Mageia 2020-0392: kernel security update
Summary
A flaw was found in the way the Linux kernel Bluetooth implementation handled
L2CAP packets with A2MP CID. A remote attacker in adjacent range could use
this flaw to crash the system causing denial of service or potentially execute
arbitrary code on the system by sending a specially crafted L2CAP packet. The
highest threat from this vulnerability is to data confidentiality and
integrity as well as system availability (CVE-2020-12351).
An information leak flaw was found in the way the Linux kernel's Bluetooth
stack implementation handled initialization of stack memory when handling
certain AMP packets. A remote attacker in adjacent range could use this flaw
to leak small portions of stack memory on the system by sending a specially
crafted AMP packets. The highest threat from this vulnerability is to data
confidentiality (CVE-2020-12352).
A flaw was found in the Linux kernel before 5.9-rc4. A failure of the file
system metadata validator in XFS can cause an inode with a valid,
user-c...
References
- https://bugs.mageia.org/show_bug.cgi?id=27443
- - - - - - - - - - - https://access.redhat.com/security/cve/CVE-2020-12351
- https://access.redhat.com/security/cve/CVE-2020-12352
- https://access.redhat.com/security/cve/CVE-2020-24490
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12351
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12352
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14385
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14386
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14390
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24490
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25211
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25221
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25284
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25285
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25641
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25643
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25645
Resolution
MGASA-2020-0392 - Updated kernel packages fix security vulnerabilities
SRPMS
- 7/core/kernel-5.7.19-3.mga7
- 7/core/kmod-virtualbox-6.0.24-6.mga7
- 7/core/xtables-addons-3.11-1.mga7
- 7/core/kmod-xtables-addons-3.11-1.mga7