RHSA-2023:1841: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: net/ulp: use-after-free in listening ULP sockets (CVE-2023-0461) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): xfsbuf deadlock between inode deletion and block allocation (aarch64) (BZ#2164266) mlx5:CX6-DX: [IPsec crypto-offload, IPv6, TCP, Tunnel] tcp traffic is broken on IPsec crypto-offload over IPv6 (BZ#2165492) Windows Server 2019 guest randomly pauses with "KVM: entry failed, hardware error 0x80000021" (BZ#2166369) MSFT MANA NET Patch RHEL-8: Fix accessing freed irq affinityhint (BZ#2175252) Ethernet Port Configuration Tool (EPCT) not supported with in-tree ice driver (BZ#2176866) Application Performance impact on cgroup v2 (BZ#2177793) In FIPS mode, kernel does not transition into error state when RCT or APT health tests fail (BZ#2181732)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-abi-stableliststo a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-docto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-s390xto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-zfcpdumpto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-zfcpdump-coreto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-zfcpdump-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-zfcpdump-develto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-zfcpdump-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-zfcpdump-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64leto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-debuginfo-common-aarch64to a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6 - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 4.18.0-372.52.1.el8_6.aa - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2177793 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2176866 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2181732 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2175252 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2166369 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2165492 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#2164266 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2023-0461 - Operational
Reboot the system after applying this kernel security and bug fix update so the changes take effect.
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:1841?
The severity of RHSA-2023:1841 is classified as important due to a use-after-free vulnerability in the Linux kernel.
How do I fix RHSA-2023:1841?
To fix RHSA-2023:1841, update the affected kernel packages to version 4.18.0-372.52.1.el8_6 or later.
What systems are affected by RHSA-2023:1841?
RHSA-2023:1841 affects systems running the Linux kernel packages prior to version 4.18.0-372.52.1.el8_6.
What does RHSA-2023:1841 address?
RHSA-2023:1841 addresses a use-after-free vulnerability in listening ULP sockets that could lead to potential escalation of privileges.
Is a reboot required after applying the update for RHSA-2023:1841?
Yes, a reboot is necessary after updating the kernel packages to ensure the changes take effect.