RHSA-2024:1332: Important: kernel-rt security update
Important: kernel-rt security update
Other sources
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.<br>Security Fix(es):<br><li> sched/membarrier: reduce the ability to hammer on sysmembarrier (CVE-2024-26602)</li> <li> use-after-free in l2capconnect and l2capleconnectreq in net/bluetooth/l2capcore.c (CVE-2022-42896)</li> <li> use-after-free in schqfq network scheduler (CVE-2023-4921)</li> <li> IGB driver inadequate buffer size for frames larger than MTU (CVE-2023-45871)</li> <li> fbcon: out-of-sync arrays in fbconmodedeleted due to wrong con2fbmap assignment (CVE-2023-38409)</li> <li> nftables: use-after-free vulnerability in the nftverdictinit() function (CVE-2024-1086)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1332?
The severity of RHSA-2024:1332 is classified as Important.
How do I fix RHSA-2024:1332?
To fix RHSA-2024:1332, upgrade to kernel-rt package version 3.10.0-1160.114.2.rt56.1266.el7.
Which systems are affected by RHSA-2024:1332?
RHSA-2024:1332 affects Red Hat Enterprise Linux for Real Time and Red Hat Enterprise Linux for Real Time for NFV.
What are the security fixes included in RHSA-2024:1332?
RHSA-2024:1332 includes a security fix for CVE-2024-... related to sched/membarrier.
Is there a specific package update required for RHSA-2024:1332?
Yes, the specific package update required is kernel-rt to version 3.10.0-1160.114.2.rt56.1266.el7.