RHSA-2019:3517-01 -- Redhat kernel, perf, bpftool, python3-perfID: oval:org.secpod.oval:def:66475 | Date: (C)2020-10-30 (M)2024-04-17 |
Class: PATCH | Family: unix |
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix: * kernel: nfs: use-after-free in svc_process_common * Kernel: vhost_net: infinite loop while receiving packets leads to DoS * Kernel: page cache side channel attacks * hardware: bluetooth: BR/EDR encryption key negotiation attacks * kernel: Heap overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c * Kernel: KVM: OOB memory access via mmio ring buffer * kernel: Information Disclosure in crypto_report_one in crypto/crypto_user.c * kernel: usb: missing size check in the __usb_get_extra_descriptor leading to DoS * kernel: Heap address information leak while using L2CAP_GET_CONF_OPT * kernel: Heap address information leak while using L2CAP_PARSE_CONF_RSP * kernel: SCTP socket buffer memory leak leading to denial of service * kernel: denial of service vector through vfio DMA mappings * kernel: null-pointer dereference in hci_uart_set_flow_control * kernel: fix race condition between mmget_not_zero/get_task_mm and core dumping * kernel: fs/ext4/extents.c leads to information disclosure * kernel: sensitive information disclosure from kernel stack memory via HIDPCONNADD command * kernel: use-after-free in arch/x86/lib/insn-eval.c * kernel: memory leak in register_queue_kobjects in net/core/net-sysfs.c leads to denial of service * kernel: Linux stack ASLR implementation Integer overflow * kernel: oob memory read in hso_probe in drivers/net/usb/hso.c * Kernel: KVM: leak of uninitialized stack contents to guest * Kernel: net: weak IP ID generation leads to remote device tracking For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Additional Changes: For detailed information on changes in this release, see the CentOS 8.1 Release Notes linked from the References section.
Product: |
kernel |
perf |
python3-perf |
bpftool |