kernel-rt] (BZ#1772522) kernel-rt: update to the RHEL7.7.z batch#4 source tree (BZ#1780322) kvm nxhugepagesrecoveryratio=0 is needed to meet KVM-RT low latency requirement (BZ#1781157) kernel-rt: hard lockup panic in during execution of CFS bandwidth period timer (BZ#1788057)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:0375?
The severity of RHSA-2020:0375 is considered important due to a heap overflow vulnerability in the Marvell WiFi driver.
How do I fix RHSA-2020:0375?
To fix RHSA-2020:0375, update to the recommended kernel-rt version 3.10.0-1062.12.1.rt56.1042.el7.
Which packages are affected by RHSA-2020:0375?
RHSA-2020:0375 affects multiple kernel-rt packages, including kernel-rt, kernel-rt-debug, and kernel-rt-devel.
What is the nature of the vulnerability in RHSA-2020:0375?
The vulnerability in RHSA-2020:0375 involves a heap overflow in the mwifiex_update_vs_ie() function.
Is there a workaround for RHSA-2020:0375?
There is no known workaround for RHSA-2020:0375 other than applying the necessary updates.