RHSA-2024:0897: Important: kernel security update
Important: kernel security update
Other sources
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: net/sched: schhfsc UAF (CVE-2023-4623) kernel: use-after-free in schqfq network scheduler (CVE-2023-4921) kernel: inactive elements in nftpipapowalk (CVE-2023-6817) kernel: IGB driver inadequate buffer size for frames larger than MTU (CVE-2023-45871) kernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destination (CVE-2024-0646) kernel: nfp: use-after-free in areacacheget() (CVE-2022-3545) kernel: null-ptr-deref vulnerabilities in sltxtimeout in drivers/net/slip (CVE-2022-41858) kernel: HID: check empty reportlist in hidvalidatevalues() (CVE-2023-1073) kernel: Possible use-after-free since the two fdget() during vhostnetsetbackend() (CVE-2023-1838) kernel: NULL pointer dereference in canrcvfilter (CVE-2023-2166) kernel: Slab-out-of-bound read in comparenetdevandip (CVE-2023-2176) kernel: A heap out-of-bounds write when function perfreadgroup is called and siblinglist is smaller than its child's siblinglist (CVE-2023-5717) kernel: NULL pointer dereference in nvmettcpbuildiovec (CVE-2023-6356) kernel: NULL pointer dereference in nvmettcpexecuterequest (CVE-2023-6535) kernel: NULL pointer dereference in nvmetreqcomplete (CVE-2023-6536) kernel: Out-Of-Bounds Read vulnerability in smbCalcSize (CVE-2023-6606) kernel: OOB Access in smb2dumpdetail (CVE-2023-6610) kernel: use-after-free in l2capsockrelease in net/bluetooth/l2capsock.c (CVE-2023-40283) kernel: SEV-ES local priv escalation (CVE-2023-46813) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0897?
The severity of RHSA-2024:0897 is classified as important due to identified vulnerabilities in the kernel packages.
How do I fix RHSA-2024:0897?
To fix RHSA-2024:0897, you need to update your kernel packages to version 4.18.0-513.18.1.el8_9.
What vulnerabilities are addressed in RHSA-2024:0897?
RHSA-2024:0897 addresses vulnerabilities including a use-after-free in the sch_qfq network scheduler and a UAF in the sch_hfsc.
Which Red Hat products are affected by RHSA-2024:0897?
Red Hat CodeReady Linux Builder for ARM 64 and Power, little endian, among other kernel-related packages, are affected by RHSA-2024:0897.
Is RHSA-2024:0897 related to CVE-2023-4623 or CVE-2023-4921?
Yes, RHSA-2024:0897 specifically addresses vulnerabilities documented as CVE-2023-4623 and CVE-2023-4921.