Red Hat Security Advisory: kernel security update
🔗 CVE IDs covered (22)
📋 Description
CVE-2021-4204 — kernel: improper input validation may lead to privilege escalation CVE-2021-47393 — kernel: hwmon: (mlxreg-fan) Return non-zero value when fan current state is enforced from sysfs CVE-2021-47461 — kernel: userfaultfd: fix a race between writeprotect and exit_mmap() CVE-2022-0500 — kernel: Linux ebpf logic vulnerability leads to critical memory read and write gaining root privileges CVE-2022-23222 — kernel: local privileges escalation in kernel/bpf/verifier.c CVE-2022-48686 — kernel: nvme-tcp: fix UAF when detecting digest errors CVE-2022-48773 — kernel: xprtrdma: fix pointer derefs in error cases of rpcrdma_ep_create CVE-2022-48929 — kernel: bpf: Fix crash due to out of bounds access into reg2btf_ids. CVE-2023-0597 — kernel: x86/mm: Randomize per-cpu entry area CVE-2023-52489 — kernel: mm/sparsemem: fix race in accessing memory_section->usage CVE-2024-26671 — kernel: blk-mq: fix IO hang from sbitmap wakeup race CVE-2024-26961 — kernel: mac802154: fix llsec key resources release in mac802154_llsec_key_del CVE-2024-31076 — kernel: genirq/cpuhotplug, x86/vector: Prevent vector leak during CPU offline CVE-2024-35823 — kernel: vt: fix unicode buffer corruption when deleting characters CVE-2024-36889 — kernel: mptcp: ensure snd_nxt is properly initialized on connect CVE-2024-36920 — kernel: scsi: mpi3mr: Avoid memcpy field-spanning write WARNING CVE-2024-38564 — kernel: bpf: Add BPF_PROG_TYPE_CGROUP_SKB attach type enforcement in BPF_LINK_CREATE CVE-2024-40988 — kernel: drm/radeon: fix UBSAN warning in kv_dpm.c CVE-2024-41009 — kernel: bpf: Fix overrunning reservations in ringbuf CVE-2024-41014 — kernel: xfs: add bounds checking to xlog_recover_process_data CVE-2024-41023 — kernel: sched/deadline: Fix task_struct reference leak CVE-2024-46858 — kernel: mptcp: pm: Fix uaf in __timer_delete_sync
🎯 Affected products122
- Red Hat CodeReady Linux Builder EUS (v.8.8)
- Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- bpftool-0:4.18.0-477.81.1.el8_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- bpftool-0:4.18.0-477.81.1.el8_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- bpftool-0:4.18.0-477.81.1.el8_8.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- bpftool-0:4.18.0-477.81.1.el8_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- bpftool-debuginfo-0:4.18.0-477.81.1.el8_8.aarch64 as a component of Red Hat CodeReady Linux Builder EUS (v.8.8)
- bpftool-debuginfo-0:4.18.0-477.81.1.el8_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- bpftool-debuginfo-0:4.18.0-477.81.1.el8_8.ppc64le as a component of Red Hat CodeReady Linux Builder EUS (v.8.8)
- bpftool-debuginfo-0:4.18.0-477.81.1.el8_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- bpftool-debuginfo-0:4.18.0-477.81.1.el8_8.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- bpftool-debuginfo-0:4.18.0-477.81.1.el8_8.x86_64 as a component of Red Hat CodeReady Linux Builder EUS (v.8.8)
- bpftool-debuginfo-0:4.18.0-477.81.1.el8_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-0:4.18.0-477.81.1.el8_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-0:4.18.0-477.81.1.el8_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-0:4.18.0-477.81.1.el8_8.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-0:4.18.0-477.81.1.el8_8.src as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-0:4.18.0-477.81.1.el8_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-abi-stablelists-0:4.18.0-477.81.1.el8_8.noarch as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-core-0:4.18.0-477.81.1.el8_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-core-0:4.18.0-477.81.1.el8_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-core-0:4.18.0-477.81.1.el8_8.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-core-0:4.18.0-477.81.1.el8_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-debug-0:4.18.0-477.81.1.el8_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-debug-0:4.18.0-477.81.1.el8_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-debug-0:4.18.0-477.81.1.el8_8.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-debug-0:4.18.0-477.81.1.el8_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-debug-core-0:4.18.0-477.81.1.el8_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-debug-core-0:4.18.0-477.81.1.el8_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-debug-core-0:4.18.0-477.81.1.el8_8.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- +92 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: For the Red Hat Enterprise Linux 7 the eBPF for unprivileged users is always disabled. For the Red Hat Enterprise Linux 8 to confirm the current state, inspect the sysctl with the command: # cat /proc/sys/kernel/unprivileged_bpf_disabled The setting of 1 would mean that unprivileged users can not use eBPF, mitigating the flaw. A kernel update will be required to mitigate the flaw for the root or users with CAP_SYS_ADMIN capabilities. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: The default Red Hat Enterprise Linux kernel prevents unprivileged users from being able to use eBPF by the kernel.unprivileged_bpf_disabled sysctl. This would require a privileged user with CAP_SYS_ADMIN or root to be able to abuse this flaw reducing its attack space. For Red Hat Enterprise Linux 7 the eBPF for unprivileged users is always disabled. For Red Hat Enterprise Linux 8 to confirm the current state, inspect the sysctl with the command: ``` # cat /proc/sys/kernel/unprivileged_bpf_disabled ``` The setting of 1 would mean that unprivileged users can not use eBPF, mitigating the flaw. A kernel update will be required to mitigate the flaw for the root or users with CAP_SYS_ADMIN (or CAP_BPF) capabilities. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (24)
- selfhttps://access.redhat.com/errata/RHSA-2024:10262
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2039178
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2043520
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2044578
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2165926
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2269189
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2272811
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278176
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278931
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2281190
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2282345
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2282896
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2284515
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2284571
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293429
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293684
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297572
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2298109
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2298412
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2300297
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2300381
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2315210
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_10262.json