Red Hat Security Advisory: kernel-rt security and bug fix update
🔗 CVE IDs covered (46)
📋 Description
CVE-2021-26341 — hw: cpu: AMD CPUs may transiently execute beyond unconditional direct branch CVE-2021-33655 — kernel: malicious data for FBIOPUT_VSCREENINFO ioctl may cause OOB write memory CVE-2021-33656 — kernel: when setting font with malicious data by ioctl PIO_FONT, kernel will write memory out of bounds CVE-2021-47592 — kernel: net: stmmac: fix tc flower deletion for VLAN priority Rx steering CVE-2022-1462 — kernel: possible race condition in drivers/tty/tty_buffers.c CVE-2022-1679 — kernel: use-after-free in ath9k_htc_probe_device() could cause an escalation of privileges CVE-2022-1789 — kernel: KVM: NULL pointer dereference in kvm_mmu_invpcid_gva CVE-2022-2196 — kernel: KVM: nVMX: missing IBPB when exiting from nested guest can lead to Spectre v2 attacks CVE-2022-2663 — kernel: netfilter: nf_conntrack_irc message handling issue CVE-2022-3028 — kernel: race condition in xfrm_probe_algs can lead to OOB read/write CVE-2022-3239 — kernel: media: em28xx: initialize refcount before kref_get CVE-2022-3522 — kernel: race condition in hugetlb_no_page() in mm/hugetlb.c CVE-2022-3524 — kernel: memory leak in ipv6_renew_options() CVE-2022-3564 — kernel: use-after-free caused by l2cap_reassemble_sdu() in net/bluetooth/l2cap_core.c CVE-2022-3566 — kernel: data races around icsk->icsk_af_ops in do_ipv6_setsockopt CVE-2022-3567 — kernel: data races around sk->sk_prot CVE-2022-3619 — kernel: memory leak in l2cap_recv_acldata of the file net/bluetooth/l2cap_core.c CVE-2022-3623 — kernel: denial of service in follow_page_pte in mm/gup.c due to poisoned pte entry CVE-2022-3625 — kernel: use-after-free after failed devlink reload in devlink_param_get CVE-2022-3628 — kernel: USB-accessible buffer overflow in brcmfmac CVE-2022-3707 — kernel: Double-free in split_2MB_gtt_entry when function intel_gvt_dma_map_guest_page failed CVE-2022-4129 — kernel: l2tp: missing lock when clearing sk_user_data can lead to NULL pointer dereference CVE-2022-4662 — kernel: Recursive locking violation in usb-storage that can cause the kernel to deadlock CVE-2022-20141 — kernel: igmp: use-after-free in ip_check_mc_rcu when opening and closing inet sockets CVE-2022-25265 — kernel: Executable Space Protection Bypass CVE-2022-30594 — kernel: Unprivileged users may use PTRACE_SEIZE to set PTRACE_O_SUSPEND_SECCOMP option CVE-2022-36879 — kernel: xfrm_expand_policies() in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice CVE-2022-39188 — kernel: unmap_mapping_range() race with munmap() on VM_PFNMAP mappings leads to stale TLB entry CVE-2022-39189 — kernel: TLB flush operations are mishandled in certain KVM_VCPU_PREEMPTED leading to guest malfunctioning CVE-2022-41218 — kernel: Report vmalloc UAF in dvb-core/dmxdev CVE-2022-41674 — kernel: u8 overflow problem in cfg80211_update_notlisted_nontrans() CVE-2022-42703 — kernel: use-after-free related to leaf anon_vma double reuse CVE-2022-42720 — kernel: use-after-free in bss_ref_get in net/wireless/scan.c CVE-2022-42721 — kernel: BSS list corruption in cfg80211_add_nontrans_list in net/wireless/scan.c CVE-2022-42722 — kernel: Denial of service in beacon protection for P2P-device CVE-2022-43750 — kernel: memory corruption in usbmon driver CVE-2022-47929 — kernel: NULL pointer dereference in traffic control subsystem CVE-2022-48695 — kernel: scsi: mpt3sas: Fix use-after-free warning CVE-2023-0394 — kernel: NULL pointer dereference in rawv6_push_pending_frames CVE-2023-0461 — kernel: net/ulp: use-after-free in listening ULP sockets CVE-2023-1095 — kernel: netfilter: NULL pointer dereference in nf_tables due to zeroed list head CVE-2023-1195 — kernel: use-after-free caused by invalid pointer hostname in fs/cifs/connect.c CVE-2023-1582 — kernel: Soft lockup occurred during __page_mapcount CVE-2023-2177 — Kernel: NULL pointer dereference problem in sctp_sched_dequeue_common CVE-2023-22998 — kernel: drm/virtio: improper return value check in virtio_gpu_object_shmem_init() CVE-2023-23454 — kernel: slab-out-of-bounds read vulnerabilities in cbq_classify
🎯 Affected products32
- Red Hat Enterprise Linux NFV (v. 8)
- Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-0:4.18.0-477.10.1.rt7.274.el8_8.src as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-0:4.18.0-477.10.1.rt7.274.el8_8.src as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-core-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-core-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-core-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-core-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-debuginfo-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-debuginfo-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-devel-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-devel-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-kvm-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-modules-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-modules-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-modules-extra-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-modules-extra-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debuginfo-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debuginfo-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debuginfo-common-x86_64-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debuginfo-common-x86_64-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-devel-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-devel-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-kvm-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-modules-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-modules-0:4.18.0-477.10.1.rt7.274.el8_8.