Oval Definition:oval:com.redhat.rhsa:def:20204431
Revision Date:2020-11-04Version:639
Title:RHSA-2020:4431: kernel security, bug fix, and enhancement update (Moderate)
Description:The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: use after free in the video driver leads to local privilege escalation (CVE-2019-9458)

  • kernel: use-after-free in drivers/bluetooth/hci_ldisc.c (CVE-2019-15917)

  • kernel: out-of-bounds access in function hclge_tm_schd_mode_vnet_base_cfg (CVE-2019-15925)

  • kernel: memory leak in ccp_run_sha_cmd() (CVE-2019-18808)

  • kernel: Denial Of Service in the __ipmi_bmc_register() (CVE-2019-19046)

  • kernel: out-of-bounds write in ext4_xattr_set_entry (CVE-2019-19319)

  • Kernel: kvm: OOB memory write via kvm_dev_ioctl_get_cpuid (CVE-2019-19332)

  • kernel: use-after-free in ext4_put_super (CVE-2019-19447)

  • kernel: a malicious USB device in the drivers/input/ff-memless.c leads to use-after-free (CVE-2019-19524)

  • kernel: race condition caused by a malicious USB device in the USB character device driver layer (CVE-2019-19537)

  • kernel: use-after-free in serial_ir_init_module() (CVE-2019-19543)

  • kernel: use-after-free in __ext4_expand_extra_isize and ext4_xattr_set_entry (CVE-2019-19767)

  • kernel: use-after-free in debugfs_remove (CVE-2019-19770)

  • kernel: out-of-bounds write via crafted keycode table (CVE-2019-20636)

  • kernel: possible use-after-free due to a race condition in cdev_get (CVE-2020-0305)

  • kernel: out-of-bounds read in in vc_do_resize function (CVE-2020-8647)

  • kernel: use-after-free in n_tty_receive_buf_common function (CVE-2020-8648)

  • kernel: invalid read location in vgacon_invert_region function (CVE-2020-8649)

  • kernel: uninitialized kernel data leak in userspace coredumps (CVE-2020-10732)

  • kernel: SELinux netlink permission check bypass (CVE-2020-10751)

  • kernel: out-of-bounds write in mpol_parse_str (CVE-2020-11565)

  • kernel: mishandles invalid descriptors in drivers/media/usb/gspca/xirlink_cit.c (CVE-2020-11668)

  • kernel: buffer overflow in mt76_add_fragment function (CVE-2020-12465)

  • kernel: xdp_umem_reg in net/xdp/xdp_umem.c has an out-of-bounds write which could result in crash and data coruption (CVE-2020-12659)

  • kernel: sg_write function lacks an sg_remove_request call in a certain failure case (CVE-2020-12770)

  • kernel: possible to send arbitrary signals to a privileged (suidroot) parent process (CVE-2020-12826)

  • kernel: referencing inode of removed superblock in get_futex_key() causes UAF (CVE-2020-14381)

  • kernel: soft-lockups in iov_iter_copy_from_user_atomic() could result in DoS (CVE-2020-25641)

  • kernel: kernel pointer leak due to WARN_ON statement in video driver leads to local information disclosure (CVE-2019-9455)

  • kernel: null pointer dereference in dlpar_parse_cc_property (CVE-2019-12614)

  • kernel: null-pointer dereference in drivers/net/fjes/fjes_main.c (CVE-2019-16231)

  • kernel: null pointer dereference in drivers/scsi/qla2xxx/qla_os.c (CVE-2019-16233)

  • kernel: memory leak in af9005_identify_state() function (CVE-2019-18809)

  • kernel: A memory leak in the mwifiex_pcie_alloc_cmdrsp_buf() function (CVE-2019-19056)

  • kernel: memory leak in the crypto_report() function (CVE-2019-19062)

  • kernel: Two memory leaks in the rtl_usb_probe() function (CVE-2019-19063)

  • kernel: A memory leak in the rtl8xxxu_submit_int_urb() function (CVE-2019-19068)

  • kernel: A memory leak in the predicate_parse() function (CVE-2019-19072)

  • kernel: information leak bug caused by a malicious USB device in the drivers/media/usb/ttusb-dec/ttusb_dec.c (CVE-2019-19533)

  • kernel: Null pointer dereference in drop_sysctl_table() (CVE-2019-20054)

  • kernel: kernel stack information leak on s390/s390x (CVE-2020-10773)

  • kernel: possibility of memory disclosure when reading the file /proc/sys/kernel/rh_features (CVE-2020-10774)

  • kernel: vhost-net: stack overflow in get_raw_socket while checking sk_family field (CVE-2020-10942)

