RHSA-2021:0878: Important: kernel security, bug fix, and enhancement update
The kernel packages contain the Linux kernel, the core of any Linux operating system.<br>Security Fix(es):<br><li> kernel: locking issue in drivers/tty/ttyjobctrl.c can lead to an use-after-free (CVE-2020-29661)</li> <li> kernel: performance counters race condition use-after-free (CVE-2020-14351)</li> <li> kernel: umask not applied on filesystem without ACL support (CVE-2020-24394)</li> <li> kernel: TOCTOU mismatch in the NFS client code (CVE-2020-25212)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> Security patch for CVE-2020-25212 breaks directory listings via 'ls' on NFS V4.2 shares mounted with selinux enabled labels (BZ#1919144)</li> <li> Enable CI and changelog for GitLab workflow (BZ#1930931)</li> Enhancement(s):<br><li> [Cavium 7.7 Feat] qla2xxx: Update to latest upstream. (BZ#1918534)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:0878?
The severity of RHSA-2021:0878 is classified as important due to the potential for use-after-free vulnerabilities.
How do I fix RHSA-2021:0878?
To fix RHSA-2021:0878, you should update your kernel packages to version 3.10.0-957.70.1.el7.
What vulnerabilities are addressed in RHSA-2021:0878?
RHSA-2021:0878 addresses use-after-free vulnerabilities in the kernel related to tty job control and performance counters.
Which software packages are affected by RHSA-2021:0878?
Software packages affected by RHSA-2021:0878 include kernel, bpftool, and various kernel-debug and kernel-tools packages.
When was RHSA-2021:0878 released?
RHSA-2021:0878 was released on April 27, 2021.