RHSA-2024:0937: Important: kpatch-patch security update
Important: kpatch-patch security update
Other sources
This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.Security Fix(es): kernel: GSM multiplexing race condition leads to privilege escalation (CVE-2023-6546) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_64_1-1-6.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_70_1-1-5.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_75_1-1-4.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_80_1-1-3.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_87_1-1-2.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_91_1-1-1.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_64_1-debuginfo-1-6.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_64_1-debugsource-1-6.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_70_1-debuginfo-1-5.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_70_1-debugsource-1-5.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_75_1-debuginfo-1-4.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_75_1-debugsource-1-4.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_80_1-debuginfo-1-3.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_80_1-debugsource-1-3.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_87_1-debuginfo-1-2.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_87_1-debugsource-1-2.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_91_1-debuginfo-1-1.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_91_1-debugsource-1-1.el8_6
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0937?
RHSA-2024:0937 is classified as an important security update.
How do I fix RHSA-2024:0937?
To resolve RHSA-2024:0937, update to the latest version of the kpatch-patch package as specified in the advisory.
What vulnerability does RHSA-2024:0937 address?
RHSA-2024:0937 addresses a privilege escalation vulnerability related to a race condition in GSM multiplexing.
Which products are affected by RHSA-2024:0937?
RHSA-2024:0937 affects various versions of Red Hat Enterprise Linux for Power, little endian, Red Hat Enterprise Linux Server, and others.
Is there a specific version I need to upgrade to for RHSA-2024:0937?
Yes, you need to upgrade to kpatch-patch versions such as 4_18_0-372_64_1-1-6.el8_6 or later.