RHSA-2020:3224: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operating system.<br>Security Fix(es):<br><li> kernel: buffer overflow in mwifiexcmdappendvsietlv function in drivers/net/wireless/marvell/mwifiex/scan.c (CVE-2020-12653)</li> <li> kernel: heap-based buffer overflow in mwifiexretwmmgetstatus function in drivers/net/wireless/marvell/mwifiex/wmm.c (CVE-2020-12654)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> kernel: provide infrastructure to support dual-signing of the kernel (foundation to help address CVE-2020-10713) (BZ#1837428)</li> <li> RHEL7.7 - Request: retrofit kernel commit f82b4b6 to RHEL 7.7/7.8 3.10 kernels. (BZ#1838601)</li> <li> Possible race condition updating the cfg structure in assignirqvector. (BZ#1854553)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:3224?
The severity of RHSA-2020:3224 is rated as important.
How do I fix RHSA-2020:3224?
To fix RHSA-2020:3224, upgrade the affected kernel packages to version 3.10.0-1062.31.2.el7 or later.
What vulnerabilities are addressed in RHSA-2020:3224?
RHSA-2020:3224 addresses vulnerabilities, including a buffer overflow in mwifiex_cmd_append_vsie_tlv function (CVE-2020-12653).
Which packages are affected by RHSA-2020:3224?
Affected packages by RHSA-2020:3224 include kernel, bpftool, and kernel-debug among others.
When was RHSA-2020:3224 released?
RHSA-2020:3224 was released in response to vulnerabilities discovered in the Linux kernel.