RHSA-2023:4138: Important: kernel-rt security and bug fix update
Important: kernel-rt security and bug fix update
Other sources
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): kernel: use-after-free in l2capconnect and l2capleconnectreq in net/bluetooth/l2capcore.c (CVE-2022-42896) kernel: use-after-free vulnerability in the perfgroupdetach function of the Linux Kernel Performance Events (CVE-2023-2235) kernel: uninitialized registers on stack in nftdochain can cause kernel pointer leakage to UM (CVE-2022-1016) kernel: use-after-free related to leaf anonvma double reuse (CVE-2022-42703) Kernel: bluetooth: Unauthorized management command execution (CVE-2023-2002) kernel: OOB access in the Linux kernel's XFS subsystem (CVE-2023-2124) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): kernel-rt: update RT source tree to the latest RHEL-9.0.z10 Batch (BZ#2209984)
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:4138?
The severity of RHSA-2023:4138 is high with a severity value of 7.
What software is affected by RHSA-2023:4138?
Red Hat Enterprise Linux for Real Time for x86_64 - 4 years of updates, Red Hat Enterprise Linux for Real Time for NFV for x86_64 - 4 years of updates, kernel-rt, kernel-rt-core, kernel-rt-debug, kernel-rt-debug-core, kernel-rt-debug-debuginfo, kernel-rt-debug-devel, kernel-rt-debug-modules, kernel-rt-debug-modules-extra, kernel-rt-debuginfo, kernel-rt-devel, kernel-rt-modules, kernel-rt-modules-extra, kernel-rt-debug-kvm, and kernel-rt-kvm are affected by RHSA-2023:4138.
What is the remedy for RHSA-2023:4138?
The remedy for RHSA-2023:4138 is to update to version 5.14.0-70.64.1.rt21.135.el9_0.
Where can I find more information about RHSA-2023:4138?
You can find more information about RHSA-2023:4138 on the Red Hat Customer Portal at https://access.redhat.com/errata/RHSA-2023:4138.
Does RHSA-2023:4138 have a Common Weakness Enumeration (CWE)?
Yes, RHSA-2023:4138 has a Common Weakness Enumeration (CWE) of 416.