Oval Definition:
oval:com.redhat.rhsa:def:20204609
Revision Date
:
2020-11-04
Version
:
638
Title
:
RHSA-2020:4609: kernel-rt security and bug fix update (Moderate)
Description
:
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.
Security Fix(es):
kernel: use after free due to race condition in the video driver leads to local privilege escalation (CVE-2019-9458)
kernel: use-after-free in drivers/bluetooth/hci_ldisc.c (CVE-2019-15917)
kernel: out-of-bounds access in function hclge_tm_schd_mode_vnet_base_cfg (CVE-2019-15925)
kernel: memory leak in ccp_run_sha_cmd() (CVE-2019-18808)
kernel: Denial Of Service in the __ipmi_bmc_register() (CVE-2019-19046)
kernel: out-of-bounds write in ext4_xattr_set_entry in fs/ext4/xattr.c (CVE-2019-19319)
Kernel: kvm: OOB memory write via kvm_dev_ioctl_get_cpuid (CVE-2019-19332)
kernel: use-after-free in ext4_put_super (CVE-2019-19447)
kernel: a malicious USB device in the drivers/input/ff-memless.c leads to use-after-free (CVE-2019-19524)
kernel: race condition caused by a malicious USB device in the USB character device driver layer (CVE-2019-19537)
kernel: use-after-free in serial_ir_init_module() (CVE-2019-19543)
kernel: use-after-free in __ext4_expand_extra_isize and ext4_xattr_set_entry (CVE-2019-19767)
kernel: use-after-free in debugfs_remove (CVE-2019-19770)
kernel: out-of-bounds write via crafted keycode table (CVE-2019-20636)
kernel: possible use-after-free due to a race condition in cdev_get of char_dev.c (CVE-2020-0305)
kernel: out-of-bounds read in in vc_do_resize (CVE-2020-8647)
kernel: use-after-free in n_tty_receive_buf_common (CVE-2020-8648)
kernel: invalid read location in vgacon_invert_region (CVE-2020-8649)
kernel: uninitialized kernel data leak in userspace coredumps (CVE-2020-10732)
kernel: SELinux netlink permission check bypass (CVE-2020-10751)
kernel: out-of-bounds write in mpol_parse_str function in mm/mempolicy.c (CVE-2020-11565)
kernel: mishandles invalid descriptors in drivers/media/usb/gspca/xirlink_cit.c (CVE-2020-11668)
kernel: out-of-bounds write in xdp_umem_reg (CVE-2020-12659)
kernel: sg_write function lacks an sg_remove_request call in a certain failure case (CVE-2020-12770)
kernel: possible to send arbitrary signals to a privileged (suidroot) parent process (CVE-2020-12826)
kernel: referencing inode of removed superblock in get_futex_key() causes UAF (CVE-2020-14381)
kernel: soft-lockups in iov_iter_copy_from_user_atomic() could result in DoS (CVE-2020-25641)
kernel: kernel pointer leak due to WARN_ON statement in video driver leads to local information disclosure (CVE-2019-9455)
kernel: null-pointer dereference in drivers/net/fjes/fjes_main.c (CVE-2019-16231)
kernel: null pointer dereference in drivers/scsi/qla2xxx/qla_os.c (CVE-2019-16233)
kernel: memory leak in af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c (CVE-2019-18809)
kernel: A memory leak in the mwifiex_pcie_alloc_cmdrsp_buf() (CVE-2019-19056)
kernel: memory leak in the crypto_report() function in crypto/crypto_user_base.c allows for DoS (CVE-2019-19062)
kernel: Two memory leaks in the rtl_usb_probe() (CVE-2019-19063)
kernel: A memory leak in the rtl8xxxu_submit_int_urb() (CVE-2019-19068)
