Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2020.2038 kernel security and bug fix update 11 June 2020 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: kernel Publisher: Red Hat Operating System: Red Hat Enterprise Linux Server 7 Impact/Access: Root Compromise -- Existing Account Denial of Service -- Remote/Unauthenticated Access Confidential Data -- Remote/Unauthenticated Resolution: Patch/Upgrade CVE Names: CVE-2020-10711 CVE-2019-19768 CVE-2019-15916 CVE-2019-14283 CVE-2019-13233 CVE-2019-12382 CVE-2019-10639 CVE-2019-9503 CVE-2019-3901 CVE-2018-20169 CVE-2018-7191 CVE-2017-18595 Reference: ESB-2020.2008 ESB-2020.1853 ESB-2020.1668 ESB-2020.1480 Original Bulletin: https://access.redhat.com/errata/RHSA-2020:2522 - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2020:2522-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:2522 Issue date: 2020-06-10 CVE Names: CVE-2017-18595 CVE-2018-7191 CVE-2018-20169 CVE-2019-3901 CVE-2019-9503 CVE-2019-10639 CVE-2019-12382 CVE-2019-13233 CVE-2019-14283 CVE-2019-15916 CVE-2019-19768 CVE-2020-10711 ===================================================================== 1. Summary: An update for kernel is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode EUS (v. 7.7) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7) - x86_64 Red Hat Enterprise Linux Server EUS (v. 7.7) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional EUS (v. 7.7) - ppc64, ppc64le, x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: double free may be caused by the function allocate_trace_buffer in the file kernel/trace/trace.c (CVE-2017-18595) * kernel: use-after-free in __blk_add_trace in kernel/trace/blktrace.c (CVE-2019-19768) * Kernel: NetLabel: null pointer dereference while receiving CIPSO packet with null category may cause kernel panic (CVE-2020-10711) * kernel: denial of service via ioctl call in network tun handling (CVE-2018-7191) * kernel: usb: missing size check in the __usb_get_extra_descriptor() leading to DoS (CVE-2018-20169) * kernel: perf_event_open() and execve() race in setuid programs allows a data leak (CVE-2019-3901) * kernel: brcmfmac frame validation bypass (CVE-2019-9503) * kernel: unchecked kstrdup of fwstr in drm_load_edid_firmware leads to denial of service (CVE-2019-12382) * kernel: use-after-free in arch/x86/lib/insn-eval.c (CVE-2019-13233) * kernel: integer overflow and OOB read in drivers/block/floppy.c (CVE-2019-14283) * kernel: memory leak in register_queue_kobjects() in net/core/net-sysfs.c leads to denial of service (CVE-2019-15916) * Kernel: net: using kernel space address bits to derive IP ID may potentially break KASLR (CVE-2019-10639) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * Backport: Guest microcode version mismatch on secondary processors (BZ#1814002) * Realtek 8111, 8112 stop working after upgrading to 3.10.0-1062 (BZ#1814601) * [mlx5] Crash on reboot while having VF configured and in switchdev mode (BZ#1814800) * qla2xxx: Urgent driver fix needed. Initiator does not relogin to target after receiving an explicit logout (BZ#1815595) * High iSCSI read latency resolved by 'tcp: implement coalescing on backlog queue' (BZ#1817498) * [RHEL7.8][Azure]Commits to resolve high network latency (BZ#1817934) * NETDEV WATCHDOG: enp3s0 (r8169): transmit queue 0 timed out (BZ#1822541) * RHEL7: block mq hang of a blk_mq_freeze_queue_wait(), which waits for a zero of a q_usage_counter, which never happens (BZ#1824545) * Kernel crashes with a