Advisories ยป MGASA-2019-0306

Updated kernel packages fix security vulnerabilities

Publication date: 29 Oct 2019
Type: security
Affected Mageia releases : 7
CVE: CVE-2019-17666


This kernel update is based on the upstream 5.3.7 and fixes several issues:
* various security issues in the usb subsystem
* rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux
  kernel through 5.3.6 lacks a certain upper-bound check, leading to a
  buffer overflow (CVE-2019-17666)

Other issues fixed by this update:

* Xorg displays a black screen with kernel > 5.2.x on some Intel GPUs
* Firmware crash with Intel(R) Dual Band Wireless AC 3168 (mga#25609)
* a fix for an MTRR bug for intel-lpss-pci causing at least some Ice Lake
  laptops to not boot

For other upstream fixes in this update, see the referenced changelog.