RHSA-2020:4287: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operating system.<br>Security Fix(es):<br><li> kernel: net: bluetooth: type confusion while processing AMP packets (CVE-2020-12351)</li> <li> kernel: net: bluetooth: information leak when processing certain AMP packets (CVE-2020-12352)</li> <li> kernel: metadata validator in XFS may cause an inode with a valid, user-creatable extended attribute to be flagged as corrupt (CVE-2020-14385)</li> <li> kernel: memory corruption in net/packet/afpacket.c leads to elevation of privilege (CVE-2020-14386)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> NFS client autodisconnect timer may fire immediately after TCP connection setup and may cause DoS type reconnect problem in complex network environments (BZ#1873571)</li> <li> hang on full fs from tracecmd (BZ#1875789)</li> <li> Secure boot key is not loaded with kernel-4.18.0-232.el8.x8664 / shim-x64-15-15 (BZ#1877527)</li> <li> [RHEL-8.3] Kdump failed to start when secure boot enabled: kexecfileload failed: Required key not available (BZ#1877529)</li> <li> [RHEL-8.3] Kdump/kexec kernel panicked on EFI boot: general protection fault: 0000 [#1] SMP PTI (BZ#1879987)</li> <li> [conntrack] udp packet reverse NAT occasionally fail when race condition request combination with the DNAT load balancing rules (BZ#1882096)</li> <li> [Regression] RHEL8.3 Beta - Do not initiate shutdown for EPOWSHUTDOWNONUPS event (BZ#1882244)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:4287?
The severity of RHSA-2020:4287 is classified as important due to potential security risks regarding Bluetooth operations.
How do I fix RHSA-2020:4287?
To fix RHSA-2020:4287, you should update the kernel and related packages to version 4.18.0-147.32.1.el8_1.
What vulnerabilities does RHSA-2020:4287 address?
RHSA-2020:4287 addresses vulnerabilities including CVE-2020-12351 which relates to type confusion in Bluetooth processing.
What systems are affected by RHSA-2020:4287?
RHSA-2020:4287 affects Red Hat Enterprise Linux 8 systems running the specified kernel version.
Is there a workaround for the vulnerabilities in RHSA-2020:4287?
There are currently no recommended workarounds for the vulnerabilities addressed by RHSA-2020:4287; updating is advised.