Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Mageia: MGASA-2021-0538 Critical: Kernel Use-After-Free and Race Condition

mageia
Calendar Grey December 5, 2021
Dist Mageia Esm H88
Firmware revision MGASA-2021-0538 addresses crucial security issues, boosting system robustness and ensuring protective measures.
This kernel update is based on upstream 5.15.6 and fixes atleast the following security issues: A vulnerability was found in Linux kernel, where a use-after-frees in nouveau's pos...

Summary

This kernel update is based on upstream 5.15.6 and fixes atleast the following security issues:
A vulnerability was found in Linux kernel, where a use-after-frees in nouveau's postclose() handler could happen if removing device (that is not common to remove video card physically without power-off, but same happens if "unbind" the driver) (CVE-2020-27820).
A race condition when the eBPF map is frozen (CVE-2021-4001).
A memory leak flaw in the Linux kernel's hugetlbfs memory usage was found in the way the user maps some regions of memory twice using shmget() which are aligned to PUD alignment with the fault of some of the memory pages. A local user could use this flaw to get unauthorized access to some data (CVE-2021-4002).
In addition to the upstream changes, we also have added the following fixes: - ata: ahci: Add Green Sardine vendor ID as board_ahci_mobile - cpufreq: intel_pstate: ITMT support for overclocked system - Revert "drm/i915: Implement Wa_1508744258" - drm/i915/adl-n: En...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=29715

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.5

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.6

- https://www.cve.org/CVERecord?id=CVE-2020-27820

- https://www.cve.org/CVERecord?id=CVE-2021-4001

- https://www.cve.org/CVERecord?id=CVE-2021-4002

Resolution

SRPMS

- 8/core/kernel-5.15.6-2.mga8

- 8/core/kmod-virtualbox-6.1.30-1.2.mga8

- 8/core/kmod-xtables-addons-3.18-1.34.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 05 Dec 2021
URL: https://advisories.mageia.org/MGASA-2021-0538.html
Type: security
CVE: CVE-2020-27820, CVE-2021-4001, CVE-2021-4002

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here