Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update
🔗 CVE IDs covered (54)
📋 Description
CVE-2021-43975 — kernel: out-of-bounds write in hw_atl_utils_fw_rpc_wait() in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_utils.c CVE-2022-3594 — kernel: Rate limit overflow messages in r8152 in intr_callback CVE-2022-3640 — kernel: use after free flaw in l2cap_conn_del in net/bluetooth/l2cap_core.c CVE-2022-4744 — kernel: tun: avoid double free in tun_free_netdev CVE-2022-28388 — kernel: double free in usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c CVE-2022-38457 — kernel: vmwgfx: use-after-free in vmw_cmd_res_check CVE-2022-40133 — kernel: vmwgfx: use-after-free in vmw_execbuf_tie_context CVE-2022-40982 — hw: Intel: Gather Data Sampling (GDS) side channel vulnerability CVE-2022-42895 — kernel: Information leak in l2cap_parse_conf_req in net/bluetooth/l2cap_core.c CVE-2022-45869 — kernel: KVM: x86/mmu: race condition in direct_page_fault() CVE-2022-45887 — kernel: memory leak in ttusb_dec_exit_dvb() in media/usb/ttusb-dec/ttusb_dec.c CVE-2023-0458 — kernel: speculative pointer dereference in do_prlimit() in kernel/sys.c CVE-2023-0590 — kernel: use-after-free due to race condition in qdisc_graft() CVE-2023-0597 — kernel: x86/mm: Randomize per-cpu entry area CVE-2023-1073 — kernel: HID: check empty report_list in hid_validate_values() CVE-2023-1074 — kernel: sctp: fail if no bound addresses can be used for a given scope CVE-2023-1075 — kernel: net/tls: tls_is_tx_ready() checked list_entry CVE-2023-1079 — kernel: hid: Use After Free in asus_remove() CVE-2023-1118 — kernel: use-after-free in drivers/media/rc/ene_ir.c due to race condition CVE-2023-1206 — kernel: hash collisions in the IPv6 connection lookup table CVE-2023-1252 — kernel: ovl: fix use after free in struct ovl_aio_req CVE-2023-1382 — kernel: denial of service in tipc_conn_close CVE-2023-1855 — kernel: use-after-free bug in remove function xgene_hwmon_remove CVE-2023-1989 — kernel: Use after free bug in btsdio_remove due to race condition CVE-2023-1998 — kernel: Spectre v2 SMT mitigations problem CVE-2023-2269 — kernel: A possible deadlock in dm_get_inactive_table in dm- ioctl.c leads to dos CVE-2023-2513 — kernel: ext4: use-after-free in ext4_xattr_set_entry() CVE-2023-3141 — kernel: Use after free bug in r592_remove CVE-2023-3161 — kernel: fbcon: shift-out-of-bounds in fbcon_set_font() CVE-2023-3212 — kernel: gfs2: NULL pointer dereference in gfs2_evict_inode() CVE-2023-3268 — kernel: out-of-bounds access in relay_file_read CVE-2023-3609 — kernel: net/sched: cls_u32 component reference counter leak if tcf_change_indev() fails CVE-2023-3611 — kernel: net/sched: sch_qfq component can be exploited if in qfq_change_agg function happens qfq_enqueue overhead CVE-2023-3772 — kernel: xfrm: NULL pointer dereference in xfrm_update_ae_params() CVE-2023-4128 — kernel: net/sched: Use-after-free vulnerabilities in the net/sched classifiers: cls_fw, cls_u32 and cls_route CVE-2023-4132 — kernel: smsusb: use-after-free caused by do_submit_urb() CVE-2023-4155 — kernel: KVM: SEV-ES / SEV-SNP VMGEXIT double fetch vulnerability CVE-2023-4206 — kernel: net/sched: Use-after-free vulnerabilities in the net/sched classifiers: cls_fw, cls_u32 and cls_route CVE-2023-4207 — kernel: net/sched: Use-after-free vulnerabilities in the net/sched classifiers: cls_fw, cls_u32 and cls_route CVE-2023-4208 — kernel: net/sched: Use-after-free vulnerabilities in the net/sched classifiers: cls_fw, cls_u32 and cls_route CVE-2023-4732 — kernel: Race between task migrating pages and another task calling exit_mmap to release those same pages getting invalid opcode BUG in include/linux/swapops.h CVE-2023-23455 — Kernel: denial of service in atm_tc_enqueue in net/sched/sch_atm.c due to type confusion CVE-2023-26545 — kernel: mpls: double free on sysctl allocation failure CVE-2023-28328 — kernel: Denial of service issue in az6027 driver in drivers/media/usb/dev-usb/az6027.c CVE-2023-28772 — kernel: lib/seq_buf.c has a seq_buf_putmem_hex buffer overflow CVE-2023-30456 — kernel: KVM: nVMX: missing consistency checks for CR0 and CR4 CVE-2023-31084 — kernel: blocking operation in dvb_frontend_get_event and wait_event_interruptible CVE-2023-31436 — kernel: out-of-bounds write in qfq_change_class function CVE-2023-33203 — kernel: net: qcom/emac: race condition leading to use-after-free in emac_remove() CVE-2023-33951 — kernel: vmwgfx: race condition leading to information disclosure vulnerability CVE-2023-33952 — kernel: vmwgfx: double free within the handling of vmw_buffer_object objects CVE-2023-35823 — kernel: saa7134: race condition leading to use-after-free in saa7134_finidev() CVE-2023-35824 — kernel: dm1105: race condition leading to use-after-free in dm1105_remove.c() CVE-2023-35825 — kernel: r592: race condition leading to use-after-free in r592_remove()
🎯 Affected products32
- Red Hat Enterprise Linux Real Time (v. 8)
- Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9.src as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9.src as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-core-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-core-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-debug-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-debug-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-debug-core-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-debug-core-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-debug-debuginfo-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-debug-debuginfo-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-debug-devel-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-debug-devel-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-debug-kvm-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-debug-modules-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-debug-modules-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-debug-modules-extra-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-debug-modules-extra-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-debuginfo-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-debuginfo-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-debuginfo-common-x86_64-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-debuginfo-common-x86_64-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-devel-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-devel-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-kvm-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- kernel-rt-modules-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time (v. 8)
- kernel-rt-modules-0:4.18.0-513.5.1.rt7.307.el8_9.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV (v. 8)
