RHSA-2021:0526: Moderate: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operating system.<br>Security Fix(es):<br><li> kernel: umask not applied on filesystem without ACL support (CVE-2020-24394)</li> <li> kernel: TOCTOU mismatch in the NFS client code (CVE-2020-25212)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> Security patch for CVE-2020-25212 breaks directory listings via 'ls' on NFS V4.2 shares mounted with selinux enabled labels (BZ#1919145)</li> <li> Panic in semctlnolock.constprop.15+0x25b (BZ#1919307)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:0526?
RHSA-2021:0526 has a moderate severity rating.
How do I fix RHSA-2021:0526?
To fix RHSA-2021:0526, upgrade the affected kernel packages to version 3.10.0-1062.45.1.el7 or higher.
Which kernel vulnerabilities are addressed in RHSA-2021:0526?
RHSA-2021:0526 addresses CVE-2020-24394 and CVE-2020-25212 vulnerabilities.
What packages are affected by RHSA-2021:0526?
The affected packages include kernel, bpftool, and several kernel-related packages in versions below 3.10.0-1062.45.1.el7.
Is kernel version 3.10.0-1062.45.1.el7 vulnerable to RHSA-2021:0526?
No, kernel version 3.10.0-1062.45.1.el7 is not vulnerable as it contains the fixes for the issues addressed in RHSA-2021:0526.