Red Hat Security Advisory: kernel security and bug fix update
🔗 CVE IDs covered (36)
📋 Description
CVE-2022-49995 — kernel: writeback: avoid use-after-free after removing device CVE-2023-0458 — kernel: speculative pointer dereference in do_prlimit() in kernel/sys.c CVE-2023-1073 — kernel: HID: check empty report_list in hid_validate_values() CVE-2023-1075 — kernel: net/tls: tls_is_tx_ready() checked list_entry CVE-2023-1079 — kernel: hid: Use After Free in asus_remove() CVE-2023-1838 — kernel: Possible use-after-free since the two fdget() during vhost_net_set_backend() CVE-2023-1855 — kernel: use-after-free bug in remove function xgene_hwmon_remove CVE-2023-2162 — kernel: UAF during login when accessing the shost ipaddress CVE-2023-2163 — kernel: bpf: Incorrect verifier pruning leads to unsafe code paths being incorrectly marked as safe CVE-2023-3141 — kernel: Use after free bug in r592_remove CVE-2023-3567 — kernel: use after free in vcs_read in drivers/tty/vt/vc_screen.c due to race CVE-2023-3611 — kernel: net/sched: sch_qfq component can be exploited if in qfq_change_agg function happens qfq_enqueue overhead CVE-2023-3772 — kernel: xfrm: NULL pointer dereference in xfrm_update_ae_params() CVE-2023-3812 — kernel: tun: bugs for oversize packet when napi frags enabled in tun_napi_alloc_frags CVE-2023-4132 — kernel: smsusb: use-after-free caused by do_submit_urb() CVE-2023-4622 — kernel: use after free in unix_stream_sendpage CVE-2023-4623 — kernel: net/sched: sch_hfsc UAF CVE-2023-5178 — kernel: use after free in nvmet_tcp_free_crypto in NVMe CVE-2023-5717 — kernel: A heap out-of-bounds write when function perf_read_group is called and sibling_list is smaller than its child's sibling_list CVE-2023-23455 — Kernel: denial of service in atm_tc_enqueue in net/sched/sch_atm.c due to type confusion CVE-2023-26545 — kernel: mpls: double free on sysctl allocation failure CVE-2023-28328 — kernel: Denial of service issue in az6027 driver in drivers/media/usb/dev-usb/az6027.c CVE-2023-31436 — kernel: out-of-bounds write in qfq_change_class function CVE-2023-33203 — kernel: net: qcom/emac: race condition leading to use-after-free in emac_remove() CVE-2023-35823 — kernel: saa7134: race condition leading to use-after-free in saa7134_finidev() CVE-2023-35824 — kernel: dm1105: race condition leading to use-after-free in dm1105_remove.c() CVE-2023-35825 — kernel: r592: race condition leading to use-after-free in r592_remove() CVE-2023-45871 — kernel: IGB driver inadequate buffer size for frames larger than MTU CVE-2023-46813 — kernel: SEV-ES local priv escalation CVE-2023-52973 — kernel: vc_screen: move load of struct vc_data pointer in vcs_read() to avoid UAF CVE-2023-52974 — kernel: scsi: iscsi_tcp: Fix UAF during login when accessing the shost ipaddress CVE-2023-52975 — kernel: scsi: iscsi_tcp: Fix UAF during logout when accessing the shost ipaddress CVE-2023-53147 — kernel: xfrm: add NULL check in xfrm_update_ae_params CVE-2023-53296 — kernel: sctp: check send stream number after wait_for_sndbuf CVE-2023-53372 — kernel: sctp: fix a potential overflow in sctp_ifwdtsn_skip CVE-2023-53996 — kernel: x86/sev: Make enc_dec_hypercall() accept a size instead of npages
🎯 Affected products122
- Red Hat CodeReady Linux Builder EUS (v.8.8)
- Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- bpftool-0:4.18.0-477.43.1.el8_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- bpftool-0:4.18.0-477.43.1.el8_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- bpftool-0:4.18.0-477.43.1.el8_8.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- bpftool-0:4.18.0-477.43.1.el8_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- bpftool-debuginfo-0:4.18.0-477.43.1.el8_8.aarch64 as a component of Red Hat CodeReady Linux Builder EUS (v.8.8)
- bpftool-debuginfo-0:4.18.0-477.43.1.el8_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- bpftool-debuginfo-0:4.18.0-477.43.1.el8_8.ppc64le as a component of Red Hat CodeReady Linux Builder EUS (v.8.8)
- bpftool-debuginfo-0:4.18.0-477.43.1.el8_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- bpftool-debuginfo-0:4.18.0-477.43.1.el8_8.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- bpftool-debuginfo-0:4.18.0-477.43.1.el8_8.x86_64 as a component of Red Hat CodeReady Linux Builder EUS (v.8.8)
- bpftool-debuginfo-0:4.18.0-477.43.1.el8_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-0:4.18.0-477.43.1.el8_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-0:4.18.0-477.43.1.el8_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-0:4.18.0-477.43.1.el8_8.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-0:4.18.0-477.43.1.el8_8.src as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-0:4.18.0-477.43.1.el8_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-abi-stablelists-0:4.18.0-477.43.1.el8_8.noarch as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-core-0:4.18.0-477.43.1.el8_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-core-0:4.18.0-477.43.1.el8_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-core-0:4.18.0-477.43.1.el8_8.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-core-0:4.18.0-477.43.1.el8_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-debug-0:4.18.0-477.43.1.el8_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-debug-0:4.18.0-477.43.1.el8_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-debug-0:4.18.0-477.43.1.el8_8.