ALAS2-2020-1488


Amazon Linux 2 Security Advisory: ALAS-2020-1488
Advisory Release Date: 2020-09-03 21:45 Pacific
Advisory Updated Date: 2020-09-04 02:53 Pacific
Severity: Important

Issue Overview:

An issue has been reported in the Linux kernel's handling of raw sockets. This issue can be used locally to cause denial of service or local privilege escalation from unprivileged processes or from containers with the CAP_NET_RAW capability enabled.

See Also:

https://marc.info/?l=linux-netdev&m=159915549623724&w=2
https://www.openwall.com/lists/oss-security/2020/09/03/3
https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-14386 (cve-2020-14386)


Affected Packages:

kernel


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update kernel to update your system.

New Packages:
aarch64:
    kernel-4.14.193-149.317.amzn2.aarch64
    kernel-headers-4.14.193-149.317.amzn2.aarch64
    kernel-debuginfo-common-aarch64-4.14.193-149.317.amzn2.aarch64
    perf-4.14.193-149.317.amzn2.aarch64
    perf-debuginfo-4.14.193-149.317.amzn2.aarch64
    python-perf-4.14.193-149.317.amzn2.aarch64
    python-perf-debuginfo-4.14.193-149.317.amzn2.aarch64
    kernel-tools-4.14.193-149.317.amzn2.aarch64
    kernel-tools-devel-4.14.193-149.317.amzn2.aarch64
    kernel-tools-debuginfo-4.14.193-149.317.amzn2.aarch64
    kernel-devel-4.14.193-149.317.amzn2.aarch64
    kernel-debuginfo-4.14.193-149.317.amzn2.aarch64

i686:
    kernel-headers-4.14.193-149.317.amzn2.i686

src:
    kernel-4.14.193-149.317.amzn2.src

x86_64:
    kernel-4.14.193-149.317.amzn2.x86_64
    kernel-headers-4.14.193-149.317.amzn2.x86_64
    kernel-debuginfo-common-x86_64-4.14.193-149.317.amzn2.x86_64
    perf-4.14.193-149.317.amzn2.x86_64
    perf-debuginfo-4.14.193-149.317.amzn2.x86_64
    python-perf-4.14.193-149.317.amzn2.x86_64
    python-perf-debuginfo-4.14.193-149.317.amzn2.x86_64
    kernel-tools-4.14.193-149.317.amzn2.x86_64
    kernel-tools-devel-4.14.193-149.317.amzn2.x86_64
    kernel-tools-debuginfo-4.14.193-149.317.amzn2.x86_64
    kernel-devel-4.14.193-149.317.amzn2.x86_64
    kernel-debuginfo-4.14.193-149.317.amzn2.x86_64
    kernel-livepatch-4.14.193-149.317-1.0-0.amzn2.x86_64