[ALSA-2021:1578] kernel security, bug fix, and enhancement update

Severity Important
Affected Packages 38
CVEs 26

An update for kernel is now available for AlmaLinux AlmaLinux Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: Integer overflow in Intel(R) Graphics Drivers (CVE-2020-12362)

  • kernel: memory leak in sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c (CVE-2019-18811)

  • kernel: use-after-free caused by a malicious USB device in the drivers/usb/misc/adutux.c driver (CVE-2019-19523)

  • kernel: use-after-free bug caused by a malicious USB device in the drivers/usb/misc/iowarrior.c driver (CVE-2019-19528)

  • kernel: possible out of bounds write in kbd_keycode of keyboard.c (CVE-2020-0431)

  • kernel: DoS by corrupting mountpoint reference counter (CVE-2020-12114)

  • kernel: use-after-free in usb_sg_cancel function in drivers/usb/core/message.c (CVE-2020-12464)

  • kernel: buffer uses out of index in ext3/4 filesystem (CVE-2020-14314)

  • kernel: Use After Free vulnerability in cgroup BPF component (CVE-2020-14356)

  • kernel: NULL pointer dereference in serial8250_isa_init_ports function in drivers/tty/serial/8250/8250_core.c (CVE-2020-15437)

  • kernel: umask not applied on filesystem without ACL support (CVE-2020-24394)

  • kernel: TOCTOU mismatch in the NFS client code (CVE-2020-25212)

  • kernel: incomplete permission checking for access to rbd devices (CVE-2020-25284)

  • kernel: race condition between hugetlb sysctl handlers in mm/hugetlb.c (CVE-2020-25285)

  • kernel: improper input validation in ppp_cp_parse_cr function leads to memory corruption and read overflow (CVE-2020-25643)

  • kernel: perf_event_parse_addr_filter memory (CVE-2020-25704)

  • kernel: use-after-free in kernel midi subsystem (CVE-2020-27786)

  • kernel: child process is able to access parent mm through hfi dev file handle (CVE-2020-27835)

  • kernel: slab-out-of-bounds read in fbcon (CVE-2020-28974)

  • kernel: fork: fix copy_process(CLONE_PARENT) race with the exiting ->real_parent (CVE-2020-35508)

  • kernel: fuse: fuse_do_getattr() calls make_bad_inode() in inappropriate situations (CVE-2020-36322)

  • kernel: use after free in tun_get_user of tun.c could lead to local escalation of privilege (CVE-2021-0342)

  • kernel: NULL pointer dereferences in ov511_mode_init_regs and ov518_mode_init_regs in drivers/media/usb/gspca/ov519.c (CVE-2020-11608)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

