Red Hat Security Advisory: kernel security, bug fix, and enhancement update
🔗 CVE IDs covered (14)
📋 Description
CVE-2020-36558 — kernel: race condition in VT_RESIZEX ioctl when vc_cons[i].d is already NULL leading to NULL pointer dereference CVE-2022-2503 — kernel: LoadPin bypass via dm-verity table reload CVE-2022-2873 — kernel: an out-of-bounds vulnerability in i2c-ismt driver CVE-2022-36879 — kernel: xfrm_expand_policies() in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice CVE-2023-0590 — kernel: use-after-free due to race condition in qdisc_graft() CVE-2023-1095 — kernel: netfilter: NULL pointer dereference in nf_tables due to zeroed list head CVE-2023-1206 — kernel: hash collisions in the IPv6 connection lookup table CVE-2023-2235 — kernel: use-after-free vulnerability in the perf_group_detach function of the Linux Kernel Performance Events CVE-2023-3090 — kernel: ipvlan: out-of-bounds write caused by unclear skb->cb CVE-2023-4004 — kernel: netfilter: use-after-free due to improper element removal in nft_pipapo_remove() CVE-2023-4128 — kernel: net/sched: Use-after-free vulnerabilities in the net/sched classifiers: cls_fw, cls_u32 and cls_route CVE-2023-35001 — kernel: nf_tables: stack-out-of-bounds-read in nft_byteorder_eval() CVE-2023-53245 — kernel: scsi: storvsc: Fix handling of virtual Fibre Channel timeouts CVE-2023-53556 — kernel: Linux kernel iavf driver: Denial of Service via use-after-free vulnerability
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2023:5627
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2112693
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119048
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119855
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2165741
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2173973
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2175903
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2177862
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2192589
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2218672
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2220892
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2225275
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2225511
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_5627.json