RHSA-2024:2621: Important: kernel security, bug fix, and enhancement update
Important: kernel security, bug fix, and enhancement update
Other sources
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: use after free flaw in l2capconndel in net/bluetooth/l2capcore.c (CVE-2022-3640) kernel: Information leak in l2capparseconfreq in net/bluetooth/l2capcore.c (CVE-2022-42895) kernel: GSM multiplexing race condition leads to privilege escalation (CVE-2023-6546,ZDI-CAN-20527) kernel: ext4: kernel bug in ext4writeinlinedataend() (CVE-2021-33631) kernel: untrusted VMM can trigger int80 syscall handling (CVE-2024-25744) Bug Fix(es): kernel: use after free flaw in l2capconndel in net/bluetooth/l2capcore.c (JIRA:RHEL-18806) tx-checksumming required for accessing port in OpenShift for RHEL 8.6 (JIRA:RHEL-20821) ceph: several cap and snap fixes (JIRA:RHEL-20908) unable to access smsc95xx based interface unless you start outgoing traffic. (JIRA:RHEL-25718) [RHEL8] ] BUG bio-696 (Not tainted): Poison overwritten (JIRA:RHEL-26100) kernel: ext4: kernel bug in ext4writeinlinedataend() (JIRA:RHEL-26330) kernel: Information leak in l2capparseconfreq in net/bluetooth/l2capcore.c (JIRA:RHEL-18808) kernel: GSM multiplexing race condition leads to privilege escalation (JIRA:RHEL-19953) Enhancement(s): [IBM 8.10 FEAT] Upgrade the qeth driver to latest from upstream, e.g. kernel 6.4 (JIRA:RHEL-25810)
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-abi-stableliststo a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-docto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-s390xto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-zfcpdumpto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-zfcpdump-coreto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-zfcpdump-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-zfcpdump-develto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-zfcpdump-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-zfcpdump-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64leto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-debuginfo-common-aarch64to a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8 - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 4.18.0-477.55.1.el8_8.aa - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch RHEL-25810 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch RHEL-18806 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch RHEL-18808 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch RHEL-26330 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch RHEL-26100 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch RHEL-19953 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch RHEL-20908 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch RHEL-25718 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch RHEL-20821 - Compensating control
System must be rebooted for this kernel update to take effect.
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2621?
RHSA-2024:2621 is classified as Important due to a use-after-free vulnerability that could affect the Linux kernel.
How do I fix RHSA-2024:2621?
To fix RHSA-2024:2621, update your system to the kernel version 4.18.0-477.55.1.el8_8 or later.
What products are affected by RHSA-2024:2621?
RHSA-2024:2621 affects various Red Hat Enterprise Linux products including Server, Power, and x86_64 architectures.
What vulnerability is addressed in RHSA-2024:2621?
RHSA-2024:2621 addresses a use-after-free flaw in the l2cap_conn_del function within the Bluetooth subsystem.
Is it necessary to reboot after applying RHSA-2024:2621?
Yes, a reboot is typically required after applying the kernel updates to ensure the vulnerabilities are fully mitigated.