RHSA-2020:1769HighCVSS 8.4

Red Hat Security Advisory: kernel security, bug fix, and enhancement update

Published
April 28, 2020
Last Modified
August 13, 2026

🔗 CVE IDs covered (37)

📋 Description

CVE-2018-16871 — kernel: nfs: NULL pointer dereference due to an anomalized NFS message sequence CVE-2019-5108 — kernel: triggering AP to send IAPP location updates for stations before the required authentication process has completed can lead to DoS CVE-2019-8980 — kernel: memory leak in the kernel_read_file function in fs/exec.c allows to cause a denial of service CVE-2019-10639 — Kernel: net: using kernel space address bits to derive IP ID may potentially break KASLR CVE-2019-12819 — kernel: use-after-free in function __mdiobus_register() in drivers/net/phy/mdio_bus.c CVE-2019-15090 — kernel: An out-of-bounds read in drivers/scsi/qedi/qedi_dbg.c leading to crash or information disclosure CVE-2019-15099 — kernel: a NULL pointer dereference in drivers/net/wireless/ath/ath10k/usb.c leads to a crash CVE-2019-15221 — kernel: Null pointer dereference in the sound/usb/line6/pcm.c CVE-2019-15223 — kernel: Null pointer dereference in the sound/usb/line6/driver.c CVE-2019-16234 — kernel: null pointer dereference in drivers/net/wireless/intel/iwlwifi/pcie/trans.c CVE-2019-16746 — kernel: buffer-overflow hardening in WiFi beacon validation code. CVE-2019-17053 — kernel: unprivileged users able to create RAW sockets in AF_IEEE802154 network protocol CVE-2019-17055 — kernel: unprivileged users able to create RAW sockets in AF_ISDN network protocol CVE-2019-18282 — kernel: The flow_dissector feature allows device tracking CVE-2019-18805 — kernel: integer overflow in tcp_ack_update_rtt in net/ipv4/tcp_input.c CVE-2019-19045 — kernel: dos in mlx5_fpga_conn_create_cq() function in drivers/net/ethernet/mellanox/mlx5/core/fpga/conn.c CVE-2019-19047 — kernel: dos in mlx5_fw_fatal_reporter_dump() function in drivers/net/ethernet/mellanox/mlx5/core/health.c CVE-2019-19055 — kernel: memory leak in the nl80211_get_ftm_responder_stats() function in net/wireless/nl80211.c allows DoS CVE-2019-19057 — kernel: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in drivers/net/wireless/marvell/mwifiex/pcie.c allows for a DoS CVE-2019-19058 — kernel: A memory leak in the alloc_sgtable() function in drivers/net/wireless/intel/iwlwifi/fw/dbg.c allows for a DoS CVE-2019-19059 — kernel: Multiple memory leaks in the iwl_pcie_ctxt_info_gen3_init() function in drivers/net/wireless/intel/iwlwifi/pcie/ctxt-info-gen3.c allows for a DoS CVE-2019-19065 — kernel: A memory leak in the sdma_init() function in drivers/infiniband/hw/hfi1/sdma.c allows for a DoS CVE-2019-19067 — kernel: Four memory leaks in the acp_hw_init() function in drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c allow for a DoS CVE-2019-19073 — kernel: Memory leaks in drivers/net/wireless/ath/ath9k/htc_hst.c in the Linux kernel (DOS) CVE-2019-19074 — kernel: a memory leak in the ath9k management function in allows local DoS CVE-2019-19077 — kernel: memory leak in bnxt_re_create_srq function in drivers/infiniband/hw/bnxt_re/ib_verbs.c CVE-2019-19532 — kernel: malicious USB devices can lead to multiple out-of-bounds write CVE-2019-19534 — kernel: information leak bug caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c driver CVE-2019-19768 — kernel: use-after-free in __blk_add_trace in kernel/trace/blktrace.c CVE-2019-19922 — kernel: when cpu.cfs_quota_us is used allows attackers to cause a denial of service against non-cpu-bound applications CVE-2020-1749 — kernel: some ipv6 protocols not encrypted over ipsec tunnel CVE-2020-7053 — kernel: use-after-free in i915_ppgtt_close in drivers/gpu/drm/i915/i915_gem_gtt.c CVE-2020-10690 — kernel: use-after-free in cdev_put() when a PTP device is removed while it's chardev is open CVE-2021-33630 — kernel: net/sched: cbs NULL pointer dereference when offloading is enabled CVE-2022-50473 — kernel: cpufreq: Init completion before kobject_init_and_add() CVE-2023-53581 — kernel: net/mlx5e: Check for NOT_READY flag state after locking CVE-2023-54064 — kernel: Kernel: Memory leak in IPMI SSIF module leads to Denial of Service

