Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Fedora 29 Kernel Update FEDORA-2019-164946aa7f Critical KVM Issues

fedora
Calendar Grey February 16, 2019
Dist Fedora Esm H88
Kernel version 4.20.8 for Fedora 29 brings essential updates, resolving significant vulnerabilities and offering crucial recommendations for system users.
The 4.20.8 stable kernel update contains a number of important fixes across the tree.

Summary

The kernel meta package

The 4.20.8 stable kernel update contains a number of important fixes across the

tree.

* Tue Feb 12 2019 Justin M. Forbes - 4.20.8-200

- Linux v4.20.8

- Fixes CVE-2019-7221 (rhbz 1671904 1673676)

- Fixes CVE-2019-6974 (rhbz 1671913 1673681)

- Fixes CVE-2019-7222 (rhbz 1671930 1673686)

* Mon Feb 11 2019 Peter Robinson

- Minor Arm fixes and enhancements

* Wed Feb 6 2019 Justin M. Forbes - 4.20.7-200

- Linux v4.20.7

* Thu Jan 31 2019 Justin M. Forbes - 4.20.6-200

- Linux v4.20.6

* Mon Jan 28 2019 Justin M. Forbes - 4.20.5-200

- Linux v4.20.5

- Fix CVE-2018-16880 (rhbz 1656472 1669545)

* Wed Jan 23 2019 Hans de Goede

- Add upstream patch fixing backlight control not working on some laptops

with a Nvidia GPU (rhbz#1663613, rhbz#1665505)

* Wed Jan 23 2019 Justin M. Forbes - 4.20.4-200

- Linux v4.20.4

* Thu Jan 17 2019 Justin M. Forbes - 4.20.3-200

- Linux v4.20.3 rebase

* Mon Jan 14 2019 Jeremy Cline - 4.19.15-300

- Linux v4.19.15

- Fix CVE-2019-3459 and CVE-2019-3460 (rbhz 1663176 1663179 1665925)

* Wed Jan 9 2019 Jeremy Cline - 4.19.14-300

- Linux v4.19.14

* Wed Jan 9 2019 Justin M. Forbes

- Fix CVE-2019-3701 (rhbz 1663729 1663730)

* Mon Jan 7 2019 Hans de Goede

- Add patch to fix bluetooth on RPI 3B+ registering twice (rhbz#1661961)

* Sat Dec 29 2018 Jeremy Cline - 4.19.13-300

- Linux v4.19.13

* Thu Dec 27 2018 Hans de Goede

- Set CONFIG_REALTEK_PHY=y to workaround realtek ethernet issues (rhbz 1650984)

* Mon Dec 24 2018 Peter Robinson 4.19.12-301

- Another fix for issue affecting Raspberry Pi 3-series WiFi (rhbz 1652093)

* Sat Dec 22 2018 Peter Robinson 4.19.12-300

- Linux v4.19.12

* Thu Dec 20 2018 Jeremy Cline - 4.19.11-300

- Linux v4.19.11

* Mon Dec 17 2018 Jeremy Cline - 4.19.10-300

- Linux v4.19.10

* Fri Dec 14 2018 Peter Robinson 4.19.9-301

- Fix Raspberry Pi issues affecting WiFi (rhbz 1652093)

* Thu Dec 13 2018 Jeremy Cline - 4.19.9-300

- Linux v4.19.9

* Tue Dec 11 2018 Hans de Goede

- Really fix non functional hotkeys on Asus FX503VD (#1645070)

* Mon Dec 10 2018 Jeremy Cline - 4.19.8-300

- Linux v4.19.8

* Thu Dec 6 2018 Peter Robinson

- Fix for ethernet LEDs on Raspberry Pi 3B+

* Wed Dec 5 2018 Jeremy Cline - 4.19.7-300

- Linux v4.19.7

* Wed Dec 5 2018 Jeremy Cline

- Fix corruption bug in direct dispatch for blk-mq

* Tue Dec 4 2018 Justin M. Forbes

- Fix CVE-2018-19824 (rhbz 1655816 1655817)

* Mon Dec 3 2018 Jeremy Cline

- Fix very quiet speakers on the Thinkpad T570 (rhbz 1554304)

* Mon Dec 3 2018 Hans de Goede

- Fix non functional hotkeys on Asus FX503VD (#1645070)

* Sun Dec 2 2018 Jeremy Cline - 4.19.6-300

- Linux v4.19.6

* Thu Nov 29 2018 Jeremy Cline

- Fix a problem with some rtl8168 chips (rhbz 1650984)

- Fix slowdowns and crashes for AMD GPUs in pre-PCIe-v3 slots

* Tue Nov 27 2018 Jeremy Cline - 4.19.5-300

- Linux v4.19.5

- Fix CVE-2018-16862 (rhbz 1649017 1653122)

- Fix CVE-2018-19407 (rhbz 1652656 1652658)

* Mon Nov 26 2018 Jeremy Cline

- Fixes a null pointer dereference with Nvidia and vmwgfx drivers (rhbz 1650224)

* Fri Nov 23 2018 Peter Robinson - 4.19.4-300

- Linux v4.19.4

* Thu Nov 22 2018 Peter Robinson

- Fixes for Rockchips 3399 devices

* Wed Nov 21 2018 Jeremy Cline - 4.19.3-300

- Linux v4.19.3

* Tue Nov 20 2018 Hans de Goede

- Turn on CONFIG_PINCTRL_GEMINILAKE on x86_64 (rhbz#1639155)

- Add a patch fixing touchscreens on HP AMD based laptops (rhbz#1644013)

- Add a patch fixing KIOX010A accelerometers (rhbz#1526312)

* Sat Nov 17 2018 Peter Robinson 4.19.2-301

- Fix WiFi on Raspberry Pi 3 on aarch64 (rhbz 1649344)

- Fixes for Raspberry Pi hwmon driver and firmware interface

* Fri Nov 16 2018 Hans de Goede

- Add patches from 4.20 fixing black screen on CHT devices with i915.fastboot=1

* Thu Nov 15 2018 Hans de Goede

- Add patch fixing touchpads on some Apollo Lake devices not working (#1526312)

* Wed Nov 14 2018 Jeremy Cline - 4.19.2-300

- Linux v4.19.2

- Fix CVE-2018-18710 (rhbz 1645140 1648485)

* Mon Nov 12 2018 Laura Abbott - 4.18.18-300

- Linux v4.18.18

* Mon Nov 5 2018 Laura Abbott - 4.18.17-300

- Linux v4.18.17

* Tue Oct 23 2018 Laura Abbott

- Add i915 eDP fixes

[ 1 ] Bug #1671930 - CVE-2019-7222 Kernel: KVM: leak of uninitialized stack contents to guest

https://bugzilla.redhat.com/show_bug.cgi?id=1671930

[ 2 ] Bug #1671913 - CVE-2019-6974 Kernel: KVM: potential use-after-free via kvm_ioctl_create_device()

https://bugzilla.redhat.com/show_bug.cgi?id=1671913

[ 3 ] Bug #1671904 - CVE-2019-7221 Kernel: KVM: nVMX: use-after-free of the hrtimer for emulation of the preemption timer

https://bugzilla.redhat.com/show_bug.cgi?id=1671904

su -c 'dnf upgrade --advisory FEDORA-2019-164946aa7f' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 29
Version: 4.20.8
Release: 200.fc29
Summary: The Linux kernel

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here