Lucene search

K
mageiaGentoo FoundationMGASA-2021-0084
HistoryFeb 15, 2021 - 10:24 p.m.

Updated kernel packages fix security vulnerability

2021-02-1522:24:33
Gentoo Foundation
advisories.mageia.org
25
kernel update
upstream 5.10.14
security patches
local privilege escalation
race conditions
af_vsock
net/vmw_vsock/af_vsock.c
cve-2021-26708
connector
proc_events
drm/amd/display
drm/amdgpu
noretry
drm/amdkfd
mm:thp
changelogs

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

CVSS3

7

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

5.2%

This kernel update is based on upstream 5.10.14 and fixes at least the following security issues: A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implementation are caused by wrong locking in net/vmw_vsock/af_vsock.c (CVE-2021-26708). It also adds the following fixes: - make CONNECTOR builtin to enable PROC_EVENTS (mga#28312) - drm/amd/display: Revert “Fix EDID parsing after resume from suspend” - drm/amdgpu: fix the issue that retry constantly once the buffer is oversize - drm/amdgpu: set default value of noretry to 1 for vega10 - drm/amdgpu: default noretry=0 for navi1x and newer - drm/amdkfd: fix null pointer panic while free buffer in kfd - mm: thp: fix MADV_REMOVE deadlock on shmem THP For other upstream fixes, see the referenced changelogs.

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

CVSS3

7

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

5.2%