Page tree
Skip to end of metadata
Go to start of metadata

CentOS Linux—the open, enterprise-class, platform upon which Lumeta solutions are builtand third-party packages such as Postgres and Oracle JRE—are continuously monitored by industry  and community groups to uncover flaws. Upgrade packages that fix these CentOS flaws (aka CVEs, Common Vulnerabilities and Exposures) are made available from CentOS and third parties (Postgres, Oracle JRE) on an ongoing basis. 

This page lists security enhancements on our radar.  It's those CVEs that Lumeta is actively addressing and expects to have fully resolved in the upcoming releases of Lumeta Enterprise Edition.

CVERepairDate3rd Party Patch
Vulnerability
 Resolved_Version & GA Date
IdentifierPKGReportedAvailable?LumetaNotes on vulnerabilityLumetaLumeta_GA
CVE-2019-19059kernel-3.10.0-1160.6.1.el7.x86_64
CentOS yesyeshttps://access.redhat.com/security/cve/cve-2019-190594.1.0.09/18/2020
CVE-2020-10757kernel-devel-3.10.0-1160.6.1.el7.x86_64
CentOS yesyes

A flaw was found in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.

https://access.redhat.com/security/cve/cve-2020-10757

4.1.0.09/18/2020
CVE-2020-10732kernel-3.10.0-1160.6.1.el7.x86_64
CentOS yesyes

A flaw was found in the Linux kernel’s implementation of Userspace core dumps. This flaw allows an attacker with a local account to crash a trivial program and exfiltrate private kernel data.

https://access.redhat.com/security/cve/cve-2020-10732

4.1.0.09/18/2020
CVE-2020-9383perf-3.10.0-1160.6.1.el7.x86_64
CentOS yesyes

An out-of-bounds (OOB) memory access flaw was found in the floppy driver module in the Linux kernel

https://access.redhat.com/security/cve/CVE-2020-9383

4.1.0.09/18/2020
CVE-2020-1749kernel-tools-libs-3.10.0-1160.6.1.el7.x86_64
CentOS yesyes

A flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tunnels over IPv6

https://access.redhat.com/security/cve/cve-2020-1749

4.1.0.09/18/2020
CVE-2020-10942kernel-tools-libs-3.10.0-1160.6.1.el7.x86_64
CentOS yesyes

A stack buffer overflow issue was found in the get_raw_socket() routine of the Host kernel accelerator for virtio net (vhost-net) driver

https://access.redhat.com/security/cve/cve-2020-10942

4.1.0.09/18/2020
CVE-2019-15917kernel-3.10.0-1160.6.1.el7.x86_64
CentOS yesyes

A flaw was found in the Linux kernel's implementation of the HCI UART driver.

https://access.redhat.com/security/cve/cve-2019-15917

4.1.0.09/18/2020



 

  • No labels