RHSA-2020:3389: Important: kernel-rt security and bug fix update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): kernel: buffer overflow in mwifiexcmdappendvsietlv function in drivers/net/wireless/marvell/mwifiex/scan.c (CVE-2020-12653) kernel: heap-based buffer overflow in mwifiexretwmmgetstatus function in drivers/net/wireless/marvell/mwifiex/wmm.c (CVE-2020-12654) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): update the MRG 2.5.z 3.10 realtime-kernel sources (BZ#1858091)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:3389?
The severity of RHSA-2020:3389 is classified as important.
How do I fix RHSA-2020:3389?
To fix RHSA-2020:3389, update to the kernel-rt package version 3.10.0-693.72.1.rt56.672.el6.
Which packages are affected by RHSA-2020:3389?
The affected packages include kernel-rt, kernel-rt-debug, kernel-rt-debug-debuginfo, and several others related to the Real Time Linux Kernel.
What vulnerability does RHSA-2020:3389 address?
RHSA-2020:3389 addresses a buffer overflow vulnerability in the mwifiex_cmd_append_vsie_tlv function within the Linux kernel.
How can I verify if I'm affected by RHSA-2020:3389?
You can verify if you're affected by comparing your installed kernel-rt package version to the vulnerable version prior to updating.