Red Hat Security Advisory: kernel-rt security update
🔗 CVE IDs covered (9)
📋 Description
CVE-2024-46695 — kernel: selinux,smack: don't bypass permissions check in inode_setsecctx hook CVE-2024-49949 — kernel: net: avoid potential underflow in qdisc_pkt_len_init() with UFO CVE-2024-50082 — kernel: blk-rq-qos: fix crash on rq_qos_wait vs. rq_qos_wake_function race CVE-2024-50099 — kernel: arm64: probes: Remove broken LDR (literal) uprobe support CVE-2024-50110 — kernel: xfrm: fix one more kernel-infoleak in algo dumping CVE-2024-50142 — kernel: xfrm: validate new SA's prefixlen using SA family when sel.family is unset CVE-2024-50192 — kernel: irqchip/gic-v4: Don't allow a VMOVP on a dying VPE CVE-2024-50256 — kernel: netfilter: nf_reject_ipv6: fix potential crash in nf_send_reset6() CVE-2024-50264 — kernel: vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans
🎯 Affected products32
- Red Hat Enterprise Linux NFV (v. 8)
- Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-0:4.18.0-553.32.1.rt7.373.el8_10.src as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-0:4.18.0-553.32.1.rt7.373.el8_10.src as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-core-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-core-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-core-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-core-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-debuginfo-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-debuginfo-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-devel-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-devel-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-kvm-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-modules-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-modules-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-modules-extra-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-modules-extra-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debuginfo-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debuginfo-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debuginfo-common-x86_64-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debuginfo-common-x86_64-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-devel-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-devel-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-kvm-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-modules-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-modules-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- +2 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2024:10944
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2312083
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2320505
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2322308
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2323904
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2323930
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2324315
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2324612
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2324889
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2327168
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_10944.json