  • kernel: sync of excessive duration via an XFS v5 image with crafted metadata (CVE-2020-12655)
  • Family:unixClass:patch
    Status:Reference(s):CVE-2019-12614
    CVE-2019-15917
    CVE-2019-15925
    CVE-2019-16231
    CVE-2019-16233
    CVE-2019-18808
    CVE-2019-18809
    CVE-2019-19046
    CVE-2019-19056
    CVE-2019-19062
    CVE-2019-19063
    CVE-2019-19068
    CVE-2019-19072
    CVE-2019-19319
    CVE-2019-19332
    CVE-2019-19447
    CVE-2019-19524
    CVE-2019-19533
    CVE-2019-19537
    CVE-2019-19543
    CVE-2019-19602
    CVE-2019-19767
    CVE-2019-19770
    CVE-2019-20054
    CVE-2019-20636
    CVE-2019-20812
    CVE-2019-9455
    CVE-2019-9458
    CVE-2020-0305
    CVE-2020-0444
    CVE-2020-10732
    CVE-2020-10751
    CVE-2020-10773
    CVE-2020-10774
    CVE-2020-10942
    CVE-2020-11565
    CVE-2020-11668
    CVE-2020-12465
    CVE-2020-12655
    CVE-2020-12659
    CVE-2020-12770
    CVE-2020-12826
    CVE-2020-14381
    CVE-2020-25641
    CVE-2020-8647
    CVE-2020-8648
    CVE-2020-8649
    CVE-2021-3715
    RHSA-2020:4431
    Platform(s):Red Hat Enterprise Linux 8
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 8 is installed
  • OR Red Hat CoreOS 4 is installed
  • AND
  • kernel earlier than 0:4.18.0-240.el8 is currently running
  • OR kernel earlier than 0:4.18.0-240.el8 is set to boot up on next boot
  • AND
  • bpftool is earlier than 0:4.18.0-240.el8
  • AND bpftool is signed with Red Hat redhatrelease2 key
  • kernel is earlier than 0:4.18.0-240.el8
  • AND kernel is signed with Red Hat redhatrelease2 key
  • kernel-abi-whitelists is earlier than 0:4.18.0-240.el8
  • AND kernel-abi-whitelists is signed with Red Hat redhatrelease2 key
  • kernel-core is earlier than 0:4.18.0-240.el8
  • AND kernel-core is signed with Red Hat redhatrelease2 key
  • kernel-cross-headers is earlier than 0:4.18.0-240.el8
  • AND kernel-cross-headers is signed with Red Hat redhatrelease2 key
  • kernel-debug is earlier than 0:4.18.0-240.el8
  • AND kernel-debug is signed with Red Hat redhatrelease2 key
  • kernel-debug-core is earlier than 0:4.18.0-240.el8
  • AND kernel-debug-core is signed with Red Hat redhatrelease2 key
  • kernel-debug-devel is earlier than 0:4.18.0-240.el8
  • AND kernel-debug-devel is signed with Red Hat redhatrelease2 key
  • kernel-debug-modules is earlier than 0:4.18.0-240.el8
  • AND kernel-debug-modules is signed with Red Hat redhatrelease2 key
  • kernel-debug-modules-extra is earlier than 0:4.18.0-240.el8
  • AND kernel-debug-modules-extra is signed with Red Hat redhatrelease2 key
  • kernel-devel is earlier than 0:4.18.0-240.el8
  • AND kernel-devel is signed with Red Hat redhatrelease2 key
  • kernel-doc is earlier than 0:4.18.0-240.el8
  • AND kernel-doc is signed with Red Hat redhatrelease2 key
  • kernel-headers is earlier than 0:4.18.0-240.el8
  • AND kernel-headers is signed with Red Hat redhatrelease2 key
  • kernel-modules is earlier than 0:4.18.0-240.el8
  • AND kernel-modules is signed with Red Hat redhatrelease2 key
  • kernel-modules-extra is earlier than 0:4.18.0-240.el8
  • AND kernel-modules-extra is signed with Red Hat redhatrelease2 key
  • kernel-tools is earlier than 0:4.18.0-240.el8
  • AND kernel-tools is signed with Red Hat redhatrelease2 key
  • kernel-tools-libs is earlier than 0:4.18.0-240.el8
  • AND kernel-tools-libs is signed with Red Hat redhatrelease2 key
  • kernel-tools-libs-devel is earlier than 0:4.18.0-240.el8
  • AND kernel-tools-libs-devel is signed with Red Hat redhatrelease2 key
  • kernel-zfcpdump is earlier than 0:4.18.0-240.el8
  • AND kernel-zfcpdump is signed with Red Hat redhatrelease2 key
  • kernel-zfcpdump-core is earlier than 0:4.18.0-240.el8
  • AND kernel-zfcpdump-core is signed with Red Hat redhatrelease2 key
  • kernel-zfcpdump-devel is earlier than 0:4.18.0-240.el8
  • AND kernel-zfcpdump-devel is signed with Red Hat redhatrelease2 key
  • kernel-zfcpdump-modules is earlier than 0:4.18.0-240.el8
  • AND kernel-zfcpdump-modules is signed with Red Hat redhatrelease2 key
  • kernel-zfcpdump-modules-extra is earlier than 0:4.18.0-240.el8
  • AND kernel-zfcpdump-modules-extra is signed with Red Hat redhatrelease2 key
  • perf is earlier than 0:4.18.0-240.el8
  • AND perf is signed with Red Hat redhatrelease2 key
  • python3-perf is earlier than 0:4.18.0-240.el8
  • AND python3-perf is signed with Red Hat redhatrelease2 key
  • BACK