RHSA-2020:3221: Important: kernel-rt security and bug fix update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): kernel: kernel: DAX hugepages not considered during mremap (CVE-2020-10757) kernel: buffer overflow in mwifiexcmdappendvsietlv function in drivers/net/wireless/marvell/mwifiex/scan.c (CVE-2020-12653) kernel: heap-based buffer overflow in mwifiexretwmmgetstatus function in drivers/net/wireless/marvell/mwifiex/wmm.c (CVE-2020-12654) kernel: use-after-free caused by a malicious USB device in the drivers/hid/usbhid/hiddev.c driver (CVE-2019-19527) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): kernel-rt: provide infrastructure to support dual-signing of the kernel (foundation to help address CVE-2020-10713) (BZ#1837438) kernel-rt: update to the latest RHEL7.8.z3 source tree (BZ#1848017)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:3221?
The severity of RHSA-2020:3221 is critical due to multiple security vulnerabilities affecting the kernel-rt packages.
How do I fix RHSA-2020:3221?
To fix RHSA-2020:3221, upgrade to kernel-rt version 3.10.0-1127.18.2.rt56.1116.el7 or later.
What vulnerabilities are addressed in RHSA-2020:3221?
RHSA-2020:3221 addresses vulnerabilities including CVE-2020-10757 and various buffer overflow issues.
Which packages are affected by RHSA-2020:3221?
Affected packages include kernel-rt, kernel-rt-debug, and kernel-rt-trace among others.
Is it safe to continue using the affected versions listed in RHSA-2020:3221?
No, using the affected versions exposes your system to security risks and it is recommended to apply the update immediately.