MGASA-2019-0306 - Updated kernel packages fix security vulnerabilities

Publication date: 29 Oct 2019
URL: https://advisories.mageia.org/MGASA-2019-0306.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2019-17666

This kernel update is based on the upstream 5.3.7 and fixes several issues:
* various security issues in the usb subsystem
* rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux
  kernel through 5.3.6 lacks a certain upper-bound check, leading to a
  buffer overflow (CVE-2019-17666)


Other issues fixed by this update:

* Xorg displays a black screen with kernel > 5.2.x on some Intel GPUs
  (mga#25546)
* Firmware crash with Intel(R) Dual Band Wireless AC 3168 (mga#25609)
* a fix for an MTRR bug for intel-lpss-pci causing atleast some Ice Lake
  laptops to not boot

For other upstream fixes in this update, see the referenced changelog.

References:
- https://bugs.mageia.org/show_bug.cgi?id=25602
- https://bugs.mageia.org/show_bug.cgi?id=25546
- https://bugs.mageia.org/show_bug.cgi?id=25609
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.7
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17666

SRPMS:
- 7/core/kernel-5.3.7-4.mga7
- 7/core/kmod-virtualbox-6.0.14-4.mga7
- 7/core/kmod-xtables-addons-3.5-6.mga7

Mageia 2019-0306: kernel security update

This kernel update is based on the upstream 5.3.7 and fixes several issues: * various security issues in the usb subsystem * rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/...

Summary

This kernel update is based on the upstream 5.3.7 and fixes several issues: * various security issues in the usb subsystem * rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer overflow (CVE-2019-17666)

Other issues fixed by this update:
* Xorg displays a black screen with kernel > 5.2.x on some Intel GPUs (mga#25546) * Firmware crash with Intel(R) Dual Band Wireless AC 3168 (mga#25609) * a fix for an MTRR bug for intel-lpss-pci causing atleast some Ice Lake laptops to not boot
For other upstream fixes in this update, see the referenced changelog.

References

- https://bugs.mageia.org/show_bug.cgi?id=25602

- https://bugs.mageia.org/show_bug.cgi?id=25546

- https://bugs.mageia.org/show_bug.cgi?id=25609

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.7

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17666

Resolution

MGASA-2019-0306 - Updated kernel packages fix security vulnerabilities

SRPMS

- 7/core/kernel-5.3.7-4.mga7

- 7/core/kmod-virtualbox-6.0.14-4.mga7

- 7/core/kmod-xtables-addons-3.5-6.mga7

Severity
Publication date: 29 Oct 2019
URL: https://advisories.mageia.org/MGASA-2019-0306.html
Type: security
CVE: CVE-2019-17666

Related News