RHSA-2020:4280: Important: kernel-rt security update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.<br>Security Fix(es):<br><li> kernel: net: bluetooth: type confusion while processing AMP packets (CVE-2020-12351)</li> <li> kernel: net: bluetooth: information leak when processing certain AMP packets (CVE-2020-12352)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:4280?
The severity of RHSA-2020:4280 is classified as critical due to potential remote code execution vulnerabilities in the Real Time Linux Kernel.
How do I fix RHSA-2020:4280?
To fix RHSA-2020:4280, update kernel-rt and dependent packages to the version 3.10.0-1160.2.2.rt56.1134.el7.
Which packages are affected by RHSA-2020:4280?
The affected packages include kernel-rt, kernel-rt-debug, and several kernel-rt related development and debug packages.
What vulnerabilities are addressed in RHSA-2020:4280?
RHSA-2020:4280 addresses a type confusion vulnerability in Bluetooth while processing AMP packets, identified as CVE-2020-12351.
Can I continue using my system with RHSA-2020:4280 unpatched?
Using your system without applying the patch for RHSA-2020:4280 is risky and can expose your system to critical vulnerabilities.