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-debug-0:4.18.0-477.43.1.el8_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-debug-core-0:4.18.0-477.43.1.el8_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-debug-core-0:4.18.0-477.43.1.el8_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-debug-core-0:4.18.0-477.43.1.el8_8.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- +92 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, prevent module tls from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: This flaw can be mitigated by preventing the affected ASUS HID driver (for notebook built-in keyboard) module from loading during the boot time, ensure the module is added into the blacklist file. ~~~ Refer: How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: This flaw can be mitigated by preventing the affected Host kernel accelerator (vhost-net) kernel module from loading during the boot time, ensure the module is added to the blacklist file. ~~~ Refer: How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: This flaw can be mitigated by preventing the affected APM X-Gene SoC HW monitor kernel driver (apm_xgene) from loading during the boot time. Ensure the module is added into the blacklist file. ~~~ Refer: How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: This flaw can be mitigated by preventing the affected iscsi_tcp.ko kernel module from loading during the boot time, ensure the module is added into the blacklist file. ~~~ Refer: How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: The default Red Hat Enterprise Linux kernel prevents unprivileged users from being able to use eBPF by the kernel.unprivileged_bpf_disabled sysctl. This would require a privileged user with CAP_SYS_ADMIN or root to be able to abuse this flaw reducing its attack space. For Red Hat Enterprise Linux 8 to confirm the current state, inspect the sysctl with the command: # cat /proc/sys/kernel/unprivileged_bpf_disabled The setting of 1 would mean that unprivileged users can not use eBPF, mitigating the flaw. Workaround: Mitigation for this issue is to skip loading the affected module sch_qfq onto the system until we have a fix available. This can be done by a blacklist mechanism and will ensure the driver is not loaded at the boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: To mitigate this issue, prevent the tun module from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: Mitigation for this issue is either not available or currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, prevent the module sch_hfsc from being loaded by blacklisting the module to prevent it from loading automatically. ~~~ https://access.redhat.com/solutions/41278 ~~~ Workaround: It is not possible to trigger this issue with the default kernel.perf_event_paranoid sysctl value 2. You may check it with: cat /proc/sys/kernel/perf_event_paranoid Workaround: The mitigation is to disable unprivileged user namespaces by setting user.max_user_namespaces to 0: ``` # echo "user.max_user_namespaces=0" > /etc/sysctl.d/userns.conf # sysctl -p /etc/sysctl.d/userns.conf ``` Workaround: To mitigate this issue, prevent the module, sch_qfq from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically.
🔗 References (32)
- selfhttps://access.redhat.com/errata/RHSA-2024:0575
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2087568
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2168332
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2173403
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2173434
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2173444
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2177389
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182443
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2184578
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2187773
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2192667
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2192671
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2193219
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2213199
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2215835
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2215836
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2215837
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2218943
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221463
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221707
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2224048
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2225191
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2230094
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2237757
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2237760
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2240249
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2241924
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2244723
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2246944
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2246945
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0575.json