MGASA-2021-0062 - Updated kernel-linus packages fix security vulnerability

Publication date: 01 Feb 2021
URL: https://advisories.mageia.org/MGASA-2021-0062.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2021-3347

This kernel-linus update is based on upstream 5.10.12 and fixes atleast the
following security issue:

An issue was discovered in the Linux kernel through 5.10.11. PI futexes
have a kernel stack use-after-free during fault handling, allowing local
users to execute code in the kernel (CVE-2021-3347).

For other upstream fixes, see the referenced changelog.

References:
- https://bugs.mageia.org/show_bug.cgi?id=28262
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.12
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3347

SRPMS:
- 7/core/kernel-linus-5.10.12-1.mga7

Mageia 2021-0062: kernel-linus security update

This kernel-linus update is based on upstream 5.10.12 and fixes atleast the following security issue: An issue was discovered in the Linux kernel through 5.10.11

Summary

This kernel-linus update is based on upstream 5.10.12 and fixes atleast the following security issue:
An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel (CVE-2021-3347).
For other upstream fixes, see the referenced changelog.

References

- https://bugs.mageia.org/show_bug.cgi?id=28262

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.12

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3347

Resolution

MGASA-2021-0062 - Updated kernel-linus packages fix security vulnerability

SRPMS

- 7/core/kernel-linus-5.10.12-1.mga7

Severity
Publication date: 01 Feb 2021
URL: https://advisories.mageia.org/MGASA-2021-0062.html
Type: security
CVE: CVE-2021-3347

Related News