RHSA-2020:1372MediumCVSS 6.8
Red Hat Security Advisory: kernel security and bug fix update
🔗 CVE IDs covered (4)
📋 Description
CVE-2019-15030 — kernel: powerpc: local user can read vector registers of other users' processes via a Facility Unavailable exception CVE-2019-15031 — kernel: powerpc: local user can read vector registers of other users' processes via an interrupt CVE-2019-18660 — kernel: powerpc: incomplete Spectre-RSB mitigation leads to information exposure CVE-2019-19527 — kernel: use-after-free caused by a malicious USB device in the drivers/hid/usbhid/hiddev.c driver
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2020:1372
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1759313
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1760063
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1777825
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1783498
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_1372.json