RHSA-2020:0609: Important: kernel-rt security and bug fix update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): kernel: use-after-free in fs/xfs/xfssuper.c (CVE-2018-20976) kernel: insufficient input validation in kernel mode driver in Intel i915 graphics leads to privilege escalation (CVE-2019-11085) kernel: heap-based buffer overflow in mwifiexprocesscountryie() function in drivers/net/wireless/marvell/mwifiex/staioctl.c (CVE-2019-14895) kernel: buffer overflow in cfg80211mgdwextgiwessid in net/wireless/wext-sme.c (CVE-2019-17133) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): update the MRG 2.5.z 3.10 realtime-kernel sources (BZ#1794133)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:0609?
The severity of RHSA-2020:0609 is considered to be critical due to the potential for exploitation of the vulnerabilities.
How do I fix RHSA-2020:0609?
To fix RHSA-2020:0609, you should update the affected kernel-rt packages to version 3.10.0-693.64.1.rt56.662.el6.
What vulnerabilities are addressed in RHSA-2020:0609?
RHSA-2020:0609 addresses a use-after-free vulnerability in fs/xfs/xfs_super.c and insufficient input validation issues.
Which systems are affected by RHSA-2020:0609?
RHSA-2020:0609 affects systems running the kernel-rt packages version up to 3.10.0-693.64.1.rt56.662.el6.
Is it safe to delay the update for RHSA-2020:0609?
It is not safe to delay the update for RHSA-2020:0609 as it may leave your system vulnerable to attacks.