RHSA-2024:0340: Important: kpatch-patch security update
Important: kpatch-patch security update
Other sources
This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.Security Fix(es): kernel: tun: bugs for oversize packet when napi frags enabled in tunnapiallocfrags (CVE-2023-3812) kernel: net/sched: schhfsc UAF (CVE-2023-4623) kernel: use after free in unixstreamsendpage (CVE-2023-4622) kernel: netfilter: potential slab-out-of-bound access due to integer underflow (CVE-2023-42753) kernel: use after free in nvmettcpfreecrypto in NVMe (CVE-2023-5178) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0340?
RHSA-2024:0340 has been classified as an important security update due to potential bugs in the kernel's tun module.
How do I fix RHSA-2024:0340?
To fix RHSA-2024:0340, you should update the kpatch-patch package to the recommended versions as specified in the advisory.
What software is affected by RHSA-2024:0340?
RHSA-2024:0340 affects Red Hat Enterprise Linux for x86_64 and ppc64le architectures, specifically the kpatch-patch package.
What vulnerabilities are addressed in RHSA-2024:0340?
RHSA-2024:0340 addresses vulnerabilities related to oversize packet handling in the kernel's tun module when napi frags are enabled.
When was RHSA-2024:0340 released?
RHSA-2024:0340 was released on a specified date in January 2024, acknowledging important security fixes.