Updated kernel packages fix security vulnerabilities
Publication date: 17 Jan 2020Modification date: 17 Feb 2022
Type: security
Affected Mageia releases : 7
CVE: CVE-2019-14615 , CVE-2019-14895
Description
This update is based on upstream 5.4.12 and fixes at least the following security vulnerabilities: Intel GPU Hardware prior to Gen11 does not clear EU state during a context switch. This can result in information leakage between contexts (CVE-2019-14615). A heap-based buffer overflow was discovered in the Marvell WiFi chip driver. The flaw could occur when the station attempts a connection negotiation during the handling of the remote devices country settings. This could allow the remote device to cause a denial of service (system crash) or possibly execute arbitrary code (CVE-2019-14895). For other fixes in this update, see the referenced changelogs.
References
SRPMS
7/core
- kernel-5.4.12-1.mga7
- kmod-virtualbox-6.0.14-20.mga7
- kmod-xtables-addons-3.7-10.mga7