ALAS2KERNEL-5.4-2022-007

Related Vulnerabilities: CVE-2021-3753   CVE-2021-40490  

A race problem was seen in the vt_k_ioctl in drivers/tty/vt/vt_ioctl.c in the Linux kernel, which may cause an out of bounds read in vt as the write access to vc_mode is not protected by lock-in vt_ioctl (KDSETMDE). The highest threat from this vulnerability is to data confidentiality. (CVE-2021-3753) A flaw was found in the Linux kernel. A race condition was discovered in the ext4 subsystem. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. (CVE-2021-40490)

ALAS2KERNEL-5.4-2022-007


Amazon Linux 2 Security Advisory: ALASKERNEL-5.4-2022-007
Advisory Release Date: 2022-01-20 19:05 Pacific
Advisory Updated Date: 2022-01-28 17:23 Pacific
Severity: Medium

Issue Overview:

A race problem was seen in the vt_k_ioctl in drivers/tty/vt/vt_ioctl.c in the Linux kernel, which may cause an out of bounds read in vt as the write access to vc_mode is not protected by lock-in vt_ioctl (KDSETMDE). The highest threat from this vulnerability is to data confidentiality. (CVE-2021-3753)

A flaw was found in the Linux kernel. A race condition was discovered in the ext4 subsystem. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. (CVE-2021-40490)


Affected Packages:

kernel


Issue Correction:
Run yum update kernel to update your system.

New Packages:
aarch64:
    kernel-5.4.144-69.257.amzn2.aarch64
    kernel-headers-5.4.144-69.257.amzn2.aarch64
    kernel-debuginfo-common-aarch64-5.4.144-69.257.amzn2.aarch64
    perf-5.4.144-69.257.amzn2.aarch64
    perf-debuginfo-5.4.144-69.257.amzn2.aarch64
    python-perf-5.4.144-69.257.amzn2.aarch64
    python-perf-debuginfo-5.4.144-69.257.amzn2.aarch64
    kernel-tools-5.4.144-69.257.amzn2.aarch64
    kernel-tools-devel-5.4.144-69.257.amzn2.aarch64
    kernel-tools-debuginfo-5.4.144-69.257.amzn2.aarch64
    bpftool-5.4.144-69.257.amzn2.aarch64
    bpftool-debuginfo-5.4.144-69.257.amzn2.aarch64
    kernel-devel-5.4.144-69.257.amzn2.aarch64
    kernel-debuginfo-5.4.144-69.257.amzn2.aarch64

i686:
    kernel-headers-5.4.144-69.257.amzn2.i686

src:
    kernel-5.4.144-69.257.amzn2.src

x86_64:
    kernel-5.4.144-69.257.amzn2.x86_64
    kernel-headers-5.4.144-69.257.amzn2.x86_64
    kernel-debuginfo-common-x86_64-5.4.144-69.257.amzn2.x86_64
    perf-5.4.144-69.257.amzn2.x86_64
    perf-debuginfo-5.4.144-69.257.amzn2.x86_64
    python-perf-5.4.144-69.257.amzn2.x86_64
    python-perf-debuginfo-5.4.144-69.257.amzn2.x86_64
    kernel-tools-5.4.144-69.257.amzn2.x86_64
    kernel-tools-devel-5.4.144-69.257.amzn2.x86_64
    kernel-tools-debuginfo-5.4.144-69.257.amzn2.x86_64
    bpftool-5.4.144-69.257.amzn2.x86_64
    bpftool-debuginfo-5.4.144-69.257.amzn2.x86_64
    kernel-devel-5.4.144-69.257.amzn2.x86_64
    kernel-debuginfo-5.4.144-69.257.amzn2.x86_64