RHSA-2020:2854: Important: kernel-alt security and bug fix update
The kernel-alt packages provide the Linux kernel version 4.x.Security Fix(es): kernel: nfs: use-after-free in svcprocesscommon() (CVE-2018-16884) Kernel: ppc: kvm: conflicting use of HSTATEHOSTR1 to store r1 state leads to host stack corruption (CVE-2020-8834) Kernel: vfio: access to disabled MMIO space of some devices may lead to DoS scenario (CVE-2020-12888) kernel: use after free due to race condition in the video driver leads to local privilege escalation (CVE-2019-9458) kernel: use-after-free in drivers/char/ipmi/ipmisiintf.c, ipmisimemio.c, ipmisiportio.c (CVE-2019-11811) kernel: use-after-free in drivers/bluetooth/hcildisc.c (CVE-2019-15917) kernel: memory leak in ccprunshacmd() function in drivers/crypto/ccp/ccp-ops.c (CVE-2019-18808) kernel: use-after-free in ext4expandextraisize and ext4xattrsetentry related to fs/ext4/inode.c and fs/ext4/super.c (CVE-2019-19767) kernel: an out-of-bounds write via crafted keycode table (CVE-2019-20636) kernel: use-after-free read in napigrofrags() in the Linux kernel (CVE-2020-10720) kernel: out-of-bounds write in mpolparsestr function in mm/mempolicy.c (CVE-2020-11565) kernel: A memory leak in the cryptoreport() function in crypto/cryptouserbase.c allows for a DoS (CVE-2019-19062) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): XFS: Metadata corruption detected at xfsattr3leafreadverify [rhel-alt-7.6.z] (BZ#1830836)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:2854?
The severity of RHSA-2020:2854 is considered important due to the potential for denial of service or execution of arbitrary code.
How do I fix RHSA-2020:2854?
To fix RHSA-2020:2854, update your system to the kernel packages version 4.14.0-115.26.1.el7a or later.
What vulnerabilities are addressed in RHSA-2020:2854?
RHSA-2020:2854 addresses vulnerabilities including CVE-2018-16884, which is a use-after-free issue in nfs.
What systems are affected by RHSA-2020:2854?
Systems using the kernel-alt packages version prior to 4.14.0-115.26.1.el7a are affected by RHSA-2020:2854.
Is there a workaround for RHSA-2020:2854?
While it's recommended to apply the updates, there are no specific workarounds for RHSA-2020:2854.