ALAS-2020-1430


Amazon Linux 1 Security Advisory: ALAS-2020-1430
Advisory Release Date: 2020-09-03 21:53 Pacific
Advisory Updated Date: 2024-05-23 21:37 Pacific
Severity: Important

Issue Overview:

2024-05-23: CVE-2020-14356 was added to this advisory.

A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system. (CVE-2020-14356)

A flaw was found in the Linux kernel. Memory corruption can be exploited to gain root privileges from unprivileged processes. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. (CVE-2020-14386)


Affected Packages:

kernel


Issue Correction:
Run yum update kernel to update your system.

New Packages:
i686:
    kernel-tools-devel-4.14.193-113.317.amzn1.i686
    kernel-4.14.193-113.317.amzn1.i686
    kernel-debuginfo-4.14.193-113.317.amzn1.i686
    perf-debuginfo-4.14.193-113.317.amzn1.i686
    perf-4.14.193-113.317.amzn1.i686
    kernel-tools-4.14.193-113.317.amzn1.i686
    kernel-tools-debuginfo-4.14.193-113.317.amzn1.i686
    kernel-debuginfo-common-i686-4.14.193-113.317.amzn1.i686
    kernel-devel-4.14.193-113.317.amzn1.i686
    kernel-headers-4.14.193-113.317.amzn1.i686

src:
    kernel-4.14.193-113.317.amzn1.src

x86_64:
    kernel-tools-4.14.193-113.317.amzn1.x86_64
    kernel-debuginfo-4.14.193-113.317.amzn1.x86_64
    kernel-debuginfo-common-x86_64-4.14.193-113.317.amzn1.x86_64
    kernel-4.14.193-113.317.amzn1.x86_64
    kernel-headers-4.14.193-113.317.amzn1.x86_64
    perf-4.14.193-113.317.amzn1.x86_64
    kernel-tools-devel-4.14.193-113.317.amzn1.x86_64
    perf-debuginfo-4.14.193-113.317.amzn1.x86_64
    kernel-tools-debuginfo-4.14.193-113.317.amzn1.x86_64
    kernel-devel-4.14.193-113.317.amzn1.x86_64