RHSA-2020:3220: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: kernel: DAX hugepages not considered during mremap (CVE-2020-10757) kernel: buffer overflow in mwifiexcmdappendvsietlv function in drivers/net/wireless/marvell/mwifiex/scan.c (CVE-2020-12653) kernel: heap-based buffer overflow in mwifiexretwmmgetstatus function in drivers/net/wireless/marvell/mwifiex/wmm.c (CVE-2020-12654) kernel: use-after-free caused by a malicious USB device in the drivers/hid/usbhid/hiddev.c driver (CVE-2019-19527) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): RHEL7.7 - scsi: ibmvfc: Avoid loss of all paths during SVC node reboot (BZ#1830889) [DELL EMC 7.8 BUG bnxten] Error messages related to hwrm observed for BCM 57504 under dmesg in RHEL 7.8 (BZ#1834190) kernel: provide infrastructure to support dual-signing of the kernel (foundation to help address CVE-2020-10713) (BZ#1837429) RHEL7.7 - Request: retrofit kernel commit f82b4b6 to RHEL 7.7/7.8 3.10 kernels. (BZ#1838602) kipmi thread high CPU consumption when performing BMC firmware upgrade (BZ#1841825) RHEL7.7 - virtio-blk: fix hwqueue stopped on arbitrary error (kvm) (BZ#1842994) rhel 7 infinite blocked waiting on inodediowait in nfs (BZ#1845520) http request is taking more time for endpoint running on different host via nodeport service (BZ#1847333) ext4: change LRU to round-robin in extent status tree shrinker (BZ#1847343) libaio is returning duplicate events (BZ#1850055) After upgrade to 3.9.89 pod containers with CPU limits fail to start due to cgroup error (BZ#1850500) Fix dpdk regression introduced by bz1837297 (BZ#1852245)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/kernel-abi-whiteliststo a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/kernel-docto a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/python-perfto a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/python-perf-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-s390xto a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/kernel-kdumpto a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/kernel-kdump-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/kernel-kdump-develto a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/kernel-bootwrapperto a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64to a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64leto a version that resolves this vulnerability.Fixed in 3.10.0-1127.18.2.el7
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:3220?
The severity of RHSA-2020:3220 is classified as important.
How do I fix RHSA-2020:3220?
To fix RHSA-2020:3220, update the kernel and associated packages to the version 3.10.0-1127.18.2.el7.
What vulnerabilities are addressed by RHSA-2020:3220?
RHSA-2020:3220 addresses vulnerabilities including CVE-2020-10757 related to DAX hugepages and a buffer overflow in the mwifiex_cmd_append_vsie_tlv function.
Which packages are affected by RHSA-2020:3220?
Affected packages include kernel, bpftool, and kernel-debug among others, specifically in the version 3.10.0-1127.18.2.el7.
Is there a specific update needed for RHSA-2020:3220?
Yes, you need to update to the specific kernel version 3.10.0-1127.18.2.el7 to mitigate the vulnerabilities.