RHSA-2020:2085: Important: kernel-rt security and bug fix update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): kernel: double free may be caused by the function allocatetracebuffer in the file kernel/trace/trace.c (CVE-2017-18595) kernel: use-after-free in blkaddtrace in kernel/trace/blktrace.c (CVE-2019-19768) Kernel: NetLabel: null pointer dereference while receiving CIPSO packet with null category may cause kernel panic (CVE-2020-10711) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): kernel-rt: update to the RHEL7.8.z batch#1 source tree (BZ#1812282)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:2085?
The severity of RHSA-2020:2085 is considered moderate due to the double free vulnerability in the kernel.
How do I fix RHSA-2020:2085?
To fix RHSA-2020:2085, update the affected kernel-rt packages to version 3.10.0-1127.8.2.rt56.1103.el7.
What systems are affected by RHSA-2020:2085?
RHSA-2020:2085 affects the kernel-rt packages on Red Hat Enterprise Linux 7 systems.
What type of vulnerability is described in RHSA-2020:2085?
RHSA-2020:2085 describes a double free vulnerability that could lead to stability issues.
Is it safe to postpone RHSA-2020:2085 updates?
It is not recommended to postpone updates for RHSA-2020:2085 as it may expose systems to potential risks.