RHSA-2023:5627HighCVSS 7.8

Red Hat Security Advisory: kernel security, bug fix, and enhancement update

Published
October 10, 2023
Last Modified
July 2, 2026

🔗 CVE IDs covered (14)

📋 Description

CVE-2020-36558 — kernel: race condition in VT_RESIZEX ioctl when vc_cons[i].d is already NULL leading to NULL pointer dereference CVE-2022-2503 — kernel: LoadPin bypass via dm-verity table reload CVE-2022-2873 — kernel: an out-of-bounds vulnerability in i2c-ismt driver CVE-2022-36879 — kernel: xfrm_expand_policies() in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice CVE-2023-0590 — kernel: use-after-free due to race condition in qdisc_graft() CVE-2023-1095 — kernel: netfilter: NULL pointer dereference in nf_tables due to zeroed list head CVE-2023-1206 — kernel: hash collisions in the IPv6 connection lookup table CVE-2023-2235 — kernel: use-after-free vulnerability in the perf_group_detach function of the Linux Kernel Performance Events CVE-2023-3090 — kernel: ipvlan: out-of-bounds write caused by unclear skb->cb CVE-2023-4004 — kernel: netfilter: use-after-free due to improper element removal in nft_pipapo_remove() CVE-2023-4128 — kernel: net/sched: Use-after-free vulnerabilities in the net/sched classifiers: cls_fw, cls_u32 and cls_route CVE-2023-35001 — kernel: nf_tables: stack-out-of-bounds-read in nft_byteorder_eval() CVE-2023-53245 — kernel: scsi: storvsc: Fix handling of virtual Fibre Channel timeouts CVE-2023-53556 — kernel: Linux kernel iavf driver: Denial of Service via use-after-free vulnerability

🔗 References (15)