RHSA-2024:0575: Important: kernel security and bug fix update
Important: kernel security and bug fix update
Other sources
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: bpf: Incorrect verifier pruning leads to unsafe code paths being incorrectly marked as safe (CVE-2023-2163) kernel: net/sched: schqfq component can be exploited if in qfqchangeagg function happens qfqenqueue overhead (CVE-2023-3611) kernel: tun: bugs for oversize packet when napi frags enabled in tunnapiallocfrags (CVE-2023-3812) kernel: use after free in unixstreamsendpage (CVE-2023-4622) kernel: net/sched: schhfsc UAF (CVE-2023-4623) kernel: use after free in nvmettcpfreecrypto in NVMe (CVE-2023-5178) kernel: out-of-bounds write in qfqchangeclass function (CVE-2023-31436) kernel: IGB driver inadequate buffer size for frames larger than MTU (CVE-2023-45871) kernel: Race Condition leading to UAF in Unix Socket could happen in skreceivequeue (BZ#2230094) kernel: speculative pointer dereference in doprlimit() in kernel/sys.c (CVE-2023-0458) kernel: HID: check empty reportlist in hidvalidatevalues() (CVE-2023-1073) kernel: hid: Use After Free in asusremove() (CVE-2023-1079) kernel: Possible use-after-free since the two fdget() during vhostnetsetbackend() (CVE-2023-1838) kernel: UAF during login when accessing the shost ipaddress (CVE-2023-2162) kernel: use after free in vcsread in drivers/tty/vt/vcscreen.c due to race (CVE-2023-3567) kernel: xfrm: NULL pointer dereference in xfrmupdateaeparams() (CVE-2023-3772) kernel: smsusb: use-after-free caused by dosubmiturb() (CVE-2023-4132) kernel: A heap out-of-bounds write (CVE-2023-5717) kernel: denial of service in atmtcenqueue in net/sched/schatm.c due to type confusion (CVE-2023-23455) kernel: mpls: double free on sysctl allocation failure (CVE-2023-26545) kernel: Denial of service issue in az6027 driver in drivers/media/usb/dev-usb/az6027.c (CVE-2023-28328) kernel: net: qcom/emac: race condition leading to use-after-free in emacremove() (CVE-2023-33203) kernel: saa7134: race condition leading to use-after-free in saa7134finidev() (CVE-2023-35823) kernel: dm1105: race condition leading to use-after-free in dm1105remove.c() (CVE-2023-35824) kernel: r592: race condition leading to use-after-free in r592remove() (CVE-2023-35825) kernel: SEV-ES local priv escalation (CVE-2023-46813) kernel: net/tls: tlsistxready() checked listentry (CVE-2023-1075) kernel: use-after-free bug in remove function xgenehwmonremove (CVE-2023-1855) kernel: Use after free bug in r592remove (CVE-2023-3141) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): [RHEL 8.9] Proactively backport locking fixes from upstream (BZ#2235393)
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-abi-stableliststo a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-docto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-s390xto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-zfcpdumpto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-zfcpdump-coreto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-zfcpdump-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-zfcpdump-develto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-zfcpdump-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-zfcpdump-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64leto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-debuginfo-common-aarch64to a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8 - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 4.18.0-477.43.1.el8_8.aa - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.9Patch BZ#2235393 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.9Patch CVE-2023-2163
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0575?
The severity of RHSA-2024:0575 is rated as Important.
How do I fix RHSA-2024:0575?
To fix RHSA-2024:0575, update your kernel packages to version 4.18.0-477.43.1.el8_8.
What are the affected components in RHSA-2024:0575?
The affected components in RHSA-2024:0575 include the kernel, bpftool, and various associated packages.
What is the main issue addressed by RHSA-2024:0575?
RHSA-2024:0575 addresses a vulnerability related to incorrect verifier pruning in BPF leading to unsafe code paths.
Is RHSA-2024:0575 applicable to all Linux systems?
No, RHSA-2024:0575 is specifically applicable to supported versions of Red Hat Enterprise Linux.