RHSA-2021:0336: Moderate: kernel security, bug fix, and enhancement update
The kernel packages contain the Linux kernel, the core of any Linux operating system.<br>Security Fix(es):<br><li> kernel: use-after-free in fs/blockdev.c (CVE-2020-15436)</li> <li> kernel: Nfsd failure to clear umask after processing an open or create (CVE-2020-35513)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> double free issue in filelayoutalloccommitinfo (BZ#1679980)</li> <li> Regression: Plantronics Device SHS2355-11 PTT button does not work after update to 7.7 (BZ#1769502)</li> <li> Openstack network node reports unregisternetdevice: waiting for qr-3cec0c92-9a to become free. Usage count = 1 (BZ#1809519)</li> <li> dlm: add ability to interrupt waiting for acquire POSIX lock (BZ#1826858)</li> <li> [Azure][RHEL7] soft lockups and performance loss occurring during final fsync with parallel dd writes to xfs filesystem in azure instance (BZ#1859364)</li> <li> Guest crashed when hotplug vcpus on booting kernel stage (BZ#1866138)</li> <li> soft lockup occurs while a thread group leader is waiting on tasklistwaiters in mmupdatenextowner() where a huge number of the thread group members are exiting and trying to take the tasklistlock. (BZ#1872110)</li> <li> [DELL EMC 7.6 BUG] Kioxia CM6 NVMe drive fails to enumerate (BZ#1883403)</li> <li> [Hyper-V][RHEL7] Request to included a commit that adds a timeout to vmbuswaitforunload (BZ#1888979)</li> <li> Unable to discover the LUNs from new storage port (BZ#1889311)</li> <li> RHEL 7.9 Kernel panic at cephputsnaprealm+0x21 (BZ#1890386)</li> <li> A hard lockup occurrs where one task is looping in an sklock spinlock that has been taken by another task running timespec64addns(). (BZ#1890911)</li> <li> ethtool/mlx5core provides incorrect SFP module info (BZ#1896756)</li> <li> RHEL7.7 - zcrypt: Fix ZCRYPTPERDEVREQCNT ioctl (BZ#1896826)</li> <li> RHEL7.7 - s390/dasd: Fix zero write for FBA devices (BZ#1896839)</li> <li> [Azure]IP forwarding issue in netvsc[7.9.z] (BZ#1898280)</li> <li> Security patch for CVE-2020-25212 breaks directory listings via 'ls' on NFS V4.2 shares mounted with selinux enabled labels (BZ#1917504)</li> Enhancement(s):<br><li> RFE : handle better ERRbaduid on SMB1 (BZ#1847041)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:0336?
The severity of RHSA-2021:0336 is critical due to multiple vulnerabilities in the Linux kernel that can lead to system compromises.
How do I fix RHSA-2021:0336?
To fix RHSA-2021:0336, update the affected packages to version 3.10.0-1160.15.2.el7 or later.
What vulnerabilities are addressed in RHSA-2021:0336?
RHSA-2021:0336 addresses vulnerabilities including a use-after-free issue in fs/block_dev.c and Nfsd failure to clear umask.
Which software is affected by RHSA-2021:0336?
RHSA-2021:0336 affects various packages including kernel, bpftool, kernel-debuginfo, and others within the specified version.
Is RHSA-2021:0336 applicable to all Linux distributions?
No, RHSA-2021:0336 specifically applies to Red Hat Enterprise Linux and its derivatives.