RHSA-2020:3222: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: use-after-free in sound/core/timer.c (CVE-2019-19807) kernel: kernel: DAX hugepages not considered during mremap (CVE-2020-10757) kernel: Rogue cross-process SSBD shutdown. Linux scheduler logical bug allows an attacker to turn off the SSBD protection. (CVE-2020-10766) kernel: Indirect Branch Prediction Barrier is force-disabled when STIBP is unavailable or enhanced IBRS is available. (CVE-2020-10767) kernel: Indirect branch speculation can be enabled after it was force-disabled by the PRSPECFORCEDISABLE prctl command. (CVE-2020-10768) kernel: buffer overflow in mwifiexcmdappendvsietlv function in drivers/net/wireless/marvell/mwifiex/scan.c (CVE-2020-12653) kernel: heap-based buffer overflow in mwifiexretwmmgetstatus function in drivers/net/wireless/marvell/mwifiex/wmm.c (CVE-2020-12654) Kernel: vfio: access to disabled MMIO space of some devices may lead to DoS scenario (CVE-2020-12888) kernel: lockdown: bypass through ACPI write via efivarssdt (CVE-2019-20908) kernel: lockdown: bypass through ACPI write via acpiconfigfs (CVE-2020-15780) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): [DELL EMC 8.1 BUG] : Observing Multiple "hw csum failure" while installing RHEL 8.1 on iSCSI LUN (BZ#1821374) kernel: provide infrastructure to support dual-signing of the kernel (foundation to help address CVE-2020-10713) (BZ#1837432) deadlock between modprobe and netns exit (BZ#1845163) exitboot failed when install RHEL8.1 (BZ#1846179) http request is taking more time for endpoint running on different host via nodeport service (BZ#1847127) RHEL8.1 - s390/cio: fix virtio-ccw DMA without PV (BZ#1847534) RHEL8.1 - zEDC problems on z14 (genwqe/pci) (BZ#1847939) NVMe/FC with DM-MP unexpected I/O failure during "transitioning" [EIOP-8345] (BZ#1854678) Backport conntrack race condition fixes (BZ#1854953) nfconntrack module unload fail and refcount become to negative (BZ#1854954)
Affected Software
Remediation
Event History
Frequently Asked Questions
What security vulnerabilities are addressed in RHSA-2020:3222?
RHSA-2020:3222 addresses multiple vulnerabilities including a use-after-free issue in sound/core/timer.c (CVE-2019-19807) and a DAX hugepages handling flaw during mremap (CVE-2020-10757).
What is the severity of RHSA-2020:3222?
The severity of RHSA-2020:3222 is high due to the potential impact of the vulnerabilities on system stability and security.
How do I fix the vulnerabilities in RHSA-2020:3222?
To fix the vulnerabilities in RHSA-2020:3222, update to the kernel packages version 4.18.0-147.24.2.el8_1 or higher.
Which packages are affected by RHSA-2020:3222?
The affected packages in RHSA-2020:3222 include kernel, kernel-core, kernel-debug, bpftool, and several others on Red Hat systems.
What platforms are impacted by RHSA-2020:3222?
RHSA-2020:3222 impacts multiple platforms including x86_64 and ppc64le architectures.