Oval Definition:oval:com.redhat.rhsa:def:20200204
Revision Date:2020-01-22Version:637
Title:RHSA-2020:0204: kernel security and bug fix update (Important)
Description:The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • hw: Machine Check Error on Page Size Change (IFU) (CVE-2018-12207)

  • hw: TSX Transaction Asynchronous Abort (TAA) (CVE-2019-11135)

  • kernel: nfs: use-after-free in svc_process_common() (CVE-2018-16884)

  • hw: Intel GPU blitter manipulation can allow for arbitrary kernel memory write (CVE-2019-0155)

  • Kernel: vhost_net: infinite loop while receiving packets leads to DoS (CVE-2019-3900)

  • Kernel: page cache side channel attacks (CVE-2019-5489)

  • hardware: bluetooth: BR/EDR encryption key negotiation attacks (KNOB) (CVE-2019-9506)

  • kernel: Heap overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c (CVE-2019-10126)

  • kernel: heap overflow in mwifiex_update_vs_ie() function of Marvell WiFi driver (CVE-2019-14816)

  • Kernel: KVM: OOB memory access via mmio ring buffer (CVE-2019-14821)

  • kernel: heap overflow in marvell/mwifiex/tdls.c (CVE-2019-14901)

  • hw: Intel GPU Denial Of Service while accessing MMIO in lower power state (CVE-2019-0154)

    For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

    Bug Fix(es):

  • Backport TCP follow-up for small buffers (BZ#1739184)

  • TCP performance regression after CVE-2019-11478 bug fix (BZ#1743170)

  • RHEL8.0 - bnx2x link down, caused by transmit timeouts during load test (Marvell/Cavium/QLogic) (L3:) (BZ#1743548)

  • block: blk-mq improvement (BZ#1780567)

  • RHEL8.0 - Regression to RHEL7.6 by changing force_latency found during RHEL8.0 validation for SAP HANA on POWER (BZ#1781111)

  • blk-mq: overwirte performance drops on real MQ device (BZ#1782183)

  • RHEL8: creating vport takes lot of memory i.e 2GB per vport which leads to drain out system memory quickly. (BZ#1782705)
  • Family:unixClass:patch
    Status:Reference(s):CVE-2018-12207
    CVE-2018-16884
    CVE-2019-0154
    CVE-2019-0155
    CVE-2019-10126
    CVE-2019-11135
    CVE-2019-14816
    CVE-2019-14821
    CVE-2019-14901
    CVE-2019-3900
    CVE-2019-5489
    CVE-2019-9506
    RHSA-2020:0204
    Platform(s):Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 8 is installed
  • AND
  • kernel earlier than 0:4.18.0-80.15.1.el8_0 is currently running
  • OR kernel earlier than 0:4.18.0-80.15.1.el8_0 is set to boot up on next boot
  • AND
  • kernel-headers is earlier than 0:4.18.0-80.15.1.el8_0
  • AND kernel-headers is signed with Red Hat redhatrelease2 key
  • kernel-devel is earlier than 0:4.18.0-80.15.1.el8_0
  • AND kernel-devel is signed with Red Hat redhatrelease2 key
  • kernel-debug-modules-extra is earlier than 0:4.18.0-80.15.1.el8_0
  • AND kernel-debug-modules-extra is signed with Red Hat redhatrelease2 key
  • kernel-debug-modules is earlier than 0:4.18.0-80.15.1.el8_0
  • AND kernel-debug-modules is signed with Red Hat redhatrelease2 key
  • kernel-debug-devel is earlier than 0:4.18.0-80.15.1.el8_0
  • AND kernel-debug-devel is signed with Red Hat redhatrelease2 key
  • kernel-debug-core is earlier than 0:4.18.0-80.15.1.el8_0
  • AND kernel-debug-core is signed with Red Hat redhatrelease2 key
  • kernel-debug is earlier than 0:4.18.0-80.15.1.el8_0
  • AND kernel-debug is signed with Red Hat redhatrelease2 key
  • kernel-cross-headers is earlier than 0:4.18.0-80.15.1.el8_0
  • AND kernel-cross-headers is signed with Red Hat redhatrelease2 key
  • kernel-core is earlier than 0:4.18.0-80.15.1.el8_0
  • AND kernel-core is signed with Red Hat redhatrelease2 key
  • kernel is earlier than 0:4.18.0-80.15.1.el8_0
  • AND kernel is signed with Red Hat redhatrelease2 key
  • bpftool is earlier than 0:4.18.0-80.15.1.el8_0
  • AND bpftool is signed with Red Hat redhatrelease2 key
  • python3-perf is earlier than 0:4.18.0-80.15.1.el8_0
  • AND python3-perf is signed with Red Hat redhatrelease2 key
  • perf is earlier than 0:4.18.0-80.15.1.el8_0
  • AND perf is signed with Red Hat redhatrelease2 key
  • kernel-tools-libs is earlier than 0:4.18.0-80.15.1.el8_0
  • AND kernel-tools-libs is signed with Red Hat redhatrelease2 key
  • kernel-tools is earlier than 0:4.18.0-80.15.1.el8_0
  • AND kernel-tools is signed with Red Hat redhatrelease2 key
  • kernel-modules-extra is earlier than 0:4.18.0-80.15.1.el8_0
  • AND kernel-modules-extra is signed with Red Hat redhatrelease2 key
  • kernel-modules is earlier than 0:4.18.0-80.15.1.el8_0
  • AND kernel-modules is signed with Red Hat redhatrelease2 key
  • kernel-doc is earlier than 0:4.18.0-80.15.1.el8_0
  • AND kernel-doc is signed with Red Hat redhatrelease2 key
  • kernel-abi-whitelists is earlier than 0:4.18.0-80.15.1.el8_0
  • AND kernel-abi-whitelists is signed with Red Hat redhatrelease2 key
  • kernel-zfcpdump-modules-extra is earlier than 0:4.18.0-80.15.1.el8_0
  • AND kernel-zfcpdump-modules-extra is signed with Red Hat redhatrelease2 key
  • kernel-zfcpdump-modules is earlier than 0:4.18.0-80.15.1.el8_0
  • AND kernel-zfcpdump-modules is signed with Red Hat redhatrelease2 key
  • kernel-zfcpdump-devel is earlier than 0:4.18.0-80.15.1.el8_0
  • AND kernel-zfcpdump-devel is signed with Red Hat redhatrelease2 key
  • kernel-zfcpdump-core is earlier than 0:4.18.0-80.15.1.el8_0
  • AND kernel-zfcpdump-core is signed with Red Hat redhatrelease2 key
  • kernel-zfcpdump is earlier than 0:4.18.0-80.15.1.el8_0
  • AND kernel-zfcpdump is signed with Red Hat redhatrelease2 key
  • BACK