RHSA-2024:0724: Important: kernel security and bug fix update
Important: kernel security and bug fix update
Other sources
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: use-after-free in schqfq network scheduler (CVE-2023-4921) kernel: inactive elements in nftpipapowalk (CVE-2023-6817) kernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destination (CVE-2024-0646) kernel: use-after-free vulnerability in function scosocksendmsg() (CVE-2021-3640) kernel: improper input validation may lead to privilege escalation (CVE-2021-4204) kernel: memory leak for large arguments in videousercopy function in drivers/media/v4l2-core/v4l2-ioctl.c (CVE-2021-30002) kernel: eBPF verification flaw (CVE-2021-34866) kernel: smb2ioctlqueryinfo NULL pointer dereference (CVE-2022-0168) kernel: Linux ebpf logic vulnerability leads to critical memory read and write gaining root privileges (CVE-2022-0500) kernel: NULL pointer dereference in udfexpandfileadinicbdue() during writeback (CVE-2022-0617) kernel: possible race condition in drivers/tty/ttybuffers.c (CVE-2022-1462) kernel: buffer overflow in nftsetdescconcatparse() (CVE-2022-2078) kernel: nftables cross-table potential use-after-free may lead to local privilege escalation (CVE-2022-2586) kernel: netfilter: nfconntrackirc message handling issue (CVE-2022-2663) kernel: memory leak in ipv6renewoptions() (CVE-2022-3524) kernel: nfp: use-after-free in areacacheget() (CVE-2022-3545) kernel: data races around icsk->icskafops in doipv6setsockopt (CVE-2022-3566) kernel: Rate limit overflow messages in r8152 in intrcallback (CVE-2022-3594) kernel: memory leak in l2caprecvacldata of the file net/bluetooth/l2capcore.c (CVE-2022-3619) kernel: denial of service in followpagepte in mm/gup.c due to poisoned pte entry (CVE-2022-3623) kernel: Double-free in split2MBgttentry when function intelgvtdmamapguestpage failed (CVE-2022-3707) kernel: possible to use the debugger to write zero into a location of choice (CVE-2022-21499) kernel: local privileges escalation in kernel/bpf/verifier.c (CVE-2022-23222) kernel: Executable Space Protection Bypass (CVE-2022-25265) kernel: double free in usb8devstartxmit in drivers/net/can/usb/usb8dev.c (CVE-2022-28388) kernel: double free in emsusbstartxmit in drivers/net/can/usb/emsusb.c (CVE-2022-28390)
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-abi-stableliststo a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-docto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-s390xto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-zfcpdumpto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-zfcpdump-coreto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-zfcpdump-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-zfcpdump-develto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-zfcpdump-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-zfcpdump-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64leto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-debuginfo-common-aarch64to a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6 - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 4.18.0-372.91.1.el8_6.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0724?
RHSA-2024:0724 is classified as important due to the presence of security fixes.
What vulnerabilities does RHSA-2024:0724 address?
RHSA-2024:0724 addresses a use-after-free vulnerability in the sch_qfq network scheduler and issues with inactive elements in nft_pipapo_walk.
How do I fix RHSA-2024:0724?
To fix RHSA-2024:0724, you should update your kernel packages to version 4.18.0-372.91.1.el8_6.
Which packages are affected by RHSA-2024:0724?
RHSA-2024:0724 affects multiple packages including kernel, bpftool, and kernel-core among others.
Is it necessary to reboot my system after applying RHSA-2024:0724?
Yes, a reboot is generally recommended to ensure all changes from the RHSA-2024:0724 update take effect.