Red Hat Security Advisory: kernel-rt security and bug fix update
🔗 CVE IDs covered (27)
📋 Description
CVE-2019-19523 — kernel: use-after-free caused by a malicious USB device in the drivers/usb/misc/adutux.c driver CVE-2019-19528 — kernel: use-after-free bug caused by a malicious USB device in the drivers/usb/misc/iowarrior.c driver CVE-2020-0431 — kernel: possible out of bounds write in kbd_keycode of keyboard.c CVE-2020-11608 — kernel: NULL pointer dereferences in ov511_mode_init_regs and ov518_mode_init_regs in drivers/media/usb/gspca/ov519.c CVE-2020-12114 — kernel: DoS by corrupting mountpoint reference counter CVE-2020-12362 — kernel: Integer overflow in Intel(R) Graphics Drivers CVE-2020-12363 — kernel: Improper input validation in some Intel(R) Graphics Drivers CVE-2020-12364 — kernel: Null pointer dereference in some Intel(R) Graphics Drivers CVE-2020-12464 — kernel: use-after-free in usb_sg_cancel function in drivers/usb/core/message.c CVE-2020-14314 — kernel: buffer uses out of index in ext3/4 filesystem CVE-2020-14356 — kernel: Use After Free vulnerability in cgroup BPF component CVE-2020-15437 — kernel: NULL pointer dereference in serial8250_isa_init_ports function in drivers/tty/serial/8250/8250_core.c CVE-2020-24394 — kernel: umask not applied on filesystem without ACL support CVE-2020-25212 — kernel: TOCTOU mismatch in the NFS client code CVE-2020-25284 — kernel: incomplete permission checking for access to rbd devices CVE-2020-25285 — kernel: race condition between hugetlb sysctl handlers in mm/hugetlb.c CVE-2020-25643 — kernel: improper input validation in ppp_cp_parse_cr function leads to memory corruption and read overflow CVE-2020-25704 — kernel: perf_event_parse_addr_filter memory CVE-2020-27786 — kernel: use-after-free in kernel midi subsystem CVE-2020-27835 — kernel: child process is able to access parent mm through hfi dev file handle CVE-2020-28974 — kernel: slab-out-of-bounds read in fbcon CVE-2020-35508 — kernel: fork: fix copy_process(CLONE_PARENT) race with the exiting ->real_parent CVE-2020-36694 — kernel: netfilter: use-after-free in the packet processing context CVE-2021-0342 — kernel: use after free in tun_get_user of tun.c could lead to local escalation of privilege CVE-2021-0605 — kernel: In pfkey_dump() dplen and splen can both be specified to access the xfrm_address_t structure out of bounds CVE-2021-3428 — kernel: integer overflow in ext4_es_cache_extent CVE-2023-1390 — kernel: remote DoS in TIPC kernel module
🔗 References (29)
- selfhttps://access.redhat.com/errata/RHSA-2021:1739
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.4_release_notes/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1783434
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1783507
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1831726
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1833445
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1848652
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1853922
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1868453
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1869141
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1877575
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1879981
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1882591
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1882594
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1886109
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1894793
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1895961
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1896842
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1897869
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1900933
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1901161
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1901709
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1902724
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1903126
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1915799
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1919889
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1930246
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_1739.json