🎯 Affected products122

  • Red Hat CodeReady Linux Builder (v. 8)
  • Red Hat Enterprise Linux BaseOS (v. 8)
  • bpftool-0:4.18.0-193.el8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • bpftool-0:4.18.0-193.el8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • bpftool-0:4.18.0-193.el8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • bpftool-0:4.18.0-193.el8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • bpftool-debuginfo-0:4.18.0-193.el8.aarch64 as a component of Red Hat CodeReady Linux Builder (v. 8)
  • bpftool-debuginfo-0:4.18.0-193.el8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • bpftool-debuginfo-0:4.18.0-193.el8.ppc64le as a component of Red Hat CodeReady Linux Builder (v. 8)
  • bpftool-debuginfo-0:4.18.0-193.el8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • bpftool-debuginfo-0:4.18.0-193.el8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • bpftool-debuginfo-0:4.18.0-193.el8.x86_64 as a component of Red Hat CodeReady Linux Builder (v. 8)
  • bpftool-debuginfo-0:4.18.0-193.el8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • kernel-0:4.18.0-193.el8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • kernel-0:4.18.0-193.el8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • kernel-0:4.18.0-193.el8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • kernel-0:4.18.0-193.el8.src as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • kernel-0:4.18.0-193.el8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • kernel-abi-whitelists-0:4.18.0-193.el8.noarch as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • kernel-core-0:4.18.0-193.el8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • kernel-core-0:4.18.0-193.el8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • kernel-core-0:4.18.0-193.el8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • kernel-core-0:4.18.0-193.el8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • kernel-debug-0:4.18.0-193.el8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • kernel-debug-0:4.18.0-193.el8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • kernel-debug-0:4.18.0-193.el8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • kernel-debug-0:4.18.0-193.el8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • kernel-debug-core-0:4.18.0-193.el8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • kernel-debug-core-0:4.18.0-193.el8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • kernel-debug-core-0:4.18.0-193.el8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • +92 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: At this time there is no known mitigations to this issue other than to install the updated kernel package. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: As the ath10k module will be auto-loaded when required, its use can be disabled by preventing the module from loading using the following instructions. On the command line, as root, execute the following command: # echo "install ath10k_usb /bin/true" >> /etc/modprobe.d/disable-ath10k_usb.conf The system will need to be restarted if the ath10k_usb module are loaded. In most circumstances, the kernel modules will be unable to be unloaded while the ath10k WiFi network interface is in use. If the system requires this module to work correctly, this mitigation may not be suitable. If you need further assistance, see KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services. Workaround: To mitigate this issue, prevent module snd-usb-line6 from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: At this time the only known way to 'mitigate' this flaw is to blacklist the kernel module from being loaded. Creating raw sockets with this protocol is a method of communicating with ISDN hardware, a technology that is becoming less and less common. Check https://access.redhat.com/solutions/41278 for instructions on how to disable the mISDN_core.ko module. Workaround: This flaw can be mitigated by setting the sysctl parameter (/proc/sys/net/ipv4/tcp_min_rtt_wlen) with 300 which means the packet time will not exceed more then 5 minutes and which should not cause an integer overflow. Workaround: In order to mitigate this issue it is possible to prevent the affected code from being loaded by blacklisting the kernel module mlx5_core. For instructions relating to how to blacklist a kernel module refer to: https://access.redhat.com/solutions/41278 . Workaround: In order to mitigate this issue it is possible to prevent the affected code from being loaded by blacklisting the kernel module cfg80211. For instructions relating to how to blacklist a kernel module refer to: https://access.redhat.com/solutions/41278 . Workaround: In order to mitigate this issue it is possible to prevent the affected code from being loaded by blacklisting the kernel module iwlmvm. For instructions relating to how to blacklist a kernel module refer to: https://access.redhat.com/solutions/41278 . Workaround: In order to mitigate this issue it is possible to prevent the affected code from being loaded by blacklisting the kernel module iwlwifi. For instructions relating to how to blacklist a kernel module refer to: https://access.redhat.com/solutions/41278 . Workaround: In order to mitigate this issue it is possible to prevent the affected code from being loaded by blacklisting the kernel module hfi1. For instructions relating to how to blacklist a kernel module refer to: https://access.redhat.com/solutions/41278 . Workaround: In order to mitigate this issue it is possible to prevent the affected code from being loaded by blacklisting the kernel module bnxt_re. For instructions relating to how to blacklist a kernel module refer to: https://access.redhat.com/solutions/41278 . Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: As the devices module will be auto-loaded when the USB CAN bus adapter is connected, its can be disabled by preventing the module from loading with the following instructions: # echo "install peak_usb /bin/true" >> /etc/modprobe.d/disable-peak-usb-canbus.conf The system will need to be restarted if the peak_usb module is already loaded. In most circumstances, the kernel modules will be unable to be unloaded while any CAN bus interfaces are active and the protocol is in use. If the system requires this module to work correctly, this mitigation may not be suitable. If you need further assistance, see KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services. Workaround: Disabling the IPV6 protocol may be a suitable workaround for systems that do not require the protocol to function correctly, however, if IPV6 is not in use this flaw will not be triggered. Workaround: In case of dedicated graphic card presence and i915 GPU is not being used, you can prevent module i915 from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent the mlx5_core module from loading. See https://access.redhat.com/solutions/41278 for instructions on blacklisting kernel modules.

🔗 References (31)