{"id":"MGASA-2021-0348","summary":"Updated kernel-linus packages fix security vulnerabilities","details":"This kernel-linus update is based on upstream 5.10.48 and fixes at least the\nfollowing security issues:\n\nThe Linux kernel through 5.8.13 does not properly enforce the Secure Boot\nForbidden Signature Database (aka dbx) protection mechanism. This affects\ncerts/blacklist.c and certs/system_keyring.c (CVE-2020-26541).\n\nAn issue was discovered in Linux: KVM through Improper handling of VM_IO|\nVM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being\nfreed while still accessible by the VMM and guest. This allows users with\nthe ability to start and control a VM to read/write random pages of memory\nand can result in local privilege escalation (CVE-2021-22543).\n\nkernel/module.c in the Linux kernel before 5.12.14 mishandles Signature\nVerification. Without CONFIG_MODULE_SIG, verification that a kernel module\nis signed, for loading via init_module, does not occur for a\nmodule.sig_enforce=1 command-line argument (CVE-2021-35039).\n\nFor other upstream fixes, see the referenced changelogs.\n","modified":"2026-04-16T04:44:33.339431055Z","published":"2021-07-12T20:26:21Z","upstream":["CVE-2020-26541","CVE-2021-22543","CVE-2021-35039"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2021-0348.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=29236"},{"type":"WEB","url":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.47"},{"type":"WEB","url":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.48"}],"affected":[{"package":{"name":"kernel-linus","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/kernel-linus?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.48-1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0348.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}