RHSA-2024:2004: Important: kernel security and bug fix update
Important: kernel security and bug fix update
Other sources
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security fixes: kernel: use after free in unixstreamsendpage (CVE-2023-4622) Kernel: bluetooth: Unauthorized management command execution (CVE-2023-2002) kernel: irdma: Improper access control (CVE-2023-25775) kernel: net/sched: schhfsc UAF (CVE-2023-4623) kernel: race condition in VTRESIZEX ioctl when vccons[i].d is already NULL leading to NULL pointer dereference (CVE-2020-36558) This update also fixes the following bugs: NFS client closes active connection (RHEL-22193) kernel panic at listdelentry from smb2reconnectserver (RHEL-26301) kernel: race condition when call to VTRESIZEX ioctl and vccons[i].d is already NULL, causing a NULL pointer dereference. (RHEL-28639) kernel: net/sched: schhfsc UAF (RHEL-16458) kernel: irdma: Improper access control (RHEL-6299) The message in RHEL 7 ?stack-protector: Kernel stack is corrupted in:? is triggered because perftracebufprepare() does not verify that percpu array perftracebuf has allocated percpu buffers in it. (RHEL-18052) [rhel7] gfs2: Invalid metadata access in punchhole (RHEL-28785) UDP packets dropped due to SELinux denial (RHEL-27751) Boot fails with kernel panic at acpidevicehid+0x6 (RHEL-8721) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2004?
The severity of RHSA-2024:2004 is considered important due to critical kernel security vulnerabilities.
How do I fix RHSA-2024:2004?
To fix RHSA-2024:2004, users should update to kernel version 3.10.0-1160.118.1.el7 or higher.
What vulnerabilities does RHSA-2024:2004 address?
RHSA-2024:2004 addresses a use after free vulnerability in unix_stream_sendpage and unauthorized management commands in Bluetooth.
Which products are affected by RHSA-2024:2004?
RHSA-2024:2004 affects various versions of Red Hat Enterprise Linux, including Desktop, Server, and Workstation.
Is there a specific package I need to update for RHSA-2024:2004?
Yes, the kernel package version 3.10.0-1160.118.1.el7 needs to be updated to mitigate the vulnerabilities in RHSA-2024:2004.