RHSA-2020:3010: Important: kernel security, bug fix, and enhancement update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: use-after-free in sound/core/timer.c (CVE-2019-19807) kernel: kernel: DAX hugepages not considered during mremap (CVE-2020-10757) kernel: Rogue cross-process SSBD shutdown. Linux scheduler logical bug allows an attacker to turn off the SSBD protection. (CVE-2020-10766) kernel: Indirect Branch Prediction Barrier is force-disabled when STIBP is unavailable or enhanced IBRS is available. (CVE-2020-10767) kernel: Indirect branch speculation can be enabled after it was force-disabled by the PRSPECFORCEDISABLE prctl command. (CVE-2020-10768) kernel: buffer overflow in mwifiexcmdappendvsietlv function in drivers/net/wireless/marvell/mwifiex/scan.c (CVE-2020-12653) kernel: heap-based buffer overflow in mwifiexretwmmgetstatus function in drivers/net/wireless/marvell/mwifiex/wmm.c (CVE-2020-12654) Kernel: vfio: access to disabled MMIO space of some devices may lead to DoS scenario (CVE-2020-12888) kernel: kvm: Information leak within a KVM guest (CVE-2019-3016) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): [FJ8.2 Bug]: kernel: retrieving process core dump of the init process (PID 1) fails (BZ#1821378) [FJ8.0 Bug]: System hungs up after setting parameters for hugepages (BZ#1835789) RHEL8.2 Alpha - ISST-LTE:PowerVM: vNIC DLPAR crashes the LPAR (ibmvnic) (BZ#1836229) "[sig-network] Services should be rejected when no endpoints exist" test fails frequently on RHEL8 nodes (BZ#1836302) RHEL8.2 Beta - RHEL8.2 reports EEH errors on internal SAS adapter during HTX run on PMEM (SCM/pmem) (BZ#1842406) RHEL8.1 - s390/cio: fix virtio-ccw DMA without PV (BZ#1842620) deadlock between modprobe and netns exit (BZ#1845164) exitboot failed when install RHEL8.1 (BZ#1846180) http request is taking more time for endpoint running on different host via nodeport service (BZ#1847128) RHEL8.1 - zEDC problems on z14 (genwqe/pci) (BZ#1847453) WARNING: CPU: 1 PID: 0 at arch/x86/kernel/apic/vector.c:846 freemovedvector+0x141/0x150 (BZ#1848545) Backport conntrack race condition fixes (BZ#1851003) nfconntrack module unload fail and refcount become to negative (BZ#1851005) OVS: backport performance patches from upstream to 8.2z (BZ#1851235) RHEL8.3: backport "smp: Allow smpcallfunctionsingleasync() to insert locked csd" (BZ#1851406) [DELL EMC 8.2 BUG] NVMe drive is not detected after multiple hotplug (hot add + surprise remove) operations (BZ#1852045) Enhancement(s): [Mellanox 8.3 FEAT] mlx5: drivers update upto Linux v5.5 (BZ#1843544) [IBM 8.3 FEAT] Update nvme driver to latest level for POWER (BZ#1846405)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:3010?
The severity of RHSA-2020:3010 is classified as important.
How do I fix RHSA-2020:3010?
To fix RHSA-2020:3010, update your kernel packages to version 4.18.0-193.13.2.el8_2 or later.
What vulnerabilities does RHSA-2020:3010 address?
RHSA-2020:3010 addresses several vulnerabilities, including CVE-2019-19807 and CVE-2020-10757.
What packages are affected by RHSA-2020:3010?
Packages affected by RHSA-2020:3010 include kernel, bpftool, and kernel-debug among others.
When was RHSA-2020:3010 released?
RHSA-2020:3010 was released on December 10, 2020.