RHSA-2020:5430: Moderate: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: out of bounds write in function i2csmbusxferemulated in drivers/i2c/i2c-core-smbus.c (CVE-2017-18551) kernel: out of bounds write in i2c driver leads to local escalation of privilege (CVE-2019-9454) kernel: mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use-after-free in ext4putsuper in fs/ext4/super.c (CVE-2019-19447) kernel: out-of-bounds write via crafted keycode table (CVE-2019-20636) kernel: sgwrite function lacks an sgremoverequest call in a certain failure case (CVE-2020-12770) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Secure boot key is not loaded with kernel-3.10.0-1159.el7: MODSIGN: Couldn't get UEFI MokListRT (BZ#1876951) RHEL7.6: no-carrier configured interfaces causes soft lockups by mount.nfs and hang booting/shutdown process (BZ#1889770) [Intel Bug]: hrtimer (rdmavt RNR timer) was lost sometimes (BZ#1892996)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:5430?
The severity of RHSA-2020:5430 is high due to out of bounds write vulnerabilities that could lead to privilege escalation.
How do I fix RHSA-2020:5430?
To fix RHSA-2020:5430, update the kernel and associated packages to version 3.10.0-693.81.1.el7 or later.
What vulnerabilities are addressed in RHSA-2020:5430?
RHSA-2020:5430 addresses out of bounds write vulnerabilities, specifically CVE-2017-18551 in the i2c driver.
Which packages are affected by RHSA-2020:5430?
The affected packages include kernel, kernel-debug, kernel-devel, and others associated with the Linux kernel versions before 3.10.0-693.81.1.el7.
Is there a workaround for RHSA-2020:5430?
There is no official workaround for RHSA-2020:5430, so applying the update is recommended.