RHSA-2020:1473: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: rtlp2pnoaie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel lacks a certain upper-bound check, leading to a buffer overflow (CVE-2019-17666) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): port show-kabi to python3 (BZ#1806925)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 3.10.0-514.74.1.el7 - Upgrade
Upgrade
redhat/kernel-abi-whiteliststo a version that resolves this vulnerability.Fixed in 3.10.0-514.74.1.el7 - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 3.10.0-514.74.1.el7 - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-514.74.1.el7 - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 3.10.0-514.74.1.el7 - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-514.74.1.el7 - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 3.10.0-514.74.1.el7 - Upgrade
Upgrade
redhat/kernel-docto a version that resolves this vulnerability.Fixed in 3.10.0-514.74.1.el7 - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 3.10.0-514.74.1.el7 - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 3.10.0-514.74.1.el7 - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-514.74.1.el7 - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 3.10.0-514.74.1.el7 - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 3.10.0-514.74.1.el7 - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 3.10.0-514.74.1.el7 - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-514.74.1.el7 - Upgrade
Upgrade
redhat/python-perfto a version that resolves this vulnerability.Fixed in 3.10.0-514.74.1.el7 - Upgrade
Upgrade
redhat/python-perf-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-514.74.1.el7 - Upgrade
Upgrade
redhat/kernel-bootwrapperto a version that resolves this vulnerability.Fixed in 3.10.0-514.74.1.el7 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64leto a version that resolves this vulnerability.Fixed in 3.10.0-514.74.1.el7 - Upgrade
Upgrade
kernel (Red Hat Enterprise Linux 7)to a version that resolves this vulnerability.Fixed in kernel-3.10.0-514.74.1.el7 - Upgrade
Upgrade
perf (Red Hat Enterprise Linux 7)to a version that resolves this vulnerability.Fixed in perf-3.10.0-514.74.1.el7 - Upgrade
Upgrade
python-perf (Red Hat Enterprise Linux 7)to a version that resolves this vulnerability.Fixed in python-perf-3.10.0-514.74.1.el7
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:1473?
The RHSA-2020:1473 vulnerability is classified as important.
How do I fix RHSA-2020:1473?
To fix RHSA-2020:1473, you need to update the kernel packages to version 3.10.0-514.74.1.el7.
What does RHSA-2020:1473 affect?
RHSA-2020:1473 affects various kernel related packages such as kernel, kernel-debug, and kernel-devel on Red Hat Enterprise Linux 7.
What is the nature of the vulnerability in RHSA-2020:1473?
The vulnerability in RHSA-2020:1473 involves a buffer overflow due to a lack of upper-bound check in the rtl_p2p_noa_ie function.
Is RHSA-2020:1473 a zero-day vulnerability?
No, RHSA-2020:1473 is not a zero-day vulnerability as it has been publicly disclosed and fixes have been made available.