This update is based on upstream 5.4.10 and fixes at least the following security issues:
ext4_empty_dir in fs/ext4/namei.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because ext4_read_dirblock(inode,0,DIRENT_HTREE) can be zero. (CVE-2019-19037)
It also fixes various potential security issues related to buffer overflows, double frees, NUll pointer dereferences, improper / missing input validations and so on.
Other fixes added in this update:
WireGuard kernel module has been updated to 0.0.20200105 and the tools has been updated to 1.0.20200102.
For other fixes in this update, see the referenced changelogs.