RHSA-2024:0432: Important: kernel security and bug fix update
Important: kernel security and bug fix update
Other sources
The kernel packages contain the Linux kernel, the core of any Linux operatingsystem.Security Fix(es): kernel: xfrmexpandpolicies() in net/xfrm/xfrmpolicy.c can cause a refcount to be dropped twice (CVE-2022-36879) kernel: null-ptr-deref vulnerabilities in sltxtimeout in drivers/net/slip (CVE-2022-41858) kernel: use-after-free caused by invalid pointer hostname in fs/cifs/connect.c (CVE-2023-1195) kernel: UAF during login when accessing the shost ipaddress (CVE-2023-2162) kernel: use after free in vcsread in drivers/tty/vt/vcscreen.c due to race (CVE-2023-3567) kernel: use-after-free in netfilter: nftables (CVE-2023-3777) kernel: net/sched: schhfsc UAF (CVE-2023-4623) kernel: use after free in nvmettcpfreecrypto in NVMe (CVE-2023-5178) kernel: IGB driver inadequate buffer size for frames larger than MTU (CVE-2023-45871) kernel: SEV-ES local priv escalation (CVE-2023-46813) Bug Fix(es): RHEL 9 Hyper-V: Excessive hvstorvsc driver logging with srbstatus SRBSTATUSINTERNALERROR (0x30) RHEL9.0 - s390/qeth: NET2016 - fix use-after-free in HSCI DM multipath showing failed path for an nvme-o-FC LUN when performing I/O operations XFS: sync to upstream v5.15 AMDSERVER 9.4 Bug, Turin: Support larger microcode patches
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-abi-stableliststo a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-debug-devel-matchedto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-devel-matchedto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-docto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-s390xto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-zfcpdumpto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-zfcpdump-coreto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-zfcpdump-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-zfcpdump-develto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-zfcpdump-devel-matchedto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-zfcpdump-modulesto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-zfcpdump-modules-extrato a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64leto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-debug-devel-matchedto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-debuginfo-common-aarch64to a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-devel-matchedto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0 - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 5.14.0-70.85.1.el9_0.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0432?
The severity of RHSA-2024:0432 is classified as Important.
How do I fix RHSA-2024:0432?
To fix RHSA-2024:0432, you should update the kernel package to version 5.14.0-70.85.1.el9_0.
What vulnerabilities are addressed in RHSA-2024:0432?
RHSA-2024:0432 addresses CVE-2022-36879, which can result in a refcount being dropped twice.
Which systems are affected by RHSA-2024:0432?
RHSA-2024:0432 affects Red Hat Enterprise Linux for ARM 64, Power LE, and various other architectures.
Is RHSA-2024:0432 applicable to non-Red Hat systems?
No, RHSA-2024:0432 is specifically for Red Hat Enterprise Linux and does not apply to non-Red Hat systems.