RHSA-2024:10771MediumCVSS 7.8

Red Hat Security Advisory: kernel security update

Published
December 4, 2024
Last Modified
August 19, 2026

🔗 CVE IDs covered (36)

📋 Description

CVE-2022-48804 — kernel: vt_ioctl: fix array_index_nospec in vt_setactivate CVE-2023-52619 — kernel: pstore/ram: Fix crash when setting number of cpus to an odd number CVE-2023-52635 — kernel: PM / devfreq: Synchronize devfreq_monitor_[start/stop] CVE-2023-52775 — kernel: net/smc: avoid data corruption caused by decline CVE-2023-52811 — kernel: scsi: ibmvfc: Remove BUG_ON in the case of an empty event pool CVE-2023-53503 — kernel: ext4: allow ext4_get_group_info() to fail CVE-2023-53861 — kernel: ext4: correct grp validation in ext4_mb_good_group CVE-2024-26601 — kernel: ext4: regenerate buddy after block freeing failed if under fc replay CVE-2024-26615 — kernel: net/smc: fix illegal rmb_desc access in SMC-D connection dump CVE-2024-26686 — kernel: fs/proc: do_task_stat: use sig->stats_lock to gather the threads/children stats CVE-2024-26704 — kernel: ext4: fix double-free of blocks due to wrong extents moved_len CVE-2024-27399 — kernel: Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout CVE-2024-36928 — kernel: s390/qeth: Fix kernel panic after setting hsuid CVE-2024-36960 — kernel: drm/vmwgfx: Fix invalid reads in fence signaled events CVE-2024-38384 — kernel: blk-cgroup: fix list corruption from reorder of WRITE ->lqueued CVE-2024-38541 — kernel: of: module: add buffer overflow check in of_modalias() CVE-2024-38555 — kernel: net/mlx5: Discard command completions in internal error CVE-2024-39507 — kernel: net: hns3: fix kernel crash problem in concurrent scenario CVE-2024-40997 — kernel: cpufreq: amd-pstate: fix memory leak on CPU EPP exit CVE-2024-41007 — kernel: tcp: avoid too many retransmit packets CVE-2024-41008 — kernel: drm/amdgpu: change vm->task_info handling CVE-2024-41009 — kernel: bpf: Fix overrunning reservations in ringbuf CVE-2024-41031 — kernel: mm/filemap: skip to create PMD-sized page cache if needed CVE-2024-41038 — kernel: firmware: cs_dsp: Prevent buffer overrun when processing V2 alg headers CVE-2024-41056 — kernel: firmware: cs_dsp: Use strnlen() on name fields in V1 wmfw files CVE-2024-41093 — kernel: drm/amdgpu: avoid using null object of framebuffer CVE-2024-42154 — kernel: tcp_metrics: validate source addr length CVE-2024-42228 — kernel: drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc CVE-2024-42237 — kernel: firmware: cs_dsp: Validate payload length before processing block CVE-2024-42238 — kernel: firmware: cs_dsp: Return error if block header overflows file CVE-2024-42240 — kernel: x86/bhi: Avoid warning in #DB handler due to BHI mitigation CVE-2024-42241 — kernel: mm/shmem: disable PMD-sized page cache if needed CVE-2024-42243 — kernel: mm/filemap: make MAX_PAGECACHE_ORDER acceptable to xarray CVE-2024-42244 — kernel: USB: serial: mos7840: fix crash on resume CVE-2024-42271 — kernel: net/iucv: fix use after free in iucv_sock_close() CVE-2024-44989 — kernel: bonding: fix xfrm real_dev null pointer dereference

🎯 Affected products200

  • Red Hat CodeReady Linux Builder EUS (v.9.4)
  • Red Hat Enterprise Linux AppStream EUS (v.9.4)
  • Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • Red Hat Enterprise Linux Real Time EUS (v.9.4)
  • Red Hat Enterprise Linux Real Time for NFV EUS (v.9.4)
  • bpftool-0:7.3.0-427.47.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • bpftool-0:7.3.0-427.47.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • bpftool-0:7.3.0-427.47.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • bpftool-0:7.3.0-427.47.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.47.1.el9_4.aarch64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.47.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.47.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.47.1.el9_4.ppc64le as a component of Red Hat CodeReady Linux Builder EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.47.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.47.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.47.1.el9_4.s390x as a component of Red Hat CodeReady Linux Builder EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.47.1.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.47.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.47.1.el9_4.x86_64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.47.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.47.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.47.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.47.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.4)
  • kernel-0:5.14.0-427.47.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • kernel-0:5.14.0-427.47.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • kernel-0:5.14.0-427.47.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • kernel-0:5.14.0-427.47.1.el9_4.src as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • kernel-0:5.14.0-427.47.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • kernel-64k-0:5.14.0-427.47.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • kernel-64k-core-0:5.14.0-427.47.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • +170 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (29)