Red Hat Security Advisory: kernel security update
🔗 CVE IDs covered (20)
📋 Description
CVE-2022-50341 — kernel: cifs: fix oops during encryption CVE-2023-0597 — kernel: x86/mm: Randomize per-cpu entry area CVE-2023-52619 — kernel: pstore/ram: Fix crash when setting number of cpus to an odd number CVE-2023-52749 — kernel: spi: Fix null dereference on suspend CVE-2023-52881 — kernel: TCP-spoofed ghost ACKs and leak leak initial sequence number CVE-2023-53521 — kernel: scsi: ses: Fix slab-out-of-bounds in ses_intf_remove() CVE-2023-53803 — kernel: scsi: ses: Fix slab-out-of-bounds in ses_enclosure_data_process() CVE-2024-26984 — kernel: nouveau: fix instmem race condition around ptr stores CVE-2024-27399 — kernel: Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout CVE-2024-36920 — kernel: scsi: mpi3mr: Avoid memcpy field-spanning write WARNING CVE-2024-36928 — kernel: s390/qeth: Fix kernel panic after setting hsuid CVE-2024-37356 — kernel: tcp: Fix shift-out-of-bounds in dctcp_update_alpha(). CVE-2024-40988 — kernel: drm/radeon: fix UBSAN warning in kv_dpm.c CVE-2024-41009 — kernel: bpf: Fix overrunning reservations in ringbuf CVE-2024-41014 — kernel: xfs: add bounds checking to xlog_recover_process_data CVE-2024-41041 — kernel: udp: Set SOCK_RCU_FREE earlier in udp_lib_get_port() CVE-2024-41093 — kernel: drm/amdgpu: avoid using null object of framebuffer CVE-2024-42154 — kernel: tcp_metrics: validate source addr length CVE-2024-42240 — kernel: x86/bhi: Avoid warning in #DB handler due to BHI mitigation CVE-2024-43854 — kernel: block: initialize integrity buffer to zero before writing it to media
🎯 Affected products200
- Red Hat CodeReady Linux Builder EUS (v.9.2)
- Red Hat Enterprise Linux AppStream EUS (v.9.2)
- Red Hat Enterprise Linux BaseOS EUS (v.9.2)
- bpftool-0:7.0.0-284.95.1.el9_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.2)
- bpftool-0:7.0.0-284.95.1.el9_2.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.2)
- bpftool-0:7.0.0-284.95.1.el9_2.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.2)
- bpftool-0:7.0.0-284.95.1.el9_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.2)
- bpftool-debuginfo-0:7.0.0-284.95.1.el9_2.aarch64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.2)
- bpftool-debuginfo-0:7.0.0-284.95.1.el9_2.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.2)
- bpftool-debuginfo-0:7.0.0-284.95.1.el9_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.2)
- bpftool-debuginfo-0:7.0.0-284.95.1.el9_2.ppc64le as a component of Red Hat CodeReady Linux Builder EUS (v.9.2)
- bpftool-debuginfo-0:7.0.0-284.95.1.el9_2.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v.9.2)
- bpftool-debuginfo-0:7.0.0-284.95.1.el9_2.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.2)
- bpftool-debuginfo-0:7.0.0-284.95.1.el9_2.s390x as a component of Red Hat CodeReady Linux Builder EUS (v.9.2)
- bpftool-debuginfo-0:7.0.0-284.95.1.el9_2.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v.9.2)
- bpftool-debuginfo-0:7.0.0-284.95.1.el9_2.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.2)
- bpftool-debuginfo-0:7.0.0-284.95.1.el9_2.x86_64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.2)
- bpftool-debuginfo-0:7.0.0-284.95.1.el9_2.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.2)
- bpftool-debuginfo-0:7.0.0-284.95.1.el9_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.2)
- kernel-0:5.14.0-284.95.1.el9_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.2)
- kernel-0:5.14.0-284.95.1.el9_2.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.2)
- kernel-0:5.14.0-284.95.1.el9_2.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.2)
- kernel-0:5.14.0-284.95.1.el9_2.src as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.2)
- kernel-0:5.14.0-284.95.1.el9_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.2)
- kernel-64k-0:5.14.0-284.95.1.el9_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.2)
- kernel-64k-core-0:5.14.0-284.95.1.el9_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.2)
- kernel-64k-debug-0:5.14.0-284.95.1.el9_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.2)
- kernel-64k-debug-core-0:5.14.0-284.95.1.el9_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.2)
- kernel-64k-debug-debuginfo-0:5.14.0-284.95.1.el9_2.aarch64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.2)
- kernel-64k-debug-debuginfo-0:5.14.0-284.95.1.el9_2.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.2)
- +170 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this issue, prevent the ses module from being loaded. See https://access.redhat.com/solutions/41278 for instructions. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Fix this issue by adding the __GFP_ZERO flag to allocations for writes.
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2024:10772
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2165926
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258875
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270084
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278333
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2280462
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2282679
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2284515
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293658
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297572
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2298412
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2300297
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2300410
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2300488
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2301522
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_10772.json