ALSA-2020:4431

Source
https://errata.almalinux.org/8/ALSA-2020-4431.html
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2020:4431.json
JSON Data
https://api.osv.dev/v1/vulns/ALSA-2020:4431
Related
Published
2020-11-03T12:03:57Z
Modified
2021-08-11T08:54:00Z
Summary
Moderate: kernel security, bug fix, and enhancement update
Details

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: use after free in the video driver leads to local privilege escalation (CVE-2019-9458)

  • kernel: use-after-free in drivers/bluetooth/hci_ldisc.c (CVE-2019-15917)

  • kernel: out-of-bounds access in function hclgetmschdmodevnetbasecfg (CVE-2019-15925)

  • kernel: memory leak in ccprunsha_cmd() (CVE-2019-18808)

  • kernel: Denial Of Service in the _ipmibmc_register() (CVE-2019-19046)

  • kernel: out-of-bounds write in ext4xattrset_entry (CVE-2019-19319)

  • Kernel: kvm: OOB memory write via kvmdevioctlgetcpuid (CVE-2019-19332)

  • kernel: use-after-free in ext4putsuper (CVE-2019-19447)

  • kernel: a malicious USB device in the drivers/input/ff-memless.c leads to use-after-free (CVE-2019-19524)

  • kernel: race condition caused by a malicious USB device in the USB character device driver layer (CVE-2019-19537)

  • kernel: use-after-free in serialirinit_module() (CVE-2019-19543)

  • kernel: use-after-free in _ext4expandextraisize and ext4xattrset_entry (CVE-2019-19767)

  • kernel: use-after-free in debugfs_remove (CVE-2019-19770)

  • kernel: out-of-bounds write via crafted keycode table (CVE-2019-20636)

  • kernel: possible use-after-free due to a race condition in cdev_get (CVE-2020-0305)

  • kernel: out-of-bounds read in in vcdoresize function (CVE-2020-8647)

  • kernel: use-after-free in nttyreceivebufcommon function (CVE-2020-8648)

  • kernel: invalid read location in vgaconinvertregion function (CVE-2020-8649)

  • kernel: uninitialized kernel data leak in userspace coredumps (CVE-2020-10732)

  • kernel: SELinux netlink permission check bypass (CVE-2020-10751)

  • kernel: out-of-bounds write in mpolparsestr (CVE-2020-11565)

  • kernel: mishandles invalid descriptors in drivers/media/usb/gspca/xirlink_cit.c (CVE-2020-11668)

  • kernel: buffer overflow in mt76addfragment function (CVE-2020-12465)

  • kernel: xdpumemreg in net/xdp/xdp_umem.c has an out-of-bounds write which could result in crash and data coruption (CVE-2020-12659)

  • kernel: sgwrite function lacks an sgremove_request call in a certain failure case (CVE-2020-12770)

  • kernel: possible to send arbitrary signals to a privileged (suidroot) parent process (CVE-2020-12826)

  • kernel: referencing inode of removed superblock in getfutexkey() causes UAF (CVE-2020-14381)

  • kernel: soft-lockups in iovitercopyfromuser_atomic() could result in DoS (CVE-2020-25641)

  • kernel: kernel pointer leak due to WARN_ON statement in video driver leads to local information disclosure (CVE-2019-9455)

  • kernel: null pointer dereference in dlparparsecc_property (CVE-2019-12614)

  • kernel: null-pointer dereference in drivers/net/fjes/fjes_main.c (CVE-2019-16231)

  • kernel: null pointer dereference in drivers/scsi/qla2xxx/qla_os.c (CVE-2019-16233)

  • kernel: memory leak in af9005identifystate() function (CVE-2019-18809)

  • kernel: A memory leak in the mwifiexpciealloccmdrspbuf() function (CVE-2019-19056)

  • kernel: memory leak in the crypto_report() function (CVE-2019-19062)

  • kernel: Two memory leaks in the rtlusbprobe() function (CVE-2019-19063)

  • kernel: A memory leak in the rtl8xxxusubmitint_urb() function (CVE-2019-19068)

  • kernel: A memory leak in the predicate_parse() function (CVE-2019-19072)

  • kernel: information leak bug caused by a malicious USB device in the drivers/media/usb/ttusb-dec/ttusb_dec.c (CVE-2019-19533)

  • kernel: Null pointer dereference in dropsysctltable() (CVE-2019-20054)

  • kernel: kernel stack information leak on s390/s390x (CVE-2020-10773)

  • kernel: possibility of memory disclosure when reading the file /proc/sys/kernel/rh_features (CVE-2020-10774)

  • kernel: vhost-net: stack overflow in getrawsocket while checking sk_family field (CVE-2020-10942)

  • kernel: sync of excessive duration via an XFS v5 image with crafted metadata (CVE-2020-12655)

References

Affected packages

AlmaLinux:8 / kernel-tools-libs-devel

Package

Name
kernel-tools-libs-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-240.el8