Amazon Linux 2 Security Advisory: ALASKERNEL-5.4-2024-066
Advisory Release Date: 2024-05-09 18:00 Pacific
Advisory Updated Date: 2024-05-20 20:43 Pacific
fpregs_state_valid in arch/x86/include/asm/fpu/internal.h in the Linux kernel before 5.4.2, when GCC 9 is used, allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact because of incorrect fpu_fpregs_owner_ctx caching, as demonstrated by mishandling of signal-based non-cooperative preemption in Go 1.14 prereleases on amd64, aka CID-59c4bd853abc. (CVE-2019-19602)
In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5. (CVE-2019-19965)
Affected Packages:
kernel
Note:
This advisory is applicable to Amazon Linux 2 - Kernel-5.4 Extra. Visit this page to learn more about Amazon Linux 2 (AL2) Extras and this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update kernel to update your system.
aarch64:
kernel-5.4.20-12.75.amzn2.aarch64
kernel-headers-5.4.20-12.75.amzn2.aarch64
kernel-debuginfo-common-aarch64-5.4.20-12.75.amzn2.aarch64
perf-5.4.20-12.75.amzn2.aarch64
perf-debuginfo-5.4.20-12.75.amzn2.aarch64
python-perf-5.4.20-12.75.amzn2.aarch64
python-perf-debuginfo-5.4.20-12.75.amzn2.aarch64
kernel-tools-5.4.20-12.75.amzn2.aarch64
kernel-tools-devel-5.4.20-12.75.amzn2.aarch64
kernel-tools-debuginfo-5.4.20-12.75.amzn2.aarch64
kernel-devel-5.4.20-12.75.amzn2.aarch64
kernel-debuginfo-5.4.20-12.75.amzn2.aarch64
i686:
kernel-headers-5.4.20-12.75.amzn2.i686
src:
kernel-5.4.20-12.75.amzn2.src
x86_64:
kernel-5.4.20-12.75.amzn2.x86_64
kernel-headers-5.4.20-12.75.amzn2.x86_64
kernel-debuginfo-common-x86_64-5.4.20-12.75.amzn2.x86_64
perf-5.4.20-12.75.amzn2.x86_64
perf-debuginfo-5.4.20-12.75.amzn2.x86_64
python-perf-5.4.20-12.75.amzn2.x86_64
python-perf-debuginfo-5.4.20-12.75.amzn2.x86_64
kernel-tools-5.4.20-12.75.amzn2.x86_64
kernel-tools-devel-5.4.20-12.75.amzn2.x86_64
kernel-tools-debuginfo-5.4.20-12.75.amzn2.x86_64
kernel-devel-5.4.20-12.75.amzn2.x86_64
kernel-debuginfo-5.4.20-12.75.amzn2.x86_64