message fs/fscache/operation.c:449! (BZ#1826293) * kernel BUG at fs/fscache/operation.c:70! FS-Cache: 4 == 5 is false - current state is FSCACHE_OP_ST_COMPLETE but should be FSCACHE_OP_CANCELLED in fscache_enqueue_operation (BZ#1839756) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1660385 - CVE-2018-20169 kernel: usb: missing size check in the __usb_get_extra_descriptor() leading to DoS 1701245 - CVE-2019-3901 kernel: perf_event_open() and execve() race in setuid programs allows a data leak 1701842 - CVE-2019-9503 kernel: brcmfmac frame validation bypass 1715554 - CVE-2019-12382 kernel: unchecked kstrdup of fwstr in drm_load_edid_firmware leads to denial of service 1716328 - CVE-2018-7191 kernel: denial of service via ioctl call in network tun handling 1727756 - CVE-2019-13233 kernel: use-after-free in arch/x86/lib/insn-eval.c 1729933 - CVE-2019-10639 Kernel: net: using kernel space address bits to derive IP ID may potentially break KASLR 1734243 - CVE-2019-14283 kernel: integer overflow and OOB read in drivers/block/floppy.c 1750813 - CVE-2019-15916 kernel: memory leak in register_queue_kobjects() in net/core/net-sysfs.c leads to denial of service 1758671 - CVE-2017-18595 kernel: double free may be caused by the function allocate_trace_buffer in the file kernel/trace/trace.c 1786164 - CVE-2019-19768 kernel: use-after-free in __blk_add_trace in kernel/trace/blktrace.c 1825116 - CVE-2020-10711 Kernel: NetLabel: null pointer dereference while receiving CIPSO packet with null category may cause kernel panic 6. Package List: Red Hat Enterprise Linux ComputeNode EUS (v. 7.7): Source: kernel-3.10.0-1062.26.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-1062.26.1.el7.noarch.rpm kernel-doc-3.10.0-1062.26.1.el7.noarch.rpm x86_64: bpftool-3.10.0-1062.26.1.el7.x86_64.rpm bpftool-debuginfo-3.10.0-1062.26.1.el7.x86_64.rpm kernel-3.10.0-1062.26.1.el7.x86_64.rpm kernel-debug-3.10.0-1062.26.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1062.26.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-1062.26.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-1062.26.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1062.26.1.el7.x86_64.rpm kernel-devel-3.10.0-1062.26.1.el7.x86_64.rpm kernel-headers-3.10.0-1062.26.1.el7.x86_64.rpm kernel-tools-3.10.0-1062.26.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1062.26.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-1062.26.1.el7.x86_64.rpm perf-3.10.0-1062.26.1.el7.x86_64.rpm perf-debuginfo-3.10.0-1062.26.1.el7.x86_64.rpm python-perf-3.10.0-1062.26.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1062.26.1.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7): x86_64: bpftool-debuginfo-3.10.0-1062.26.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1062.26.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-1062.26.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1062.26.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1062.26.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-1062.26.1.el7.x86_64.rpm perf-debuginfo-3.10.0-1062.26.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1062.26.1.el7.x86_64.rpm Red Hat Enterprise Linux Server EUS (v. 7.7): Source: kernel-3.10.0-1062.26.