MGASA-2020-0041

Advisory lineage Upstream: 2 Downstream: 0
Published: 17 Jan 2020, 10:16
Last modified:16 Apr 2026, 04:26

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

17 Jan 2020, 10:16
Published
Vulnerability first disclosed
16 Apr 2026, 04:26
Last Modified
Vulnerability information updated

Description

Updated kernel packages fix security vulnerabilities This update is based on upstream 5.4.12 and fixes at least the following security vulnerabilities: Intel GPU Hardware prior to Gen11 does not clear EU state during a context switch. This can result in information leakage between contexts (CVE-2019-14615). A heap-based buffer overflow was discovered in the Marvell WiFi chip driver. The flaw could occur when the station attempts a connection negotiation during the handling of the remote devices country settings. This could allow the remote device to cause a denial of service (system crash) or possibly execute arbitrary code (CVE-2019-14895). For other fixes in this update, see the referenced changelogs.

Affected Systems

  • mageiakernel

    < 5.4.12-1.mga7

  • mageiakmod-virtualbox

    < 6.0.14-20.mga7

  • mageiakmod-xtables-addons

    < 3.7-10.mga7

References (4)