Package Affected Version
pkg:rpm/almalinux/python3-perf?arch=x86_64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/python3-perf?arch=aarch64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/perf?arch=x86_64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/perf?arch=aarch64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel?arch=x86_64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel?arch=aarch64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-tools?arch=x86_64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-tools?arch=aarch64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-tools-libs?arch=x86_64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-tools-libs?arch=aarch64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-tools-libs-devel?arch=x86_64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-tools-libs-devel?arch=aarch64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-modules?arch=x86_64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-modules?arch=aarch64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-modules-extra?arch=x86_64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-modules-extra?arch=aarch64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-headers?arch=x86_64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-headers?arch=aarch64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-doc?arch=noarch&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-devel?arch=x86_64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-devel?arch=aarch64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-debug?arch=x86_64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-debug?arch=aarch64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-debug-modules?arch=x86_64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-debug-modules?arch=aarch64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-debug-modules-extra?arch=x86_64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-debug-modules-extra?arch=aarch64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-debug-devel?arch=x86_64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-debug-devel?arch=aarch64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-debug-core?arch=x86_64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-debug-core?arch=aarch64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-cross-headers?arch=x86_64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-cross-headers?arch=aarch64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-core?arch=x86_64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-core?arch=aarch64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/kernel-abi-stablelists?arch=noarch&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/bpftool?arch=x86_64&distro=almalinux-8 < 4.18.0-305.el8
pkg:rpm/almalinux/bpftool?arch=aarch64&distro=almalinux-8 < 4.18.0-305.el8
ID
ALSA-2021:1578
Severity
important
URL
https://errata.almalinux.org/ALSA-2021:1578.html
Published
2021-05-18T05:33:57
(3 years ago)
Modified
2021-08-11T08:54:00
(3 years ago)
Rights
Copyright 2021 AlmaLinux OS
Other Advisories
Source # ID Name URL
CVE CVE-2019-18811 https://vulners.com/cve/CVE-2019-18811
CVE CVE-2019-19523 https://vulners.com/cve/CVE-2019-19523
CVE CVE-2019-19528 https://vulners.com/cve/CVE-2019-19528
CVE CVE-2020-0431 https://vulners.com/cve/CVE-2020-0431
CVE CVE-2020-11608 https://vulners.com/cve/CVE-2020-11608
CVE CVE-2020-12114 https://vulners.com/cve/CVE-2020-12114
CVE CVE-2020-12362 https://vulners.com/cve/CVE-2020-12362
CVE CVE-2020-12363 https://vulners.com/cve/CVE-2020-12363
CVE CVE-2020-12364 https://vulners.com/cve/CVE-2020-12364
CVE CVE-2020-12464 https://vulners.com/cve/CVE-2020-12464
CVE CVE-2020-14314 https://vulners.com/cve/CVE-2020-14314
CVE CVE-2020-14356 https://vulners.com/cve/CVE-2020-14356
CVE CVE-2020-15437 https://vulners.com/cve/CVE-2020-15437
CVE CVE-2020-24394 https://vulners.com/cve/CVE-2020-24394
CVE CVE-2020-25212 https://vulners.com/cve/CVE-2020-25212
CVE CVE-2020-25284 https://vulners.com/cve/CVE-2020-25284
CVE CVE-2020-25285 https://vulners.com/cve/CVE-2020-25285
CVE CVE-2020-25643 https://vulners.com/cve/CVE-2020-25643
CVE CVE-2020-25704 https://vulners.com/cve/CVE-2020-25704
CVE CVE-2020-27786 https://vulners.com/cve/CVE-2020-27786
CVE CVE-2020-27835 https://vulners.com/cve/CVE-2020-27835
CVE CVE-2020-28974 https://vulners.com/cve/CVE-2020-28974
CVE CVE-2020-35508 https://vulners.com/cve/CVE-2020-35508
CVE CVE-2020-36322 https://vulners.com/cve/CVE-2020-36322
CVE CVE-2021-0342 https://vulners.com/cve/CVE-2021-0342
CVE CVE-2021-0605 https://vulners.com/cve/CVE-2021-0605
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/almalinux/python3-perf?arch=x86_64&distro=almalinux-8 almalinux python3-perf < 4.18.0-305.el8 almalinux-8 x86_64
Affected pkg:rpm/almalinux/python3-perf?arch=aarch64&distro=almalinux-8 almalinux python3-perf < 4.18.0-305.el8 almalinux-8 aarch64
