Mageia 2019-0333: kernel-linus security update
Summary
This kernel-linus update is based on the upstream 5.3.13 and fixes atleast
the following security issues:
Insufficient access control in a subsystem for Intel (R) processor graphics
may allow an authenticated user to potentially enable escalation of
privilege via local access (CVE-2019-0155).
A Spectre SWAPGS gadget was found in the Linux kernel's implementation of
system interrupts. An attacker with local access could use this information
to reveal private data through a Spectre like side channel (CVE-2019-1125).
A flaw was found in the Linux kernel’s Bluetooth implementation of UART.
An attacker with local access and write permissions to the Bluetooth
hardware could use this flaw to issue a specially crafted ioctl function
call and cause the system to crash (CVE-2019-10207).
TSX Asynchronous Abort condition on some CPUs utilizing speculative
execution may allow an authenticated user to potentially enable
information disclosure via a side channel with local access
...
References
- https://bugs.mageia.org/show_bug.cgi?id=25687
- https://bugs.mageia.org/show_bug.cgi?id=25688
- https://kernelnewbies.org/Linux_5.2
- https://kernelnewbies.org/Linux_5.3
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.1
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.2
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.3
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.4
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.5
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.6
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.7
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.8
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.9
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.10
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.11
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-0155
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1125
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10207
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11135
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12207
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14814
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14815
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14816
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14821
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14835
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16714
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17666
Resolution
MGASA-2019-0333 - Updated kernel-linus packages fix security vulnerabilities
SRPMS
- 7/core/kernel-linus-5.3.11-1.mga7