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- +2 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, prevent the module ath9k from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically. Workaround: This vulnerability can be mitigated by disabling the nested virtualization feature: ``` # modprobe -r kvm_intel # modprobe kvm_intel nested=0 ``` Workaround: To mitigate this issue, prevent the module nf_conntrack_irc from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent module em28xx from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate these vulnerabilities on the operating system level, disable the Bluetooth functionality via blocklisting kernel modules in the Linux kernel. The kernel modules can be prevented from being loaded by using system-wide modprobe rules. Instructions on how to disable Bluetooth modules are available on the Customer Portal at https://access.redhat.com/solutions/2682931. Alternatively, Bluetooth can be disabled within the hardware or at BIOS level which will also provide an effective mitigation as the kernel will not be able to detect that Bluetooth hardware is present on the system. Workaround: Mitigation for this issue is either not available or currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate these vulnerabilities on the operating system level, disable the Bluetooth functionality via blocklisting kernel modules in the Linux kernel. The kernel modules can be prevented from being loaded by using system-wide modprobe rules. Instructions on how to disable Bluetooth modules are available on the customer portal at https://access.redhat.com/solutions/268293. Alternatively, bluetooth can be disabled within the hardware or at the BIOS level, which will also provide effective mitigation as the kernel will not detect Bluetooth hardware on the system. Workaround: To mitigate this issue, prevent the brcmfmac module from being loaded. See https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: If ptrace is not required, ptrace can be disabled in multiple ways. 1. SELinux policy. # setsebool -P deny_ptrace on 2. Kernel sysctl. # sysctl -w kernel.yama.ptrace_scope=3 Or to make persistent , create /etc/sysctl.d/99-yama-ptrace_scope.conf kernel.yama.ptrace_scope=3 If you need further assistance, see the KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services. Workaround: To mitigate this issue, prevent the module dvb-core from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria, comprised of ease of use and deployment, applicability to widespread installation base, and stability. Workaround: To mitigate this issue, prevent module mac80211 from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: The mitigation is to disable unprivileged user namespaces by setting user.max_user_namespaces to 0: ``` # echo "user.max_user_namespaces=0" > /etc/sysctl.d/userns.conf # sysctl -p /etc/sysctl.d/userns.conf ``` Workaround: To mitigate this issue, prevent module tls from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: This flaw can be mitigated by preventing the affected netfilter kernel module from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278. Workaround: This flaw can be mitigated by disabling THP on the system. ~~~ How to disable THP ? https://access.redhat.com/solutions/1320153 ~~~ Workaround: The mitigation is to disable unprivileged user namespaces by setting user.max_user_namespaces to 0: ``` # echo "user.max_user_namespaces=0" > /etc/sysctl.d/userns.conf # sysctl -p /etc/sysctl.d/userns.conf ``` It is also possible to prevent the affected code from being loaded by blacklisting the `cbq` kernel module. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278.
🔗 References (43)
- selfhttps://access.redhat.com/errata/RHSA-2023:2736
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.8_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2055499
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2061703
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2078466
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2084125
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2085300
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2090723
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2108691
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2108696
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2114937
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2122228
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2122960
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2123056
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2124788
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2127985
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2130141
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2133483
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134377
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134451
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134506
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134517
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134528
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2137979
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2143893
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2143943
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2144720
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2150947
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2150960
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2150979
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2150999
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2151270
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2154171
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2154235
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2160023
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2162120
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2165721
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2168246
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2168297
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2176192
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2180936
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_2736.json