ALAS2LIVEPATCH-2021-040


Amazon Linux 2 Security Advisory: ALASLIVEPATCH-2021-040
Advisory Release Date: 2021-02-22 19:03 Pacific
Advisory Updated Date: 2021-04-07 18:55 Pacific
Severity: Important

Issue Overview:

A flaw was found in the Linux kernel. A use-after-free memory flaw in the Fast Userspace Mutexes functionality allowing a local user to crash the system or escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. (CVE-2021-3347)


Affected Packages:

kernel-livepatch-4.14.209-160.335


Issue Correction:
Please ensure you have live patching enabled.
Run yum update kernel-livepatch-4.14.209-160.335 to update your system.

New Packages:
src:
    kernel-livepatch-4.14.209-160.335-1.0-4.amzn2.src

x86_64:
    kernel-livepatch-4.14.209-160.335-1.0-4.amzn2.x86_64
    kernel-livepatch-4.14.209-160.335-debuginfo-1.0-4.amzn2.x86_64