RHSA-2023:1662: Important: kpatch-patch security update
This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.Security Fix(es): ALSA: pcm: Move rwsem lock inside sndctlelemread to prevent UAF (CVE-2023-0266) kernel: net/ulp: use-after-free in listening ULP sockets (CVE-2023-0461) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_65_1-1-5.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_71_1-1-4.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_72_1-1-3.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_76_1-1-2.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_82_1-1-1.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_65_1-debuginfo-1-5.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_65_1-debugsource-1-5.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_71_1-debuginfo-1-4.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_71_1-debugsource-1-4.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_72_1-debuginfo-1-3.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_72_1-debugsource-1-3.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_76_1-debuginfo-1-2.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_76_1-debugsource-1-2.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_82_1-debuginfo-1-1.el8_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-305_82_1-debugsource-1-1.el8_4 - Compensating control
Ensure the kpatch-patch security update is installed and that the kpatch live patch module is loaded (the RPM post-install script automatically loads the module to modify a running kernel).
Event History
Frequently Asked Questions
What security issues does RHSA-2023:1662 address?
RHSA-2023:1662 addresses vulnerabilities related to the ALSA subsystem, particularly a use-after-free issue in the PCM interface (CVE-2023-0266).
How can I remediate RHSA-2023:1662?
To remediate RHSA-2023:1662, you should update the kpatch-patch package to one of the patched versions specified in the advisory.
What versions of kpatch-patch are affected by RHSA-2023:1662?
The affected versions of kpatch-patch for RHSA-2023:1662 include versions prior to 4_18_0-305_82_1-1-1.el8_4.
Is RHSA-2023:1662 severity rated?
Yes, RHSA-2023:1662 is classified with an important severity rating due to the nature of the vulnerabilities it addresses.
What is the impact of not addressing RHSA-2023:1662?
Failure to address RHSA-2023:1662 may leave the system vulnerable to exploitation through the identified use-after-free issues.