Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Fedora 32: 2021-6b0f287b8b Critical: Kernel Memory Leak & DoS Threats

fedora
Calendar Grey April 1, 2021
Dist Fedora Esm H88
Fedora 32 receives a kernel headers update that addresses numerous vital concerns and incorporates key patches for optimal functionality.
The 5.11.11 stable kernel update contains a number of important fixes across the tree.

Summary

Kernel-headers includes the C header files that specify the interface

between the Linux kernel and userspace libraries and programs. The

header files define structures and constants that are needed for

building most standard programs and are also needed for rebuilding the

glibc package.

The 5.11.11 stable kernel update contains a number of important fixes across the

tree.

* Tue Mar 30 2021 Justin M. Forbes - 5.11.11-100

- Linux v5.11.11

[ 1 ] Bug #1945345 - CVE-2021-29646 kernel: improper input validation in tipc_nl_retrieve_key function in net/tipc/node.c

https://bugzilla.redhat.com/show_bug.cgi?id=1945345

[ 2 ] Bug #1945361 - CVE-2021-29647 kernel: information disclosure due to uninitialized data structure in qrtr_recvmsg function in net/qrtr/qrtr.c

https://bugzilla.redhat.com/show_bug.cgi?id=1945361

[ 3 ] Bug #1945373 - CVE-2021-29648 kernel: DoS due to BPF subsystem does not properly consider that resolved_ids and resolved_sizes are intentionally uninitialized in the vmlinux BPF

https://bugzilla.redhat.com/show_bug.cgi?id=1945373

[ 4 ] Bug #1945379 - CVE-2021-29649 kernel: memory leak in user mode driver due to lack of cleanup steps in kernel/usermode_driver.c and kernel/bpf/preload/bpf_preload_kern.c

https://bugzilla.redhat.com/show_bug.cgi?id=1945379

[ 5 ] Bug #1945388 - CVE-2021-29650 kernel: lack a full memory barrier upon the assignment of a new table value in net/netfilter/x_tables.c and include/linux/netfilter/x_tables.h may lead to DoS

https://bugzilla.redhat.com/show_bug.cgi?id=1945388

su -c 'dnf upgrade --advisory FEDORA-2021-6b0f287b8b' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 32
Version: 5.11.11
Release: 100.fc32
Summary: Header files for the Linux kernel for use by glibc

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here