Red Hat Security Advisory: kernel-rt security and bug fix update
🔗 CVE IDs covered (51)
📋 Description
CVE-2021-26341 — hw: cpu: AMD CPUs may transiently execute beyond unconditional direct branch CVE-2021-33631 — kernel: ext4: kernel bug in ext4_write_inline_data_end() CVE-2021-33655 — kernel: malicious data for FBIOPUT_VSCREENINFO ioctl may cause OOB write memory CVE-2021-47560 — kernel: mlxsw: spectrum: Protect driver from buggy firmware CVE-2021-47592 — kernel: net: stmmac: fix tc flower deletion for VLAN priority Rx steering CVE-2022-1462 — kernel: possible race condition in drivers/tty/tty_buffers.c CVE-2022-1789 — kernel: KVM: NULL pointer dereference in kvm_mmu_invpcid_gva CVE-2022-1882 — kernel: use-after-free in free_pipe_info() could lead to privilege escalation CVE-2022-2196 — kernel: KVM: nVMX: missing IBPB when exiting from nested guest can lead to Spectre v2 attacks CVE-2022-2663 — kernel: netfilter: nf_conntrack_irc message handling issue CVE-2022-3028 — kernel: race condition in xfrm_probe_algs can lead to OOB read/write CVE-2022-3435 — kernel: out-of-bounds read in fib_nh_match of the file net/ipv4/fib_semantics.c CVE-2022-3522 — kernel: race condition in hugetlb_no_page() in mm/hugetlb.c CVE-2022-3524 — kernel: memory leak in ipv6_renew_options() CVE-2022-3566 — kernel: data races around icsk->icsk_af_ops in do_ipv6_setsockopt CVE-2022-3567 — kernel: data races around sk->sk_prot CVE-2022-3619 — kernel: memory leak in l2cap_recv_acldata of the file net/bluetooth/l2cap_core.c CVE-2022-3623 — kernel: denial of service in follow_page_pte in mm/gup.c due to poisoned pte entry CVE-2022-3625 — kernel: use-after-free after failed devlink reload in devlink_param_get CVE-2022-3628 — kernel: USB-accessible buffer overflow in brcmfmac CVE-2022-3640 — kernel: use after free flaw in l2cap_conn_del in net/bluetooth/l2cap_core.c CVE-2022-3707 — kernel: Double-free in split_2MB_gtt_entry when function intel_gvt_dma_map_guest_page failed CVE-2022-4128 — kernel: mptcp: NULL pointer dereference in subflow traversal at disconnect time CVE-2022-4129 — kernel: l2tp: missing lock when clearing sk_user_data can lead to NULL pointer dereference CVE-2022-4662 — kernel: Recursive locking violation in usb-storage that can cause the kernel to deadlock CVE-2022-20141 — kernel: igmp: use-after-free in ip_check_mc_rcu when opening and closing inet sockets CVE-2022-21505 — kernel: lockdown bypass using IMA CVE-2022-28388 — kernel: double free in usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c CVE-2022-33743 — kernel: network backend may cause Linux netfront to use freed SKBs (XSA-405) CVE-2022-36280 — kernel: vmwgfx: out-of-bounds write in vmw_kms_cursor_snoop CVE-2022-36879 — kernel: xfrm_expand_policies() in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice CVE-2022-39188 — kernel: unmap_mapping_range() race with munmap() on VM_PFNMAP mappings leads to stale TLB entry CVE-2022-39189 — kernel: TLB flush operations are mishandled in certain KVM_VCPU_PREEMPTED leading to guest malfunctioning CVE-2022-41674 — kernel: u8 overflow problem in cfg80211_update_notlisted_nontrans() CVE-2022-42703 — kernel: use-after-free related to leaf anon_vma double reuse CVE-2022-42720 — kernel: use-after-free in bss_ref_get in net/wireless/scan.c CVE-2022-42721 — kernel: BSS list corruption in cfg80211_add_nontrans_list in net/wireless/scan.c CVE-2022-42722 — kernel: Denial of service in beacon protection for P2P-device CVE-2022-42896 — kernel: use-after-free in l2cap_connect and l2cap_le_connect_req in net/bluetooth/l2cap_core.c CVE-2022-43750 — kernel: memory corruption in usbmon driver CVE-2022-47929 — kernel: NULL pointer dereference in traffic control subsystem CVE-2022-48695 — kernel: scsi: mpt3sas: Fix use-after-free warning CVE-2023-0394 — kernel: NULL pointer dereference in rawv6_push_pending_frames CVE-2023-0461 — kernel: net/ulp: use-after-free in listening ULP sockets CVE-2023-0590 — kernel: use-after-free due to race condition in qdisc_graft() CVE-2023-1195 — kernel: use-after-free caused by invalid pointer hostname in fs/cifs/connect.c CVE-2023-1382 — kernel: denial of service in tipc_conn_close CVE-2023-2177 — Kernel: NULL pointer dereference problem in sctp_sched_dequeue_common CVE-2023-2513 — kernel: ext4: use-after-free in ext4_xattr_set_entry() CVE-2023-22998 — kernel: drm/virtio: improper return value check in virtio_gpu_object_shmem_init() CVE-2023-52340 — kernel: ICMPv6 “Packet Too Big” packets force a DoS of the Linux kernel by forcing 100% CPU
🎯 Affected products36
- Red Hat Enterprise Linux NFV (v. 9)
- Red Hat Enterprise Linux RT (v. 9)
- kernel-rt-0:5.14.0-284.11.1.rt14.296.el9_2.src as a component of Red Hat Enterprise Linux NFV (v. 9)
- kernel-rt-0:5.14.0-284.11.1.rt14.296.el9_2.src as a component of Red Hat Enterprise Linux RT (v. 9)
- kernel-rt-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 9)
- kernel-rt-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux RT (v. 9)
- kernel-rt-core-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 9)
- kernel-rt-core-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux RT (v. 9)
- kernel-rt-debug-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 9)
- kernel-rt-debug-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux RT (v. 9)
- kernel-rt-debug-core-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 9)
- kernel-rt-debug-core-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux RT (v. 9)
- kernel-rt-debug-debuginfo-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 9)
- kernel-rt-debug-debuginfo-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux RT (v. 9)
- kernel-rt-debug-devel-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 9)
- kernel-rt-debug-devel-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux RT (v. 9)
- kernel-rt-debug-kvm-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 9)
- kernel-rt-debug-modules-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 9)
- kernel-rt-debug-modules-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux RT (v. 9)
- kernel-rt-debug-modules-core-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 9)
- kernel-rt-debug-modules-core-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux RT (v. 9)
