RHSA-2024:1306: Important: kernel-rt security and bug fix update
Important: kernel-rt security and bug fix update
Other sources
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): memcg does not limit the number of POSIX file locks allowing memory exhaustion (CVE-2022-0480) vmwgfx: NULL pointer dereference in vmwcmddxdefinequery (CVE-2022-38096) use-after-free in smb2isstatusiotimeout() (CVE-2023-1192) nfp: use-after-free in areacacheget() (CVE-2022-3545) NULL pointer dereference in canrcvfilter (CVE-2023-2166) Slab-out-of-bound read in comparenetdevandip (CVE-2023-2176) UAF in nftables when nftsetlookupglobal triggered after handling named and anonymous sets in batch requests (CVE-2023-3390) out-of-bounds access in relayfileread (CVE-2023-3268) vmxnet3: NULL pointer dereference in vmxnet3rqcleanup() (CVE-2023-4459) Gather Data Sampling (GDS) side channel vulnerability (CVE-2022-40982,Downfall) net/sched: clsu32 component reference counter leak if tcfchangeindev() fails (CVE-2023-3609) fbcon: out-of-sync arrays in fbconmodedeleted due to wrong con2fbmap assignment (CVE-2023-38409) Race Condition leading to UAF in Unix Socket could happen in skreceivequeue () use-after-free in l2capsockrelease in net/bluetooth/l2capsock.c (CVE-2023-40283) use after free in unixstreamsendpage (CVE-2023-4622) bpf: Incorrect verifier pruning leads to unsafe code paths being incorrectly marked as safe (CVE-2023-2163) A heap out-of-bounds write when function perfreadgroup is called and siblinglist is smaller than its child's siblinglist (CVE-2023-5717) ktls overwrites readonly memory pages when using function splice with a ktls socket as destination (CVE-2024-0646) use-after-free in IPv4 IGMP (CVE-2023-6932) GSM multiplexing race condition leads to privilege escalation (CVE-2023-6546,ZDI-CAN-20527) refcount leak in ctnetlinkcreateconntrack() (CVE-2023-7192) Bug Fix(es): fbcon: out-of-sync arrays in fbconmodedeleted due to wrong con2fbmap assignment (JIRA:RHEL-1107) out-of-bounds access in relayfileread (JIRA:RHEL-1749) vmxnet3: NULL pointer dereference in vmxnet3rqcleanup() (JIRA:RHEL-18085) NULL pointer dereference in canrcvfilter (JIRA:RHEL-19524) update RT source tree to the latest RHEL-9.0.z Batch 15 (JIRA:RHEL-21555) Gather Data Sampling (GDS) side channel vulnerability (JIRA:RHEL-9285) A heap out-of-bounds write (JIRA:RHEL-18011) Slab-out-of-bound read in comparenetdevandip (JIRA:RHEL-19398) A flaw leading to a use-after-free in areacacheget() (JIRA:RHEL-19534) Incorrect verifier pruning leads to unsafe code paths being incorrectly marked as safe (JIRA:RHEL-8980) various flaws (JIRA:RHEL-16150) refcount leak in ctnetlinkcreateconntrack() (JIRA:RHEL-20311) use-after-free in l2capsockrelease in net/bluetooth/l2capsock.c (JIRA:RHEL-20502) ktls overwrites readonly memory pages when using function splice with a ktls socket as destination (JIRA:RHEL-22095) use-after-free in smb2isstatusiotimeout() (JIRA:RHEL-15171) use-after-free in IPv4 IGMP (JIRA:RHEL-21658) memcg does not limit the number of POSIX file locks allowing memory exhaustion (JIRA:RHEL-8996) GSM multiplexing race condition leads to privilege escalation (JIRA:RHEL-19968) NULL pointer dereference in vmwcmddxdefinequery (JIRA:RHEL-22751) kernel: sched/membarrier: reduce the ability to hammer on sysmembarrier (JIRA:RHEL-26381)
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1306?
The severity of RHSA-2024:1306 is classified as important.
How do I fix RHSA-2024:1306?
To fix RHSA-2024:1306, update the kernel-rt package to version 5.14.0-70.93.1.rt21.165.el9_0.
Which systems are affected by RHSA-2024:1306?
RHSA-2024:1306 affects Red Hat Enterprise Linux for Real Time for x86_64 and associated kernel-rt packages.
What type of update is provided in RHSA-2024:1306?
RHSA-2024:1306 provides a security and bug fix update for the kernel-rt.
When was RHSA-2024:1306 released?
RHSA-2024:1306 was released on a date that is specified in the advisory.