Affected pkg:rpm/almalinux/perf?arch=x86_64&distro=almalinux-8 almalinux perf < 4.18.0-305.el8 almalinux-8 x86_64
Affected pkg:rpm/almalinux/perf?arch=aarch64&distro=almalinux-8 almalinux perf < 4.18.0-305.el8 almalinux-8 aarch64
Affected pkg:rpm/almalinux/kernel?arch=x86_64&distro=almalinux-8 almalinux kernel < 4.18.0-305.el8 almalinux-8 x86_64
Affected pkg:rpm/almalinux/kernel?arch=aarch64&distro=almalinux-8 almalinux kernel < 4.18.0-305.el8 almalinux-8 aarch64
Affected pkg:rpm/almalinux/kernel-tools?arch=x86_64&distro=almalinux-8 almalinux kernel-tools < 4.18.0-305.el8 almalinux-8 x86_64
Affected pkg:rpm/almalinux/kernel-tools?arch=aarch64&distro=almalinux-8 almalinux kernel-tools < 4.18.0-305.el8 almalinux-8 aarch64
Affected pkg:rpm/almalinux/kernel-tools-libs?arch=x86_64&distro=almalinux-8 almalinux kernel-tools-libs < 4.18.0-305.el8 almalinux-8 x86_64
Affected pkg:rpm/almalinux/kernel-tools-libs?arch=aarch64&distro=almalinux-8 almalinux kernel-tools-libs < 4.18.0-305.el8 almalinux-8 aarch64
Affected pkg:rpm/almalinux/kernel-tools-libs-devel?arch=x86_64&distro=almalinux-8 almalinux kernel-tools-libs-devel < 4.18.0-305.el8 almalinux-8 x86_64
Affected pkg:rpm/almalinux/kernel-tools-libs-devel?arch=aarch64&distro=almalinux-8 almalinux kernel-tools-libs-devel < 4.18.0-305.el8 almalinux-8 aarch64
Affected pkg:rpm/almalinux/kernel-modules?arch=x86_64&distro=almalinux-8 almalinux kernel-modules < 4.18.0-305.el8 almalinux-8 x86_64
Affected pkg:rpm/almalinux/kernel-modules?arch=aarch64&distro=almalinux-8 almalinux kernel-modules < 4.18.0-305.el8 almalinux-8 aarch64
Affected pkg:rpm/almalinux/kernel-modules-extra?arch=x86_64&distro=almalinux-8 almalinux kernel-modules-extra < 4.18.0-305.el8 almalinux-8 x86_64
Affected pkg:rpm/almalinux/kernel-modules-extra?arch=aarch64&distro=almalinux-8 almalinux kernel-modules-extra < 4.18.0-305.el8 almalinux-8 aarch64
Affected pkg:rpm/almalinux/kernel-headers?arch=x86_64&distro=almalinux-8 almalinux kernel-headers < 4.18.0-305.el8 almalinux-8 x86_64
Affected pkg:rpm/almalinux/kernel-headers?arch=aarch64&distro=almalinux-8 almalinux kernel-headers < 4.18.0-305.el8 almalinux-8 aarch64
Affected pkg:rpm/almalinux/kernel-doc?arch=noarch&distro=almalinux-8 almalinux kernel-doc < 4.18.0-305.el8 almalinux-8 noarch
Affected pkg:rpm/almalinux/kernel-devel?arch=x86_64&distro=almalinux-8 almalinux kernel-devel < 4.18.0-305.el8 almalinux-8 x86_64
Affected pkg:rpm/almalinux/kernel-devel?arch=aarch64&distro=almalinux-8 almalinux kernel-devel < 4.18.0-305.el8 almalinux-8 aarch64
Affected pkg:rpm/almalinux/kernel-debug?arch=x86_64&distro=almalinux-8 almalinux kernel-debug < 4.18.0-305.el8 almalinux-8 x86_64
Affected pkg:rpm/almalinux/kernel-debug?arch=aarch64&distro=almalinux-8 almalinux kernel-debug < 4.18.0-305.el8 almalinux-8 aarch64
Affected pkg:rpm/almalinux/kernel-debug-modules?arch=x86_64&distro=almalinux-8 almalinux kernel-debug-modules < 4.18.0-305.el8 almalinux-8 x86_64
Affected pkg:rpm/almalinux/kernel-debug-modules?arch=aarch64&distro=almalinux-8 almalinux kernel-debug-modules < 4.18.0-305.el8 almalinux-8 aarch64
Affected pkg:rpm/almalinux/kernel-debug-modules-extra?arch=x86_64&distro=almalinux-8 almalinux kernel-debug-modules-extra < 4.18.0-305.el8 almalinux-8 x86_64
Affected pkg:rpm/almalinux/kernel-debug-modules-extra?arch=aarch64&distro=almalinux-8 almalinux kernel-debug-modules-extra < 4.18.0-305.el8 almalinux-8 aarch64
Affected pkg:rpm/almalinux/kernel-debug-devel?arch=x86_64&distro=almalinux-8 almalinux kernel-debug-devel < 4.18.0-305.el8 almalinux-8 x86_64
Affected pkg:rpm/almalinux/kernel-debug-devel?arch=aarch64&distro=almalinux-8 almalinux kernel-debug-devel < 4.18.0-305.el8 almalinux-8 aarch64
Affected pkg:rpm/almalinux/kernel-debug-core?arch=x86_64&distro=almalinux-8 almalinux kernel-debug-core < 4.18.0-305.el8 almalinux-8 x86_64
Affected pkg:rpm/almalinux/kernel-debug-core?arch=aarch64&distro=almalinux-8 almalinux kernel-debug-core < 4.18.0-305.el8 almalinux-8 aarch64
Affected pkg:rpm/almalinux/kernel-cross-headers?arch=x86_64&distro=almalinux-8 almalinux kernel-cross-headers < 4.18.0-305.el8 almalinux-8 x86_64
Affected pkg:rpm/almalinux/kernel-cross-headers?arch=aarch64&distro=almalinux-8 almalinux kernel-cross-headers < 4.18.0-305.el8 almalinux-8 aarch64
Affected pkg:rpm/almalinux/kernel-core?arch=x86_64&distro=almalinux-8 almalinux kernel-core < 4.18.0-305.el8 almalinux-8 x86_64
Affected pkg:rpm/almalinux/kernel-core?arch=aarch64&distro=almalinux-8 almalinux kernel-core < 4.18.0-305.el8 almalinux-8 aarch64
Affected pkg:rpm/almalinux/kernel-abi-stablelists?arch=noarch&distro=almalinux-8 almalinux kernel-abi-stablelists < 4.18.0-305.el8 almalinux-8 noarch
Affected pkg:rpm/almalinux/bpftool?arch=x86_64&distro=almalinux-8 almalinux bpftool < 4.18.0-305.el8 almalinux-8 x86_64
Affected pkg:rpm/almalinux/bpftool?arch=aarch64&distro=almalinux-8 almalinux bpftool < 4.18.0-305.el8 almalinux-8 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...