First published: Tue Sep 12 2023(Updated: )
The kernel packages contain the Linux kernel, the core of any Linux operating system.<br>The following packages have been upgraded to a later upstream version: kernel (5.14.0).<br>Security Fix(es):<br><li> kernel: UAF in nftables when nft_set_lookup_global triggered after handling named and anonymous sets in batch requests (CVE-2023-3390)</li> <li> kernel: netfilter: nf_tables: fix chain binding transaction logic in the abort path of NFT_MSG_NEWRULE (CVE-2023-3610)</li> <li> kernel: net/sched: cls_fw component can be exploited as result of failure in tcf_change_indev function (CVE-2023-3776)</li> <li> kernel: netfilter: use-after-free due to improper element removal in nft_pipapo_remove() (CVE-2023-4004)</li> <li> kernel: netfilter: nf_tables_newrule when adding a rule with NFTA_RULE_CHAIN_ID leads to use-after-free (CVE-2023-4147)</li> <li> kernel: nf_tables: use-after-free in nft_chain_lookup_byid() (CVE-2023-31248)</li> <li> kernel: nf_tables: stack-out-of-bounds-read in nft_byteorder_eval() (CVE-2023-35001)</li> <li> kernel: save/restore speculative MSRs during S3 suspend/resume (CVE-2023-1637)</li> <li> hw: amd: Cross-Process Information Leak (CVE-2023-20593)</li> <li> kernel: bypass of shadow stack protection due to a logic error (CVE-2023-21102)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> [Intel 9.3 BUG] [SPR][EMR][FHF] ACPI: Fix system hang during S3 wakeup (BZ#2218026)</li> <li> [Dell 9.2 BUG] Monitor lost after replug WD19TBS to SUT port wiith VGA/DVI to type-C dongle (BZ#2219463)</li> <li> rtmutex: Incorrect waiter woken when requeueing in rt_mutex_adjust_prio_chain() (BZ#2222121)</li> <li> RHEL AWS ARM Instability During Microshift e2e tests (BZ#2223310)</li> <li> RHEL 9.x updates for SEV-SNP guest support (BZ#2224587)</li> <li> Lock state corruption from nested rtmutex blocking in blk_flush_plug() (BZ#2225623)</li> <li> bpf_jit_limit hit again - copy_seccomp() fix (BZ#2226945)</li> <li> libceph: harden msgr2.1 frame segment length checks (BZ#2227070)</li> <li> Temporary values used for the FIPS integrity test should be zeroized after use (BZ#2227768)</li> <li> Important iavf bug fixes July 2023 (BZ#2228156)</li> <li> [i40e/ice] error: Cannot set interface MAC/vlanid to 1e:b7:e2:02:b1:aa/0 for ifname ens4f0 vf 0: Resource temporarily unavailable (BZ#2228158)</li> <li> lvconvert --splitcache, --uncache operations getting hung (BZ#2228481)</li> <li> perf: EMR core and uncore PMU support (BZ#2230175)</li> <li> NVIDIA - Grace: Backport i2c: tegra: Set ACPI node as primary fwnode (BZ#2230483)</li> <li> NVIDIA - Grace: Backport i2c: tegra: Fix PEC support for SMBUS block read (BZ#2230488)</li> <li> [Hyper-V][RHEL 9]incomplete fc_transport implementation in storvsc causes null dereference in fc_timed_out() (BZ#2230747)</li> <li> Kernel config option CONFIG_CRYPTO_STATS should be disabled until it is enhanced (BZ#2231850)</li> <li> [RHEL 9][Hyper-V]Excessive hv_storvsc driver logging with srb_status SRB_STATUS_INTERNAL_ERROR (0x30) (BZ#2231990)</li> <li> RHEL-9: WARNING: bad unlock balance detected! (BZ#2232213)</li> <li> NVIDIA - Grace: Backport drm/ast patch expected for kernel 6.4 (BZ#2232302)</li> <li> [Lenovo 9.1 bug] RHEL 9 will hang when "echo c > /proc/sysrq-trigger". (BZ#2232700)</li> <li> [RHEL-9] bz2022169 in /kernel/general/process/reg-suit fails on aarch64 (/proc/[pid]/wchan broken) (BZ#2233928)</li> Enhancement(s):<br><li> [Intel 9.3 FEAT] cpufreq: intel_pstate: Enable HWP IO boost for all servers (BZ#2210270)</li> <li> [Dell 9.3 FEAT] - New MB with AMP Codec Change on Maya Bay (audio driver) (BZ#2218960)</li> <li> [Lenovo 9.3 FEAT] MDRAID - Update to the latest upstream (BZ#2221170)</li> <li> [Intel 9.3 FEAT] [EMR] Add EMR support to uncore-frequency driver (BZ#2230169)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/bpftool | <7.0.0-284.30.1.el9_2 | 7.0.0-284.30.1.el9_2 |
redhat/bpftool-debuginfo | <7.0.0-284.30.1.el9_2 | 7.0.0-284.30.1.el9_2 |
redhat/kernel | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-abi-stablelists | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-core | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug-core | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug-debuginfo | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug-devel | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug-devel-matched | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug-modules | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug-modules-core | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug-modules-extra | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug-uki-virt | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debuginfo | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-devel | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-devel-matched | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-doc | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-headers | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-modules | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-modules-core | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-modules-extra | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-tools | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-tools-debuginfo | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-tools-libs | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-uki-virt | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/perf | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/perf-debuginfo | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/python3-perf | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/python3-perf-debuginfo | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/rtla | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/bpftool | <7.0.0-284.30.1.el9_2 | 7.0.0-284.30.1.el9_2 |
redhat/bpftool-debuginfo | <7.0.0-284.30.1.el9_2 | 7.0.0-284.30.1.el9_2 |
redhat/kernel-core | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug-core | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug-debuginfo | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug-devel | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug-devel-matched | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug-modules | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug-modules-core | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug-modules-extra | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debuginfo | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debuginfo-common-s390x | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-devel | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-devel-matched | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-headers | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-modules | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-modules-core | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-modules-extra | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-tools | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-tools-debuginfo | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-zfcpdump | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-zfcpdump-core | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-zfcpdump-debuginfo | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-zfcpdump-devel | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-zfcpdump-devel-matched | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-zfcpdump-modules | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-zfcpdump-modules-core | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-zfcpdump-modules-extra | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/perf | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/perf-debuginfo | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/python3-perf | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/python3-perf-debuginfo | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/rtla | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/bpftool | <7.0.0-284.30.1.el9_2 | 7.0.0-284.30.1.el9_2 |
redhat/bpftool-debuginfo | <7.0.0-284.30.1.el9_2 | 7.0.0-284.30.1.el9_2 |
redhat/kernel | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-core | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug-core | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug-debuginfo | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug-devel | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug-devel-matched | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug-modules | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug-modules-core | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debug-modules-extra | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debuginfo | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-debuginfo-common-ppc64le | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-devel | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-devel-matched | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-headers | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-modules | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-modules-core | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-modules-extra | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-tools | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-tools-debuginfo | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-tools-libs | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/perf | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/perf-debuginfo | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/python3-perf | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/python3-perf-debuginfo | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/rtla | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/bpftool | <7.0.0-284.30.1.el9_2.aa | 7.0.0-284.30.1.el9_2.aa |
redhat/bpftool-debuginfo | <7.0.0-284.30.1.el9_2.aa | 7.0.0-284.30.1.el9_2.aa |
redhat/kernel | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/kernel | <64k-5.14.0-284.30.1.el9_2.aa | 64k-5.14.0-284.30.1.el9_2.aa |
redhat/kernel | <64k-core-5.14.0-284.30.1.el9_2.aa | 64k-core-5.14.0-284.30.1.el9_2.aa |
redhat/kernel | <64k-debug-5.14.0-284.30.1.el9_2.aa | 64k-debug-5.14.0-284.30.1.el9_2.aa |
redhat/kernel | <64k-debug-core-5.14.0-284.30.1.el9_2.aa | 64k-debug-core-5.14.0-284.30.1.el9_2.aa |
redhat/kernel | <64k-debug-debuginfo-5.14.0-284.30.1.el9_2.aa | 64k-debug-debuginfo-5.14.0-284.30.1.el9_2.aa |
redhat/kernel | <64k-debug-devel-5.14.0-284.30.1.el9_2.aa | 64k-debug-devel-5.14.0-284.30.1.el9_2.aa |
redhat/kernel | <64k-debug-devel-matched-5.14.0-284.30.1.el9_2.aa | 64k-debug-devel-matched-5.14.0-284.30.1.el9_2.aa |
redhat/kernel | <64k-debug-modules-5.14.0-284.30.1.el9_2.aa | 64k-debug-modules-5.14.0-284.30.1.el9_2.aa |
redhat/kernel | <64k-debug-modules-core-5.14.0-284.30.1.el9_2.aa | 64k-debug-modules-core-5.14.0-284.30.1.el9_2.aa |
redhat/kernel | <64k-debug-modules-extra-5.14.0-284.30.1.el9_2.aa | 64k-debug-modules-extra-5.14.0-284.30.1.el9_2.aa |
redhat/kernel | <64k-debuginfo-5.14.0-284.30.1.el9_2.aa | 64k-debuginfo-5.14.0-284.30.1.el9_2.aa |
redhat/kernel | <64k-devel-5.14.0-284.30.1.el9_2.aa | 64k-devel-5.14.0-284.30.1.el9_2.aa |
redhat/kernel | <64k-devel-matched-5.14.0-284.30.1.el9_2.aa | 64k-devel-matched-5.14.0-284.30.1.el9_2.aa |
redhat/kernel | <64k-modules-5.14.0-284.30.1.el9_2.aa | 64k-modules-5.14.0-284.30.1.el9_2.aa |
redhat/kernel | <64k-modules-core-5.14.0-284.30.1.el9_2.aa | 64k-modules-core-5.14.0-284.30.1.el9_2.aa |
redhat/kernel | <64k-modules-extra-5.14.0-284.30.1.el9_2.aa | 64k-modules-extra-5.14.0-284.30.1.el9_2.aa |
redhat/kernel-core | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/kernel-debug | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/kernel-debug-core | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/kernel-debug-debuginfo | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/kernel-debug-devel | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/kernel-debug-devel-matched | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/kernel-debug-modules | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/kernel-debug-modules-core | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/kernel-debug-modules-extra | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/kernel-debuginfo | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/kernel-debuginfo-common-aarch64 | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/kernel-devel | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/kernel-devel-matched | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/kernel-headers | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/kernel-modules | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/kernel-modules-core | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/kernel-modules-extra | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/kernel-tools | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/kernel-tools-debuginfo | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/kernel-tools-libs | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/perf | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/perf-debuginfo | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/python3-perf | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/python3-perf-debuginfo | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/rtla | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/kernel-cross-headers | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-tools-libs-devel | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-cross-headers | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-tools-libs-devel | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
redhat/kernel-cross-headers | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/kernel-tools-libs-devel | <5.14.0-284.30.1.el9_2.aa | 5.14.0-284.30.1.el9_2.aa |
redhat/kernel-cross-headers | <5.14.0-284.30.1.el9_2 | 5.14.0-284.30.1.el9_2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.