RHSA-2020:4182: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: Count overflow in FUSE request leading to use-after-free issues. (CVE-2019-11487) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): NULL sdev dereference race in atapiqccomplete() (BZ#1876296)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 2.6.32-754.35.1.el6 - Upgrade
Upgrade
redhat/kernel-abi-whiteliststo a version that resolves this vulnerability.Fixed in 2.6.32-754.35.1.el6 - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 2.6.32-754.35.1.el6 - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 2.6.32-754.35.1.el6 - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 2.6.32-754.35.1.el6 - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 2.6.32-754.35.1.el6 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-i686to a version that resolves this vulnerability.Fixed in 2.6.32-754.35.1.el6 - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 2.6.32-754.35.1.el6 - Upgrade
Upgrade
redhat/kernel-docto a version that resolves this vulnerability.Fixed in 2.6.32-754.35.1.el6 - Upgrade
Upgrade
redhat/kernel-firmwareto a version that resolves this vulnerability.Fixed in 2.6.32-754.35.1.el6 - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 2.6.32-754.35.1.el6 - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 2.6.32-754.35.1.el6 - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 2.6.32-754.35.1.el6 - Upgrade
Upgrade
redhat/python-perfto a version that resolves this vulnerability.Fixed in 2.6.32-754.35.1.el6 - Upgrade
Upgrade
redhat/python-perf-debuginfoto a version that resolves this vulnerability.Fixed in 2.6.32-754.35.1.el6 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-s390xto a version that resolves this vulnerability.Fixed in 2.6.32-754.35.1.el6 - Upgrade
Upgrade
redhat/kernel-kdumpto a version that resolves this vulnerability.Fixed in 2.6.32-754.35.1.el6 - Upgrade
Upgrade
redhat/kernel-kdump-debuginfoto a version that resolves this vulnerability.Fixed in 2.6.32-754.35.1.el6 - Upgrade
Upgrade
redhat/kernel-kdump-develto a version that resolves this vulnerability.Fixed in 2.6.32-754.35.1.el6 - Upgrade
Upgrade
redhat/kernel-bootwrapperto a version that resolves this vulnerability.Fixed in 2.6.32-754.35.1.el6 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64to a version that resolves this vulnerability.Fixed in 2.6.32-754.35.1.el6
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:4182?
The severity of RHSA-2020:4182 is classified as critical due to the potential for use-after-free vulnerabilities in the Linux kernel.
How do I fix RHSA-2020:4182?
To fix RHSA-2020:4182, upgrade the kernel packages to version 2.6.32-754.35.1.el6 or later.
Which systems are affected by RHSA-2020:4182?
RHSA-2020:4182 affects systems running the Red Hat Enterprise Linux 6 kernel prior to version 2.6.32-754.35.1.el6.
What are the vulnerabilities addressed in RHSA-2020:4182?
RHSA-2020:4182 addresses a use-after-free vulnerability caused by a count overflow in FUSE requests, identified by CVE-2019-11487.
Is there a workaround for RHSA-2020:4182?
There are no known workarounds for RHSA-2020:4182, and users are advised to apply the security update as soon as possible.