MGASA-2020-0355

Advisory lineage Upstream: 2 Downstream: 0
Published: 30 Aug 2020, 18:45
Last modified:16 Apr 2026, 04:25

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Aug 2020, 18:45
Published
Vulnerability first disclosed
16 Apr 2026, 04:25
Last Modified
Vulnerability information updated

Description

Updated kernel and kernel-linus packages fix security vulnerabilities This update is based on the upstream 5.7.19 kernel and fixes at least the following security issue: In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free-space-cache.c because the pointer to a left data structure can be the same as the pointer to a right data structure (CVE-2019-19448). A memory out-of-bounds read flaw was found in the Linux kernel's ext3/ext4 filesystem, in the way it accesses a directory with broken indexing. This flaw allows a local user to crash the system if the directory exists. The highest threat from this vulnerability is to system availability (CVE-2020-14314). For other upstream fixes and changes in this update, see the referenced changelogs. Also, the wireguard-tools package has been updated to version 1.0.20200827.

Affected Systems

  • mageiakernel

    < 5.7.19-1.mga7

  • mageiakernel-linus

    < 5.7.19-1.mga7

  • mageiakmod-virtualbox

    < 6.0.24-5.mga7

  • mageiakmod-xtables-addons

    < 3.10-3.mga7

  • mageiawireguard-tools

    < 1.0.20200827-1.mga7

References (10)