RHSA-2024:7003: Important: kernel-rt security update
Important: kernel-rt security update
Other sources
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): kernel: TIPC message reassembly use-after-free remote code execution vulnerability (CVE-2024-36886) kernel: fs: sysfs: Fix reference leak in sysfsbreakactiveprotection() (CVE-2024-26993) kernel: wifi: mac80211: Avoid address calculations via out of bounds array indexing (CVE-2024-41071) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:7003?
The severity of RHSA-2024:7003 is classified as Important.
What types of systems are affected by RHSA-2024:7003?
RHSA-2024:7003 affects the Real Time Linux Kernel packages for Red Hat Enterprise Linux for Real Time and Telecommunications Update Services.
How do I fix RHSA-2024:7003?
To fix RHSA-2024:7003, update to the kernel-rt package version 4.18.0-305.141.1.rt7.217.el8_4.
What vulnerabilities does RHSA-2024:7003 address?
RHSA-2024:7003 addresses a use-after-free vulnerability in TIPC message reassembly that could lead to remote code execution.
Which packages need to be updated for RHSA-2024:7003?
You need to update kernel-rt, kernel-rt-core, and several related packages to remediate RHSA-2024:7003.