RHSA-2024:1960: Important: kpatch-patch security update
Important: kpatch-patch security update
Other sources
This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.Security Fix(es): kernel: use after free in unixstreamsendpage (CVE-2023-4622) kernel: net/sched: schhfsc UAF (CVE-2023-4623) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1960?
The severity of RHSA-2024:1960 is classified as Important.
What vulnerabilities does RHSA-2024:1960 address?
RHSA-2024:1960 addresses a use-after-free vulnerability in unix_stream_sendpage identified as CVE-2023-4622.
How do I fix RHSA-2024:1960?
To fix RHSA-2024:1960, update the 'kpatch-patch' package to the specified remedial versions listed in the advisory.
Which versions of kpatch-patch are affected by RHSA-2024:1960?
Affected versions of kpatch-patch include 3_10_0-1160_102_1-1-4.el7, 3_10_0-1160_105_1-1-3.el7, and 3_10_0-1160_108_1-1-2.el7.
Is RHSA-2024:1960 applicable to all Red Hat Enterprise Linux versions?
RHSA-2024:1960 specifically applies to Red Hat Enterprise Linux Server versions that utilize the affected kpatch-patch packages.