RHSA-2020:1493: Important: kernel-alt security and bug fix update
The kernel-alt packages provide the Linux kernel version 4.x.Security Fix(es): kernel: heap-based buffer overflow in mwifiexprocesscountryie() function in drivers/net/wireless/marvell/mwifiex/staioctl.c (CVE-2019-14895) kernel: heap overflow in marvell/mwifiex/tdls.c (CVE-2019-14901) kernel: triggering AP to send IAPP location updates for stations before the required authentication process has completed can lead to DoS (CVE-2019-5108) kernel: powerpc: local user can read vector registers of other users' processes via an interrupt (CVE-2019-15031) kernel: out-of-bounds array access in xfrmpolicyunlink (CVE-2019-15666) kernel: a NULL pointer dereference in drivers/net/wireless/ath/ath10k/usb.c leads to a crash (CVE-2019-15099) kernel: when cpu.cfsquotaus is used allows attackers to cause a denial of service against non-cpu-bound applications (CVE-2019-19922) kernel: Null pointer dereference in dropsysctltable() in fs/proc/procsysctl.c (CVE-2019-20054) kernel: memory leak in mwifiextmcmd in drivers/net/wireless/marvell/mwifiex/cfg80211.c (CVE-2019-20095) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): rhel-alt-76z bsd process accounting(acct(2)) does not work (BZ#1763618)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:1493?
The severity of RHSA-2020:1493 is rated as important due to potential heap-based buffer overflow vulnerabilities.
How do I fix RHSA-2020:1493?
To fix RHSA-2020:1493, update your kernel-alt packages to version 4.14.0-115.19.1.el7a or the corresponding remedial versions.
What vulnerabilities does RHSA-2020:1493 address?
RHSA-2020:1493 addresses heap-based buffer overflow vulnerabilities in the mwifiex_process_country_ie() function and additional related issues.
Which systems are affected by RHSA-2020:1493?
Systems using the kernel-alt packages version prior to 4.14.0-115.19.1.el7a are affected by RHSA-2020:1493.
What packages need to be updated for RHSA-2020:1493?
Update the kernel, kernel-alt, kernel-debug, kernel-devel, and related packages to the specified remedial versions to resolve RHSA-2020:1493.