RHSA-2020:0036: Moderate: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: Use-after-free in sndpcminfo function in ALSA subsystem potentially leads to privilege escalation (CVE-2017-0861) kernel: Handling of mightcancel queueing is not properly pretected against race (CVE-2017-10661) kernel: kvm: guest userspace to guest kernel write (CVE-2018-10853) kernel: TLB flush happens too late on mremap (CVE-2018-18281) kernel: a NULL pointer dereference in drivers/scsi/megaraid/megaraidsasbase.c leading to DoS (CVE-2019-11810) kernel: use-after-free in drivers/char/ipmi/ipmisiintf.c, ipmisimemio.c, ipmisiportio.c (CVE-2019-11811) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Hard lockup in freeonepage()->rawspinlock() because sosreport command is reading from /proc/pagetypeinfo (BZ#1770730)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:0036?
RHSA-2020:0036 is classified as a moderate severity vulnerability affecting the Linux kernel.
How do I fix RHSA-2020:0036?
To fix RHSA-2020:0036, upgrade the affected kernel packages to at least version 3.10.0-862.46.1.el7.
What vulnerabilities are addressed in RHSA-2020:0036?
RHSA-2020:0036 addresses a use-after-free vulnerability in the snd_pcm_info function in the ALSA subsystem, which could lead to privilege escalation.
Which systems are affected by RHSA-2020:0036?
RHSA-2020:0036 affects systems running specific versions of the Red Hat Enterprise Linux kernel, including those prior to 3.10.0-862.46.1.el7.
What packages are impacted by RHSA-2020:0036?
The packages impacted by RHSA-2020:0036 include kernel, kernel-debug, kernel-devel, and others that are part of the kernel package suite.