RHSA-2020:2522: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operating system.<br>Security Fix(es):<br><li> kernel: double free may be caused by the function allocatetracebuffer in the file kernel/trace/trace.c (CVE-2017-18595)</li> <li> kernel: use-after-free in blkaddtrace in kernel/trace/blktrace.c (CVE-2019-19768)</li> <li> Kernel: NetLabel: null pointer dereference while receiving CIPSO packet with null category may cause kernel panic (CVE-2020-10711)</li> <li> kernel: denial of service via ioctl call in network tun handling (CVE-2018-7191)</li> <li> kernel: usb: missing size check in the usbgetextradescriptor() leading to DoS (CVE-2018-20169)</li> <li> kernel: perfeventopen() and execve() race in setuid programs allows a data leak (CVE-2019-3901)</li> <li> kernel: brcmfmac frame validation bypass (CVE-2019-9503)</li> <li> kernel: unchecked kstrdup of fwstr in drmloadedidfirmware leads to denial of service (CVE-2019-12382)</li> <li> kernel: use-after-free in arch/x86/lib/insn-eval.c (CVE-2019-13233)</li> <li> kernel: integer overflow and OOB read in drivers/block/floppy.c (CVE-2019-14283)</li> <li> kernel: memory leak in registerqueuekobjects() in net/core/net-sysfs.c leads to denial of service (CVE-2019-15916)</li> <li> Kernel: net: using kernel space address bits to derive IP ID may potentially break KASLR (CVE-2019-10639)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> Backport: Guest microcode version mismatch on secondary processors (BZ#1814002)</li> <li> Realtek 8111, 8112 stop working after upgrading to 3.10.0-1062 (BZ#1814601)</li> <li> [mlx5] Crash on reboot while having VF configured and in switchdev mode (BZ#1814800)</li> <li> qla2xxx: Urgent driver fix needed. Initiator does not relogin to target after receiving an explicit logout (BZ#1815595)</li> <li> High iSCSI read latency resolved by 'tcp: implement coalescing on backlog queue' (BZ#1817498)</li> <li> [RHEL7.8][Azure]Commits to resolve high network latency (BZ#1817934)</li> <li> NETDEV WATCHDOG: enp3s0 (r8169): transmit queue 0 timed out (BZ#1822541)</li> <li> RHEL7: block mq hang of a blkmqfreezequeuewait(), which waits for a zero of a qusagecounter, which never happens (BZ#1824545)</li> <li> Kernel crashes with a message fs/fscache/operation.c:449! (BZ#1826293)</li> <li> kernel BUG at fs/fscache/operation.c:70! FS-Cache: 4 == 5 is false - current state is FSCACHEOPSTCOMPLETE but should be FSCACHEOPCANCELLED in fscacheenqueueoperation (BZ#1839756)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:2522?
RHSA-2020:2522 is classified as a moderate severity vulnerability affecting the Linux kernel.
How do I fix RHSA-2020:2522?
To fix RHSA-2020:2522, update your kernel packages to the latest version 3.10.0-1062.26.1.el7 or later.
What vulnerabilities are addressed in RHSA-2020:2522?
RHSA-2020:2522 addresses vulnerabilities including a double free issue and a use-after-free condition in the Linux kernel.
Which packages are affected by RHSA-2020:2522?
RHSA-2020:2522 affects multiple packages, including kernel, kernel-debug, and bpftool, among others.
Is a reboot required after applying the fix for RHSA-2020:2522?
Yes, a reboot is required to ensure the updated kernel is loaded and the vulnerabilities are mitigated.