- kernel-rt-debug-modules-extra-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 9)
- kernel-rt-debug-modules-extra-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux RT (v. 9)
- kernel-rt-debuginfo-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 9)
- kernel-rt-debuginfo-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux RT (v. 9)
- kernel-rt-debuginfo-common-x86_64-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 9)
- kernel-rt-debuginfo-common-x86_64-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux RT (v. 9)
- kernel-rt-devel-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 9)
- kernel-rt-devel-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux RT (v. 9)
- kernel-rt-kvm-0:5.14.0-284.11.1.rt14.296.el9_2.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 9)
- +6 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: This vulnerability can be mitigated by disabling the nested virtualization feature: ``` # modprobe -r kvm_intel # modprobe kvm_intel nested=0 ``` Workaround: To mitigate this issue, prevent the module nf_conntrack_irc from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically. Workaround: No known mitigation available. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate these vulnerabilities on the operating system level, disable the Bluetooth functionality via blocklisting kernel modules in the Linux kernel. The kernel modules can be prevented from being loaded by using system-wide modprobe rules. Instructions on how to disable Bluetooth modules are available on the customer portal at https://access.redhat.com/solutions/268293. Alternatively, bluetooth can be disabled within the hardware or at the BIOS level, which will also provide effective mitigation as the kernel will not detect Bluetooth hardware on the system. Workaround: To mitigate this issue, prevent the brcmfmac module from being loaded. See https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent module usb_8dev from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, it is possible to prevent the affected code from being loaded by blacklisting the vmwgfx kernel module. For instructions relating to blacklisting a kernel module, please see https://access.redhat.com/solutions/41278. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria, comprised of ease of use and deployment, applicability to widespread installation base, and stability. Workaround: To mitigate this issue, prevent module mac80211 from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: This flaw can be mitigated by disabling Bluetooth on the operating system level. The kernel modules can be prevented from being loaded by using system-wide modprobe rules. For instructions on how to disable Bluetooth on RHEL please refer to https://access.redhat.com/solutions/2682931. Alternatively Bluetooth can be disabled within the hardware or at BIOS level which will also provide an effective mitigation as the kernel will not be able to detect that Bluetooth hardware is present on the system. Workaround: The mitigation is to disable unprivileged user namespaces by setting user.max_user_namespaces to 0: ``` # echo "user.max_user_namespaces=0" > /etc/sysctl.d/userns.conf # sysctl -p /etc/sysctl.d/userns.conf ``` Workaround: To mitigate this issue, prevent module tls from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: This flaw can be mitigated by preventing the affected transparent inter-process communication (TIPC) protocol kernel module from loading during the boot time. Ensure the module is added into the blacklist file. ~~~ Refer: How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~
🔗 References (44)
- selfhttps://access.redhat.com/errata/RHSA-2023:2148
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/9.2_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2061703
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2073091
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2078466
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2089701
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2090723
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2106830
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2107924
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2108691
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2114937
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2122228
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2123056
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2124788
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2130141
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2133483
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2133490
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134377
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134380
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134451
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134506
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134517
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134528
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2137979
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2139610
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2143893
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2143943
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2144720
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2147364
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2150947
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2150960
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2150979
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2151270
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2154171
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2154235
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2160023
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2162120
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2165721
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2165741
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2168246
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2176192
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2177371
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_2148.json