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-1062.26.1.el7.noarch.rpm kernel-doc-3.10.0-1062.26.1.el7.noarch.rpm ppc64: bpftool-3.10.0-1062.26.1.el7.ppc64.rpm bpftool-debuginfo-3.10.0-1062.26.1.el7.ppc64.rpm kernel-3.10.0-1062.26.1.el7.ppc64.rpm kernel-bootwrapper-3.10.0-1062.26.1.el7.ppc64.rpm kernel-debug-3.10.0-1062.26.1.el7.ppc64.rpm kernel-debug-debuginfo-3.10.0-1062.26.1.el7.ppc64.rpm kernel-debug-devel-3.10.0-1062.26.1.el7.ppc64.rpm kernel-debuginfo-3.10.0-1062.26.1.el7.ppc64.rpm kernel-debuginfo-common-ppc64-3.10.0-1062.26.1.el7.ppc64.rpm kernel-devel-3.10.0-1062.26.1.el7.ppc64.rpm kernel-headers-3.10.0-1062.26.1.el7.ppc64.rpm kernel-tools-3.10.0-1062.26.1.el7.ppc64.rpm kernel-tools-debuginfo-3.10.0-1062.26.1.el7.ppc64.rpm kernel-tools-libs-3.10.0-1062.26.1.el7.ppc64.rpm perf-3.10.0-1062.26.1.el7.ppc64.rpm perf-debuginfo-3.10.0-1062.26.1.el7.ppc64.rpm python-perf-3.10.0-1062.26.1.el7.ppc64.rpm python-perf-debuginfo-3.10.0-1062.26.1.el7.ppc64.rpm ppc64le: bpftool-3.10.0-1062.26.1.el7.ppc64le.rpm bpftool-debuginfo-3.10.0-1062.26.1.el7.ppc64le.rpm kernel-3.10.0-1062.26.1.el7.ppc64le.rpm kernel-bootwrapper-3.10.0-1062.26.1.el7.ppc64le.rpm kernel-debug-3.10.0-1062.26.1.el7.ppc64le.rpm kernel-debug-debuginfo-3.10.0-1062.26.1.el7.ppc64le.rpm kernel-debuginfo-3.10.0-1062.26.1.el7.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-1062.26.1.el7.ppc64le.rpm kernel-devel-3.10.0-1062.26.1.el7.ppc64le.rpm kernel-headers-3.10.0-1062.26.1.el7.ppc64le.rpm kernel-tools-3.10.0-1062.26.1.el7.ppc64le.rpm kernel-tools-debuginfo-3.10.0-1062.26.1.el7.ppc64le.rpm kernel-tools-libs-3.10.0-1062.26.1.el7.ppc64le.rpm perf-3.10.0-1062.26.1.el7.ppc64le.rpm perf-debuginfo-3.10.0-1062.26.1.el7.ppc64le.rpm python-perf-3.10.0-1062.26.1.el7.ppc64le.rpm python-perf-debuginfo-3.10.0-1062.26.1.el7.ppc64le.rpm s390x: bpftool-3.10.0-1062.26.1.el7.s390x.rpm bpftool-debuginfo-3.10.0-1062.26.1.el7.s390x.rpm kernel-3.10.0-1062.26.1.el7.s390x.rpm kernel-debug-3.10.0-1062.26.1.el7.s390x.rpm kernel-debug-debuginfo-3.10.0-1062.26.1.el7.s390x.rpm kernel-debug-devel-3.10.0-1062.26.1.el7.s390x.rpm kernel-debuginfo-3.10.0-1062.26.1.el7.s390x.rpm kernel-debuginfo-common-s390x-3.10.0-1062.26.1.el7.s390x.rpm kernel-devel-3.10.0-1062.26.1.el7.s390x.rpm kernel-headers-3.10.0-1062.26.1.el7.s390x.rpm kernel-kdump-3.10.0-1062.26.1.el7.s390x.rpm kernel-kdump-debuginfo-3.10.0-1062.26.1.el7.s390x.rpm kernel-kdump-devel-3.10.0-1062.26.1.el7.s390x.rpm perf-3.10.0-1062.26.1.el7.s390x.rpm perf-debuginfo-3.10.0-1062.26.1.el7.s390x.rpm python-perf-3.10.0-1062.26.1.el7.s390x.rpm python-perf-debuginfo-3.10.0-1062.26.1.el7.s390x.rpm x86_64: bpftool-3.10.0-1062.26.1.el7.x86_64.rpm bpftool-debuginfo-3.10.0-1062.26.1.el7.x86_64.rpm kernel-3.10.0-1062.26.1.el7.x86_64.rpm kernel-debug-3.10.0-1062.26.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1062.26.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-1062.26.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-1062.26.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1062.26.1.el7.x86_64.rpm kernel-devel-3.10.0-1062.26.1.el7.x86_64.rpm kernel-headers-3.10.0-1062.26.1.el7.x86_64.rpm kernel-tools-3.10.0-1062.26.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1062.26.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-1062.26.1.el7.x86_64.rpm perf-3.10.0-1062.26.1.el7.x86_64.rpm perf-debuginfo-3.10.0-1062.26.1.el7.x86_64.rpm python-perf-3.10.0-1062.26.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1062.26.1.