MGASA-2021-0419

Advisory lineage Upstream: 4 Downstream: 0
Published: 08 Sept 2021, 09:23
Last modified:16 Apr 2026, 04:24

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

08 Sept 2021, 09:23
Published
Vulnerability first disclosed
16 Apr 2026, 04:24
Last Modified
Vulnerability information updated

Description

Updated kernel-linus packages fix security vulnerabilities This kernel-linus update is based on upstream 5.10.62 and fixes at least the following security issues: Specifically timed and handcrafted traffic can cause internal errors in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic in ath9k (CVE-2020-3702). A process with CAP_SYS_ADMIN can cause a kernel NULL pointer dereference in btrfs code (CVE-2021-3739). there is an out-of-bound read bug in qrtr_endpoint_post in net/qrtr/qrtr.c (CVE-2021-3743). An out-of-bounds read due to a race condition has been found in the Linux kernel due to write access to vc_mode is not protected by a lock in vt_ioctl (KDSETMDE) (CVE-2021-3753). For other upstream fixes, see the referenced changelogs.

Affected Systems

  • mageiakernel-linus

    < 5.10.62-1.mga8

References (4)