- +2 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: To mitigate this issue, prevent the module atlantic from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically. Workaround: This flaw can be mitigated by preventing the affected Realtek RTL8152/RTL8153 Based USB Ethernet Adapters (r8152) kernel module from loading during the boot time. Ensure the module is added into the blacklist file. ~~~ Refer: How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, prevent the tun module from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent module usb_8dev from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, it is possible to prevent the affected code from being loaded by blacklisting the vmwgfx kernel module. For instructions relating to blacklisting a kernel module, please see https://access.redhat.com/solutions/41278. Workaround: The vulnerability can be mitigated by installing the CPU microcode package microcode_ctl version 20230808. Workaround: This vulnerability can be mitigated by disabling the nested virtualization feature. For Intel: ``` # modprobe -r kvm_intel # modprobe kvm_intel nested=0 ``` For AMD: ``` # modprobe -r kvm_amd # modprobe kvm_amd nested=0 ``` Workaround: To mitigate this issue, it is possible to prevent the affected code from being loaded by blacklisting the `ttusb_dec` kernel module. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, prevent module sctp from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent module tls from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: This flaw can be mitigated by preventing the affected ASUS HID driver (for notebook built-in keyboard) module from loading during the boot time, ensure the module is added into the blacklist file. ~~~ Refer: How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: To mitigate this issue, prevent module ene_ir from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: https://access.redhat.com/solutions/30453 Workaround: This flaw can be mitigated by preventing the affected transparent inter-process communication (TIPC) protocol kernel module from loading during the boot time. Ensure the module is added into the blacklist file. ~~~ Refer: How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: This flaw can be mitigated by preventing the affected APM X-Gene SoC HW monitor kernel driver (apm_xgene) from loading during the boot time. Ensure the module is added into the blacklist file. ~~~ Refer: How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: This flaw can be mitigated by preventing the affected Generic Bluetooth SDIO driver kernel module from loading during the boot time. Ensure the module is added into the blacklist file. ~~~ Refer: How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: This flaw can be mitigated by disabling Simultaneous Multithreading (SMT). For instructions on how to disable SMT in RHEL, please see https://access.redhat.com/solutions/rhel-smt. Workaround: To mitigate this issue, prevent module cls_u32 from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: Mitigation for this issue is to skip loading the affected module sch_qfq onto the system until we have a fix available. This can be done by a blacklist mechanism and will ensure the driver is not loaded at the boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: To mitigate this issue, prevent the module cls_u32 from being loaded by blacklisting the module to prevent it from loading automatically. ~~~ https://access.redhat.com/solutions/41278 ~~~ Workaround: A possible workaround is disabling Transparent Hugepage Workaround: The mitigation is to disable unprivileged user namespaces by setting user.max_user_namespaces to 0: ``` # echo "user.max_user_namespaces=0" > /etc/sysctl.d/userns.conf # sysctl -p /etc/sysctl.d/userns.conf ``` Workaround: This vulnerability can be mitigated by disabling the nested virtualization feature: ``` # modprobe -r kvm_intel # modprobe kvm_intel nested=0 ``` Workaround: To mitigate this issue, prevent the module, sch_qfq from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically. Workaround: This flaw can be mitigated by preventing the affected `vmwgfx` kernel module from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278.
🔗 References (56)
- selfhttps://access.redhat.com/errata/RHSA-2023:6901
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.9_release_notes/index
- externalhttps://access.redhat.com/solutions/7027704
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2024989
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2073091
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2133453
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2133455
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2139610
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2147356
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2148520
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2149024
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2151317
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2156322
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2165741
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2165926
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2168332
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2173403
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2173430
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2173434
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2173444
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2174400
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2175903
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2176140
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2177371
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2177389
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2181330
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182443
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2184578
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2185945
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2187257
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2188468
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2192667
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2192671
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2193097
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2193219
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2213139
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2213199
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2213485
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2213802
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2214348
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2215502
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2215835
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2215836
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2215837
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2218195
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2218212
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2218943
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2219530
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221707
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2223949
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2225191
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2225201
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2225511
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2236982
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6901.json