RHSA-2020:0664: Important: kernel security, bug fix, and enhancement update
The kernel packages contain the Linux kernel, the core of any Linux operating system.<br>Security Fix(es):<br><li> kernel: Use-after-free in blkdrainqueue() function in block/blk-core.c (CVE-2018-20856)</li> <li> kernel: heap overflow in mwifiexupdatevsie() function of Marvell WiFi driver (CVE-2019-14816)</li> <li> kernel: heap-based buffer overflow in mwifiexprocesscountryie() function in drivers/net/wireless/marvell/mwifiex/staioctl.c (CVE-2019-14895)</li> <li> kernel: buffer overflow in cfg80211mgdwextgiwessid in net/wireless/wext-sme.c (CVE-2019-17133)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> [PATCH] perf: Fix a race between ringbufferdetach() and ringbufferwakeup() (BZ#1772826)</li> <li> core: backports from upstream (BZ#1780031)</li> <li> Race between ttyopen() and flushtoldisc() using the ttystruct->driverdata field. (BZ#1780160)</li> <li> [Hyper-V][RHEL7.6]Hyper-V guest waiting indefinitely for RCU callback when removing a mem cgroup (BZ#1783176)</li> Enhancement(s):<br><li> Selective backport: perf: Sync with upstream v4.16 (BZ#1782752)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:0664?
RHSA-2020:0664 is classified as a critical vulnerability due to the potential for exploitation leading to severe impacts on affected systems.
How do I fix RHSA-2020:0664?
To fix RHSA-2020:0664, update the kernel packages to version 3.10.0-957.46.1.el7 or later.
What types of vulnerabilities are addressed in RHSA-2020:0664?
RHSA-2020:0664 addresses a use-after-free vulnerability and a heap overflow, which can lead to potential code execution.
Which systems are affected by RHSA-2020:0664?
RHSA-2020:0664 affects various Red Hat Enterprise Linux 7 systems using specific kernel packages.
Is there a workaround for RHSA-2020:0664?
There is no known workaround for RHSA-2020:0664; thus, it is essential to apply the recommended updates.