Synopsis:          Moderate: kernel security and bug fix update
Advisory ID:       SLSA-2022:0063-1
Issue Date:        2022-01-14
CVE Numbers:       CVE-2020-25704
                   CVE-2020-36322
                   CVE-2021-42739
--

Security Fix(es):

* kernel: perf_event_parse_addr_filter memory (CVE-2020-25704)

* kernel: fuse: fuse_do_getattr() calls make_bad_inode() in inappropriate
situations (CVE-2020-36322)

* kernel: Heap buffer overflow in firedtv driver (CVE-2021-42739)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE

Bug Fix(es):

*    A gfs2 withdrawal occurs function = gfs2_setbit, file fs/gfs2/rgrp.c, line = 109

*    i40e SR-IOV TX driver issue detected on VF 7 - VF connectivity 
loose after VF down/up duplicate ACK not sent when expected

*    [kernel-debug] BUG: bad unlock balance detected! when
running LTP read_all  *    Rudimentary support for AMD Milan - Call
init_amd_zn() om Family 19h processors
*    A VM with <=8 CPUs handles all the Mellanox NIC interrupts on CPU0
only, causing low performance

*    fix _PSD override quirk for AMD family 19h+

*    generic_file_aio_read returns 0 when interrupted early with a fatal
signal
--

SL7
  x86_64
    bpftool-3.10.0-1160.53.1.el7.x86_64.rpm
    bpftool-debuginfo-3.10.0-1160.53.1.el7.x86_64.rpm
    kernel-3.10.0-1160.53.1.el7.x86_64.rpm
    kernel-debug-3.10.0-1160.53.1.el7.x86_64.rpm
    kernel-debug-debuginfo-3.10.0-1160.53.1.el7.x86_64.rpm
    kernel-debug-devel-3.10.0-1160.53.1.el7.x86_64.rpm
    kernel-debuginfo-3.10.0-1160.53.1.el7.x86_64.rpm
    kernel-debuginfo-common-x86_64-3.10.0-1160.53.1.el7.x86_64.rpm
    kernel-devel-3.10.0-1160.53.1.el7.x86_64.rpm
    kernel-headers-3.10.0-1160.53.1.el7.x86_64.rpm
    kernel-tools-3.10.0-1160.53.1.el7.x86_64.rpm
    kernel-tools-debuginfo-3.10.0-1160.53.1.el7.x86_64.rpm
    kernel-tools-libs-3.10.0-1160.53.1.el7.x86_64.rpm
    kernel-tools-libs-devel-3.10.0-1160.53.1.el7.x86_64.rpm
    perf-3.10.0-1160.53.1.el7.x86_64.rpm
    perf-debuginfo-3.10.0-1160.53.1.el7.x86_64.rpm
    python-perf-3.10.0-1160.53.1.el7.x86_64.rpm
    python-perf-debuginfo-3.10.0-1160.53.1.el7.x86_64.rpm

  noarch
    kernel-abi-whitelists-3.10.0-1160.53.1.el7.noarch.rpm
    kernel-doc-3.10.0-1160.53.1.el7.noarch.rpm

- Scientific Linux Development Team

SciLinux: SLSA-2022-0063-1 Important: kernel on SL7.x x86_64

kernel: perf_event_parse_addr_filter memory (CVE-2020-25704) * kernel: fuse: fuse_do_getattr() calls make_bad_inode() in inappropriate situations (CVE-2020-36322) * kernel: Heap bu...

Summary

Moderate: kernel security and bug fix update



Security Fixes

* kernel: perf_event_parse_addr_filter memory (CVE-2020-25704)
* kernel: fuse: fuse_do_getattr() calls make_bad_inode() in inappropriate situations (CVE-2020-36322)
* kernel: Heap buffer overflow in firedtv driver (CVE-2021-42739)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE

Severity
Advisory ID: SLSA-2022:0063-1
Issued Date: : 2022-01-14
CVE Numbers: CVE-2020-25704
CVE-2020-36322
CVE-2021-42739

Related News