RHSA-2020:4431: Moderate: kernel security, bug fix, and enhancement update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: use after free in the video driver leads to local privilege escalation (CVE-2019-9458) kernel: use-after-free in drivers/bluetooth/hcildisc.c (CVE-2019-15917) kernel: out-of-bounds access in function hclgetmschdmodevnetbasecfg (CVE-2019-15925) kernel: memory leak in ccprunshacmd() (CVE-2019-18808) kernel: Denial Of Service in the ipmibmcregister() (CVE-2019-19046) kernel: out-of-bounds write in ext4xattrsetentry (CVE-2019-19319) Kernel: kvm: OOB memory write via kvmdevioctlgetcpuid (CVE-2019-19332) kernel: use-after-free in ext4putsuper (CVE-2019-19447) kernel: a malicious USB device in the drivers/input/ff-memless.c leads to use-after-free (CVE-2019-19524) kernel: race condition caused by a malicious USB device in the USB character device driver layer (CVE-2019-19537) kernel: use-after-free in serialirinitmodule() (CVE-2019-19543) kernel: use-after-free in ext4expandextraisize and ext4xattrsetentry (CVE-2019-19767) kernel: use-after-free in debugfsremove (CVE-2019-19770) kernel: out-of-bounds write via crafted keycode table (CVE-2019-20636) kernel: possible use-after-free due to a race condition in cdevget (CVE-2020-0305) kernel: out-of-bounds read in in vcdoresize function (CVE-2020-8647) kernel: use-after-free in nttyreceivebufcommon function (CVE-2020-8648) kernel: invalid read location in vgaconinvertregion function (CVE-2020-8649) kernel: uninitialized kernel data leak in userspace coredumps (CVE-2020-10732) kernel: SELinux netlink permission check bypass (CVE-2020-10751) kernel: out-of-bounds write in mpolparsestr (CVE-2020-11565) kernel: mishandles invalid descriptors in drivers/media/usb/gspca/xirlinkcit.c (CVE-2020-11668) kernel: buffer overflow in mt76addfragment function (CVE-2020-12465) kernel: xdpumemreg in net/xdp/xdpumem.c has an out-of-bounds write which could result in crash and data coruption (CVE-2020-12659) kernel: sgwrite function lacks an sgremoverequest call in a certain failure case (CVE-2020-12770) kernel: possible to send arbitrary signals to a privileged (suidroot) parent process (CVE-2020-12826) kernel: referencing inode of removed superblock in getfutexkey() causes UAF (CVE-2020-14381) kernel: soft-lockups in iovitercopyfromuseratomic() could result in DoS (CVE-2020-25641) kernel: kernel pointer leak due to WARNON statement in video driver leads to local information disclosure (CVE-2019-9455) kernel: null pointer dereference in dlparparseccproperty (CVE-2019-12614) kernel: null-pointer dereference in drivers/net/fjes/fjesmain.c (CVE-2019-16231) kernel: null pointer dereference in drivers/scsi/qla2xxx/qlaos.c (CVE-2019-16233) kernel: memory leak in af9005identifystate() function (CVE-2019-18809) kernel: A memory leak in the mwifiexpciealloccmdrspbuf() function (CVE-2019-19056) kernel: memory leak in the cryptoreport() function (CVE-2019-19062) kernel: Two memory leaks in the rtlusbprobe() function (CVE-2019-19063) kernel: A memory leak in the rtl8xxxusubmitinturb() function (CVE-2019-19068) kernel: A memory leak in the predicateparse() function (CVE-2019-19072) kernel: information leak bug caused by a malicious USB device in the drivers/media/usb/ttusb-dec/ttusbdec.c (CVE-2019-19533) kernel: Null pointer dereference in dropsysctltable() (CVE-2019-20054) kernel: kernel stack information leak on s390/s390x (CVE-2020-10773) kernel: possibility of memory disclosure when reading the file /proc/sys/kernel/rhfeatures (CVE-2020-10774) kernel: vhost-net: stack overflow in getrawsocket while checking skfamily field (CVE-2020-10942) kernel: sync of excessive duration via an XFS v5 image with crafted metadata (CVE-2020-12655)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:4431?
RHSA-2020:4431 is classified as a critical severity vulnerability.
How do I fix RHSA-2020:4431?
To fix RHSA-2020:4431, you should update your kernel packages to version 4.18.0-240.el8 or later.
What are the affected systems in RHSA-2020:4431?
RHSA-2020:4431 affects Red Hat Enterprise Linux 8 systems using kernel version 4.18.0-240.el8.
What type of vulnerability is addressed in RHSA-2020:4431?
RHSA-2020:4431 addresses a use-after-free vulnerability that can lead to local privilege escalation.
What should I do if I cannot apply the update for RHSA-2020:4431 immediately?
If you cannot apply the update immediately, ensure that your system is protected by other security measures and monitoring for suspicious activities.