RHSA-2023:5069: Important: kernel security, bug fix, and enhancement update
The kernel packages contain the Linux kernel, the core of any Linux operating system.The following packages have been upgraded to a later upstream version: kernel (5.14.0).Security Fix(es): kernel: UAF in nftables when nftsetlookupglobal triggered after handling named and anonymous sets in batch requests (CVE-2023-3390) kernel: netfilter: nftables: fix chain binding transaction logic in the abort path of NFTMSGNEWRULE (CVE-2023-3610) kernel: net/sched: clsfw component can be exploited as result of failure in tcfchangeindev function (CVE-2023-3776) kernel: netfilter: use-after-free due to improper element removal in nftpipaporemove() (CVE-2023-4004) kernel: netfilter: nftablesnewrule when adding a rule with NFTARULECHAINID leads to use-after-free (CVE-2023-4147) kernel: nftables: use-after-free in nftchainlookupbyid() (CVE-2023-31248) kernel: nftables: stack-out-of-bounds-read in nftbyteordereval() (CVE-2023-35001) kernel: save/restore speculative MSRs during S3 suspend/resume (CVE-2023-1637) hw: amd: Cross-Process Information Leak (CVE-2023-20593) kernel: bypass of shadow stack protection due to a logic error (CVE-2023-21102) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): [Intel 9.3 BUG] [SPR][EMR][FHF] ACPI: Fix system hang during S3 wakeup (BZ#2218026) [Dell 9.2 BUG] Monitor lost after replug WD19TBS to SUT port wiith VGA/DVI to type-C dongle (BZ#2219463) rtmutex: Incorrect waiter woken when requeueing in rtmutexadjustpriochain() (BZ#2222121) RHEL AWS ARM Instability During Microshift e2e tests (BZ#2223310) RHEL 9.x updates for SEV-SNP guest support (BZ#2224587) Lock state corruption from nested rtmutex blocking in blkflushplug() (BZ#2225623) bpfjitlimit hit again - copyseccomp() fix (BZ#2226945) libceph: harden msgr2.1 frame segment length checks (BZ#2227070) Temporary values used for the FIPS integrity test should be zeroized after use (BZ#2227768) Important iavf bug fixes July 2023 (BZ#2228156) [i40e/ice] error: Cannot set interface MAC/vlanid to 1e:b7:e2:02:b1:aa/0 for ifname ens4f0 vf 0: Resource temporarily unavailable (BZ#2228158) lvconvert --splitcache, --uncache operations getting hung (BZ#2228481) perf: EMR core and uncore PMU support (BZ#2230175) NVIDIA - Grace: Backport i2c: tegra: Set ACPI node as primary fwnode (BZ#2230483) NVIDIA - Grace: Backport i2c: tegra: Fix PEC support for SMBUS block read (BZ#2230488) [Hyper-V][RHEL 9]incomplete fctransport implementation in storvsc causes null dereference in fctimedout() (BZ#2230747) Kernel config option CONFIGCRYPTOSTATS should be disabled until it is enhanced (BZ#2231850) [RHEL 9][Hyper-V]Excessive hvstorvsc driver logging with srbstatus SRBSTATUSINTERNALERROR (0x30) (BZ#2231990) RHEL-9: WARNING: bad unlock balance detected! (BZ#2232213) NVIDIA - Grace: Backport drm/ast patch expected for kernel 6.4 (BZ#2232302) [Lenovo 9.1 bug] RHEL 9 will hang when "echo c > /proc/sysrq-trigger". (BZ#2232700) [RHEL-9] bz2022169 in /kernel/general/process/reg-suit fails on aarch64 (/proc/[pid]/wchan broken) (BZ#2233928) Enhancement(s): [Intel 9.3 FEAT] cpufreq: intelpstate: Enable HWP IO boost for all servers (BZ#2210270) [Dell 9.3 FEAT] - New MB with AMP Codec Change on Maya Bay (audio driver) (BZ#2218960) [Lenovo 9.3 FEAT] MDRAID - Update to the latest upstream (BZ#2221170) [Intel 9.3 FEAT] [EMR] Add EMR support to uncore-frequency driver (BZ#2230169)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:5069?
The severity of RHSA-2023:5069 is currently classified as important.
How do I fix RHSA-2023:5069?
To fix RHSA-2023:5069, upgrade to kernel version 5.14.0-284.30.1.el9_2 or later.
What packages are affected by RHSA-2023:5069?
Affected packages include kernel, kernel-core, kernel-debug, and bpftool among others.
When was the RHSA-2023:5069 advisory released?
The RHSA-2023:5069 advisory was released on October 6, 2023.
What types of vulnerabilities does RHSA-2023:5069 address?
RHSA-2023:5069 addresses a use-after-free (UAF) vulnerability in nftables.