RHSA-2023:5548: Important: kpatch-patch security update
Important: kpatch-patch security update
Other sources
This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.Security Fix(es): kernel: ipvlan: out-of-bounds write caused by unclear skb->cb (CVE-2023-3090) kernel: netfilter: use-after-free due to improper element removal in nftpipaporemove() (CVE-2023-4004) kernel: net/sched: Use-after-free vulnerabilities in the net/sched classifiers: clsfw, clsu32 and clsroute (CVE-2023-4128) kernel: nftables: stack-out-of-bounds-read in nftbyteordereval() (CVE-2023-35001) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_46_1-1-6.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_51_1-1-5.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_52_1-1-4.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_57_1-1-3.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_64_1-1-2.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_70_1-1-1.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_46_1-debuginfo-1-6.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_46_1-debugsource-1-6.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_51_1-debuginfo-1-5.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_51_1-debugsource-1-5.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_52_1-debuginfo-1-4.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_52_1-debugsource-1-4.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_57_1-debuginfo-1-3.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_57_1-debugsource-1-3.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_64_1-debuginfo-1-2.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_64_1-debugsource-1-2.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_70_1-debuginfo-1-1.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_70_1-debugsource-1-1.el8_6 - Upgrade
Upgrade
kernel (kpatch-patch live patch module)to a version that resolves this vulnerability.Patch kpatch-patch security update - Compensating control
Use the kpatch-patch security update that is automatically loaded by the RPM post-install script to modify the code of a running kernel, as described for applying this advisory in https://access.redhat.com/articles/11258 (covers fixes for CVE-2023-4128, CVE-2023-4004, CVE-2023-35001, and CVE-2023-3090).
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:5548?
RHSA-2023:5548 is classified as an important security update.
How do I fix RHSA-2023:5548?
To resolve RHSA-2023:5548, update the kpatch-patch package to version 4_18_0-372_70_1-1-1.el8_6 or later.
Which systems are affected by RHSA-2023:5548?
RHSA-2023:5548 affects various versions of Red Hat Enterprise Linux, including Power and x86_64 architectures.
Is RHSA-2023:5548 related to a specific vulnerability?
Yes, RHSA-2023:5548 addresses security vulnerabilities pertaining to the kpatch-patch package.
What is the expected outcome after applying RHSA-2023:5548?
After applying RHSA-2023:5548, systems will have improved security and protection against identified vulnerabilities.