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional EUS (v. 7.7): ppc64: bpftool-debuginfo-3.10.0-1062.26.1.el7.ppc64.rpm kernel-debug-debuginfo-3.10.0-1062.26.1.el7.ppc64.rpm kernel-debuginfo-3.10.0-1062.26.1.el7.ppc64.rpm kernel-debuginfo-common-ppc64-3.10.0-1062.26.1.el7.ppc64.rpm kernel-tools-debuginfo-3.10.0-1062.26.1.el7.ppc64.rpm kernel-tools-libs-devel-3.10.0-1062.26.1.el7.ppc64.rpm perf-debuginfo-3.10.0-1062.26.1.el7.ppc64.rpm python-perf-debuginfo-3.10.0-1062.26.1.el7.ppc64.rpm ppc64le: bpftool-debuginfo-3.10.0-1062.26.1.el7.ppc64le.rpm kernel-debug-debuginfo-3.10.0-1062.26.1.el7.ppc64le.rpm kernel-debug-devel-3.10.0-1062.26.1.el7.ppc64le.rpm kernel-debuginfo-3.10.0-1062.26.1.el7.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-1062.26.1.el7.ppc64le.rpm kernel-tools-debuginfo-3.10.0-1062.26.1.el7.ppc64le.rpm kernel-tools-libs-devel-3.10.0-1062.26.1.el7.ppc64le.rpm perf-debuginfo-3.10.0-1062.26.1.el7.ppc64le.rpm python-perf-debuginfo-3.10.0-1062.26.1.el7.ppc64le.rpm x86_64: bpftool-debuginfo-3.10.0-1062.26.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1062.26.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-1062.26.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1062.26.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1062.26.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-1062.26.1.el7.x86_64.rpm perf-debuginfo-3.10.0-1062.26.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1062.26.1.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2017-18595 https://access.redhat.com/security/cve/CVE-2018-7191 https://access.redhat.com/security/cve/CVE-2018-20169 https://access.redhat.com/security/cve/CVE-2019-3901 https://access.redhat.com/security/cve/CVE-2019-9503 https://access.redhat.com/security/cve/CVE-2019-10639 https://access.redhat.com/security/cve/CVE-2019-12382 https://access.redhat.com/security/cve/CVE-2019-13233 https://access.redhat.com/security/cve/CVE-2019-14283 https://access.redhat.com/security/cve/CVE-2019-15916 https://access.redhat.com/security/cve/CVE-2019-19768 https://access.redhat.com/security/cve/CVE-2020-10711 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. - -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXuGSt9zjgjWX9erEAQiIYg/+M21yXrS2L5sogFt5Q/4kq6PORkuQePOP FNwRbsPn4wjAwnHtCG4M2wTCgbF/wgEF+GNuK5tfpvUKpz7HE2mLSVt57vzsgv2o cb9IAZulO+UIDnYIDt9qoZF6YKQEkozcTpfhOpbgJN+s8+ZuUz0BvKKXrsG8092I O624ROFqxNyonhZJaZ7fui2IA8sKcIrfELpobKgmK5RQNh19X6tUXSPxCgfnTs9m xe/KcHxT1HcGA5TUAMpJVoVcFWN7Cv0r99IMG0I/8g/X1poBWzJtiI7oI4/BuET+ +wxfj3nctMrUXX7UFl9NuphIkqQFbV8BSIx/DKMl2gRU4SCrf2FGzbMBnI8TlCPZ ZE4A/rt0Wm/BOqi+/zZ8Ewg4r3JN5TjAjhrkiKIY3rhKD5SPNEHS1XHiUxNM8yX1 XSR5VQD3YrSzb+8ix8TaqCxtBe/DYXuv/e/NFOQ5p/B2Bcon6oxH6OhqY2Sdybcj mZBLf36tQHjPkxAtUk7G97NZin/lfPjxsxISJVRp3N2KGGtnL0FGdPMacS0Xb5Yc jJDLIFb4iHZJsaZaQugLmfS8xGuyhCiM9YTi6vk10eKl+1Jxp93rzUjLcT0YdnN2 VQLymumuAtevI1YpLrmf0Ga3TwLa9NgY9q/rpl84lV6hnnWFRlZa0JZyqZiRIt7D atXlRSACVv4= =q1Ey - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBXuHFQ+NLKJtyKPYoAQhdUg/+N0ZbABBtBFM9FJqx9C3GW+4jXSVzJE++ X47pBcipktCQuIMTV+LHs7B/LhFpOvRSZWAuggsttGeJDS0E/unfG5eFraEPpz/h Rw1/rEeyO3apwUGhcWZEEca1pUKXK9CcnXThAfCGuKLWK7kvikoOAzoR/utii3Zg ebN/pAE3NqIPjz+/9eCLyIFcppvyNul8om/nVZAfdxLk2lLClZzbECUBagGmAD8f q69wPyW5F3yhh2P9OswyPlBVphcVrvxLFMs9ljEz/pai733iPQiDdIY/LwJzUTCz zD0k1OwJ0UnqSVdktjEPF9tI1WxtFXmJ8lHxS7HuqNM03LsX8QGfXA3n/G5t5LiU JLwIBhgBZI0tK2LXSYi5W/rn1S0az5qoema94qyJJS+OdZc73gaEPJFOr/QKmCzX HO05D6mGbEMSTbIaOdeZQZX0kFNllvSWUBlhjDeXE/km6sLw+G8aQIcbEXVG6dEv koW7tuHYwjfLYJzbFgfH/SS52Kr+zsnGwf7l75mdYns2ZBq1y+GXu4pCbqUN1ETL YfojTAWMPwRmkoaUwkRW1J1/4bfu+BRM8pDWKl4DN9wRHgvd885r+GLCDHkVKasT VmE4faJvUcftG97ajTK5kSB/zm1YJNYTxN+3v82G9+JX7ufI4fXkv/Mdgm1BJFAE TZW7aO6hMf0= =u5ht -----END PGP SIGNATURE-----