kernel: A memory leak in the predicate_parse() function in kernel/trace/trace_events_filter.c allows for a DoS (CVE-2019-19072)
kernel: information leak bug caused by a malicious USB device in the drivers/media/usb/ttusb-dec/ttusb_dec.c (CVE-2019-19533)
kernel: Null pointer dereference in drop_sysctl_table() in fs/proc/proc_sysctl.c (CVE-2019-20054)
kernel: possibility of memory disclosure when reading the file /proc/sys/kernel/rh_features (CVE-2020-10774)
kernel: vhost-net: stack overflow in get_raw_socket while checking sk_family field (CVE-2020-10942)
kernel: sync of excessive duration via an XFS v5 image with crafted metadata (CVE-2020-12655)
Family
:
unix
Class
:
patch
Status
:
Reference(s)
:
CVE-2019-15917
CVE-2019-15925
CVE-2019-16231
CVE-2019-16233
CVE-2019-18808
CVE-2019-18809
CVE-2019-19046
CVE-2019-19056
CVE-2019-19062
CVE-2019-19063
CVE-2019-19068
CVE-2019-19072
CVE-2019-19319
CVE-2019-19332
CVE-2019-19447
CVE-2019-19524
CVE-2019-19533
CVE-2019-19537
CVE-2019-19543
CVE-2019-19767
CVE-2019-19770
CVE-2019-20054
CVE-2019-20636
CVE-2019-9455
CVE-2019-9458
CVE-2020-0305
CVE-2020-10732
CVE-2020-10751
CVE-2020-10774
CVE-2020-10942
CVE-2020-11565
CVE-2020-11668
CVE-2020-12655
CVE-2020-12659
CVE-2020-12770
CVE-2020-12826
CVE-2020-14381
CVE-2020-25641
CVE-2020-8647
CVE-2020-8648
CVE-2020-8649
CVE-2021-3715
RHSA-2020:4609
Platform(s)
:
Red Hat Enterprise Linux 8
Product(s)
:
Definition Synopsis
Red Hat Enterprise Linux must be installed
OR
Package Information
Red Hat Enterprise Linux 8 is installed
OR
Red Hat CoreOS 4 is installed
AND
kernel-rt earlier than 0:4.18.0-240.rt7.54.el8 is currently running
OR
kernel-rt earlier than 0:4.18.0-240.rt7.54.el8 is set to boot up on next boot
AND
kernel-rt is earlier than 0:4.18.0-240.rt7.54.el8
AND
kernel-rt is signed with Red Hat redhatrelease2 key
kernel-rt-core is earlier than 0:4.18.0-240.rt7.54.el8
AND
kernel-rt-core is signed with Red Hat redhatrelease2 key
kernel-rt-debug is earlier than 0:4.18.0-240.rt7.54.el8
AND
kernel-rt-debug is signed with Red Hat redhatrelease2 key
kernel-rt-debug-core is earlier than 0:4.18.0-240.rt7.54.el8
AND
kernel-rt-debug-core is signed with Red Hat redhatrelease2 key
kernel-rt-debug-devel is earlier than 0:4.18.0-240.rt7.54.el8
AND
kernel-rt-debug-devel is signed with Red Hat redhatrelease2 key
kernel-rt-debug-kvm is earlier than 0:4.18.0-240.rt7.54.el8
AND
kernel-rt-debug-kvm is signed with Red Hat redhatrelease2 key
kernel-rt-debug-modules is earlier than 0:4.18.0-240.rt7.54.el8
AND
kernel-rt-debug-modules is signed with Red Hat redhatrelease2 key
kernel-rt-debug-modules-extra is earlier than 0:4.18.0-240.rt7.54.el8
AND
kernel-rt-debug-modules-extra is signed with Red Hat redhatrelease2 key
kernel-rt-devel is earlier than 0:4.18.0-240.rt7.54.el8
AND
kernel-rt-devel is signed with Red Hat redhatrelease2 key
kernel-rt-kvm is earlier than 0:4.18.0-240.rt7.54.el8
AND
kernel-rt-kvm is signed with Red Hat redhatrelease2 key
kernel-rt-modules is earlier than 0:4.18.0-240.rt7.54.el8
AND
kernel-rt-modules is signed with Red Hat redhatrelease2 key
kernel-rt-modules-extra is earlier than 0:4.18.0-240.rt7.54.el8
AND
kernel-rt-modules-extra is signed with Red Hat redhatrelease2 key
BACK