Advisories ยป MGASA-2020-0041

Updated kernel packages fix security vulnerabilities

Publication date: 17 Jan 2020
Modification date: 17 Feb 2022
Type: security
Affected Mageia releases : 7
CVE: CVE-2019-14615 , CVE-2019-14895

Description

This update is based on upstream 5.4.12 and fixes at least the following
security vulnerabilities:

Intel GPU Hardware prior to Gen11 does not clear EU state during a
context switch. This can result in information leakage between
contexts (CVE-2019-14615).

A heap-based buffer overflow was discovered in the Marvell WiFi chip
driver. The flaw could occur when the station attempts a connection
negotiation during the handling of the remote devices country settings.
This could allow the remote device to cause a denial of service (system
crash) or possibly execute arbitrary code (CVE-2019-14895).

For other fixes in this update, see the referenced changelogs.
                

References

SRPMS

7/core