First published: Wed Apr 05 2023(Updated: )
This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.<br>Security Fix(es):<br><li> ALSA: pcm: Move rwsem lock inside snd_ctl_elem_read to prevent UAF (CVE-2023-0266)</li> <li> kernel: net/ulp: use-after-free in listening ULP sockets (CVE-2023-0461)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kpatch-patch | <4_18_0-305_65_1-1-5.el8_4 | 4_18_0-305_65_1-1-5.el8_4 |
redhat/kpatch-patch | <4_18_0-305_71_1-1-4.el8_4 | 4_18_0-305_71_1-1-4.el8_4 |
redhat/kpatch-patch | <4_18_0-305_72_1-1-3.el8_4 | 4_18_0-305_72_1-1-3.el8_4 |
redhat/kpatch-patch | <4_18_0-305_76_1-1-2.el8_4 | 4_18_0-305_76_1-1-2.el8_4 |
redhat/kpatch-patch | <4_18_0-305_82_1-1-1.el8_4 | 4_18_0-305_82_1-1-1.el8_4 |
redhat/kpatch-patch | <4_18_0-305_65_1-1-5.el8_4 | 4_18_0-305_65_1-1-5.el8_4 |
redhat/kpatch-patch | <4_18_0-305_65_1-debuginfo-1-5.el8_4 | 4_18_0-305_65_1-debuginfo-1-5.el8_4 |
redhat/kpatch-patch | <4_18_0-305_65_1-debugsource-1-5.el8_4 | 4_18_0-305_65_1-debugsource-1-5.el8_4 |
redhat/kpatch-patch | <4_18_0-305_71_1-1-4.el8_4 | 4_18_0-305_71_1-1-4.el8_4 |
redhat/kpatch-patch | <4_18_0-305_71_1-debuginfo-1-4.el8_4 | 4_18_0-305_71_1-debuginfo-1-4.el8_4 |
redhat/kpatch-patch | <4_18_0-305_71_1-debugsource-1-4.el8_4 | 4_18_0-305_71_1-debugsource-1-4.el8_4 |
redhat/kpatch-patch | <4_18_0-305_72_1-1-3.el8_4 | 4_18_0-305_72_1-1-3.el8_4 |
redhat/kpatch-patch | <4_18_0-305_72_1-debuginfo-1-3.el8_4 | 4_18_0-305_72_1-debuginfo-1-3.el8_4 |
redhat/kpatch-patch | <4_18_0-305_72_1-debugsource-1-3.el8_4 | 4_18_0-305_72_1-debugsource-1-3.el8_4 |
redhat/kpatch-patch | <4_18_0-305_76_1-1-2.el8_4 | 4_18_0-305_76_1-1-2.el8_4 |
redhat/kpatch-patch | <4_18_0-305_76_1-debuginfo-1-2.el8_4 | 4_18_0-305_76_1-debuginfo-1-2.el8_4 |
redhat/kpatch-patch | <4_18_0-305_76_1-debugsource-1-2.el8_4 | 4_18_0-305_76_1-debugsource-1-2.el8_4 |
redhat/kpatch-patch | <4_18_0-305_82_1-1-1.el8_4 | 4_18_0-305_82_1-1-1.el8_4 |
redhat/kpatch-patch | <4_18_0-305_82_1-debuginfo-1-1.el8_4 | 4_18_0-305_82_1-debuginfo-1-1.el8_4 |
redhat/kpatch-patch | <4_18_0-305_82_1-debugsource-1-1.el8_4 | 4_18_0-305_82_1-debugsource-1-1.el8_4 |
redhat/kpatch-patch | <4_18_0-305_65_1-1-5.el8_4 | 4_18_0-305_65_1-1-5.el8_4 |
redhat/kpatch-patch | <4_18_0-305_65_1-debuginfo-1-5.el8_4 | 4_18_0-305_65_1-debuginfo-1-5.el8_4 |
redhat/kpatch-patch | <4_18_0-305_65_1-debugsource-1-5.el8_4 | 4_18_0-305_65_1-debugsource-1-5.el8_4 |
redhat/kpatch-patch | <4_18_0-305_71_1-1-4.el8_4 | 4_18_0-305_71_1-1-4.el8_4 |
redhat/kpatch-patch | <4_18_0-305_71_1-debuginfo-1-4.el8_4 | 4_18_0-305_71_1-debuginfo-1-4.el8_4 |
redhat/kpatch-patch | <4_18_0-305_71_1-debugsource-1-4.el8_4 | 4_18_0-305_71_1-debugsource-1-4.el8_4 |
redhat/kpatch-patch | <4_18_0-305_72_1-1-3.el8_4 | 4_18_0-305_72_1-1-3.el8_4 |
redhat/kpatch-patch | <4_18_0-305_72_1-debuginfo-1-3.el8_4 | 4_18_0-305_72_1-debuginfo-1-3.el8_4 |
redhat/kpatch-patch | <4_18_0-305_72_1-debugsource-1-3.el8_4 | 4_18_0-305_72_1-debugsource-1-3.el8_4 |
redhat/kpatch-patch | <4_18_0-305_76_1-1-2.el8_4 | 4_18_0-305_76_1-1-2.el8_4 |
redhat/kpatch-patch | <4_18_0-305_76_1-debuginfo-1-2.el8_4 | 4_18_0-305_76_1-debuginfo-1-2.el8_4 |
redhat/kpatch-patch | <4_18_0-305_76_1-debugsource-1-2.el8_4 | 4_18_0-305_76_1-debugsource-1-2.el8_4 |
redhat/kpatch-patch | <4_18_0-305_82_1-1-1.el8_4 | 4_18_0-305_82_1-1-1.el8_4 |
redhat/kpatch-patch | <4_18_0-305_82_1-debuginfo-1-1.el8_4 | 4_18_0-305_82_1-debuginfo-1-1.el8_4 |
redhat/kpatch-patch | <4_18_0-305_82_1-debugsource-1-1.el8_4 | 4_18_0-305_82_1-debugsource-1-1.el8_4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2023:1662 addresses vulnerabilities related to the ALSA subsystem, particularly a use-after-free issue in the PCM interface (CVE-2023-0266).
To remediate RHSA-2023:1662, you should update the kpatch-patch package to one of the patched versions specified in the advisory.
The affected versions of kpatch-patch for RHSA-2023:1662 include versions prior to 4_18_0-305_82_1-1-1.el8_4.
Yes, RHSA-2023:1662 is classified with an important severity rating due to the nature of the vulnerabilities it addresses.
Failure to address RHSA-2023:1662 may leave the system vulnerable to exploitation through the identified use-after-free issues.