Red Hat Security Advisory: kernel-rt security and bug fix update
🔗 CVE IDs covered (49)
📋 Description
CVE-2019-13631 — kernel: OOB writes in parse_hid_report_descriptor in drivers/input/tablet/gtco.c CVE-2019-15505 — kernel: out of bounds read in drivers/media/usb/dvb-usb/technisat-usb2.c CVE-2020-25656 — kernel: use-after-free in read in vt_do_kdgkb_ioctl CVE-2021-3753 — kernel: a race out-of-bound read in vt CVE-2021-4204 — kernel: improper input validation may lead to privilege escalation CVE-2022-0500 — kernel: Linux ebpf logic vulnerability leads to critical memory read and write gaining root privileges CVE-2022-3565 — kernel: use-after-free in l1oip timer handlers CVE-2022-23222 — kernel: local privileges escalation in kernel/bpf/verifier.c CVE-2022-45934 — kernel: integer overflow in l2cap_config_req() in net/bluetooth/l2cap_core.c CVE-2023-1513 — kernel: KVM: information leak in KVM_GET_DEBUGREGS ioctl on 32-bit systems CVE-2023-3567 — kernel: use after free in vcs_read in drivers/tty/vt/vc_screen.c due to race CVE-2023-4133 — kernel: cxgb4: use-after-free in ch_flower_stats_cb() CVE-2023-4244 — kernel: Use-after-free in nft_verdict_dump due to a race between set GC and transaction CVE-2023-6121 — kernel: NVMe: info leak due to out-of-bounds read in nvmet_ctrl_find_get CVE-2023-6176 — kernel: local dos vulnerability in scatterwalk_copychunks CVE-2023-6622 — kernel: null pointer dereference vulnerability in nft_dynset_init() CVE-2023-6915 — kernel: Null Pointer Dereference vulnerability in ida_free in lib/idr.c CVE-2023-6932 — kernel: use-after-free in IPv4 IGMP CVE-2023-24023 — kernel: Bluetooth Forward and Future Secrecy Attacks and Defenses CVE-2023-25775 — kernel: irdma: Improper access control CVE-2023-28464 — Kernel: double free in hci_conn_cleanup of the bluetooth subsystem CVE-2023-31083 — kernel: race condition between HCIUARTSETPROTO and HCIUARTGETPROTO in hci_uart_tty_ioctl CVE-2023-37453 — kernel: usb: out-of-bounds read in read_descriptors CVE-2023-38409 — kernel: fbcon: out-of-sync arrays in fbcon_mode_deleted due to wrong con2fb_map assignment CVE-2023-39189 — kernel: netfilter: nftables out-of-bounds read in nf_osf_match_one() CVE-2023-39192 — kernel: netfilter: xtables out-of-bounds read in u32_match_it() CVE-2023-39193 — kernel: netfilter: xtables sctp out-of-bounds read in match_flags() CVE-2023-39194 — kernel: xfrm: out-of-bounds read in __xfrm_state_filter_match() CVE-2023-39198 — kernel: QXL: race condition leading to use-after-free in qxl_mode_dumb_create() CVE-2023-42754 — kernel: ipv4: NULL pointer dereference in ipv4_send_dest_unreach() CVE-2023-42755 — kernel: rsvp: out-of-bounds read in rsvp_classify() CVE-2023-45863 — kernel: lib/kobject.c vulnerable to fill_kobj_path out-of-bounds write CVE-2023-51779 — kernel: bluetooth: bt_sock_ioctl race condition leads to use-after-free in bt_sock_recvmsg CVE-2023-51780 — kernel: use-after-free in net/atm/ioctl.c CVE-2023-52340 — kernel: ICMPv6 “Packet Too Big” packets force a DoS of the Linux kernel by forcing 100% CPU CVE-2023-52434 — kernel: smb: client: fix potential OOBs in smb2_parse_contexts() CVE-2023-52448 — kernel: gfs2: Fix kernel NULL pointer dereference in gfs2_rgrp_dump CVE-2023-52489 — kernel: mm/sparsemem: fix race in accessing memory_section->usage CVE-2023-52574 — kernel: team: NULL pointer dereference when team device type is changed CVE-2023-52580 — kernel: net/core: kernel crash in ETH_P_1588 flow dissector CVE-2023-52581 — kernel: netfilter: nf_tables: memory leak when more than 255 elements expired CVE-2023-52597 — kernel: KVM: s390: fix setting of fpc register CVE-2023-52620 — kernel: netfilter: nf_tables: disallow timeout for anonymous sets CVE-2024-0841 — kernel: hugetlbfs: Null pointer dereference in hugetlbfs_fill_super function CVE-2024-25742 — hw: amd: Instruction raise #VC exception at exit CVE-2024-25743 — hw: amd: Instruction raise #VC exception at exit CVE-2024-26602 — kernel: sched/membarrier: reduce the ability to hammer on sys_membarrier CVE-2024-26609 — kernel: netfilter: nf_tables: reject QUEUE/DROP verdict parameters CVE-2024-26671 — kernel: blk-mq: fix IO hang from sbitmap wakeup race
🎯 Affected products32
- Red Hat Enterprise Linux NFV (v. 8)
- Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-0:4.18.0-553.rt7.342.el8_10.src as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-0:4.18.0-553.rt7.342.el8_10.src as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-core-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-core-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-core-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-core-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-debuginfo-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-debuginfo-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-devel-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-devel-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-kvm-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-modules-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-modules-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-modules-extra-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-modules-extra-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debuginfo-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debuginfo-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debuginfo-common-x86_64-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debuginfo-common-x86_64-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-devel-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-devel-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-kvm-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-modules-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-modules-0:4.18.0-553.rt7.342.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- +2 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: It is possible to prevent the kernel from loading the affected code by blacklisting the gtco kernel module. Visit https://access.redhat.com/solutions/41278 for specifics. Workaround: Mitigation for this issue is to skip loading the affected module technisat_usb2 onto the system till we have a fix available, this can be done by a blacklist mechanism, this will ensure the driver is not loaded at the boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: For the Red Hat Enterprise Linux 7 the eBPF for unprivileged users is always disabled. For the Red Hat Enterprise Linux 8 to confirm the current state, inspect the sysctl with the command: # cat /proc/sys/kernel/unprivileged_bpf_disabled The setting of 1 would mean that unprivileged users can not use eBPF, mitigating the flaw. A kernel update will be required to mitigate the flaw for the root or users with CAP_SYS_ADMIN capabilities. Workaround: The default Red Hat Enterprise Linux kernel prevents unprivileged users from being able to use eBPF by the kernel.unprivileged_bpf_disabled sysctl. This would require a privileged user with CAP_SYS_ADMIN or root to be able to abuse this flaw reducing its attack space. For Red Hat Enterprise Linux 7 the eBPF for unprivileged users is always disabled. For Red Hat Enterprise Linux 8 to confirm the current state, inspect the sysctl with the command: ``` # cat /proc/sys/kernel/unprivileged_bpf_disabled ``` The setting of 1 would mean that unprivileged users can not use eBPF, mitigating the flaw. A kernel update will be required to mitigate the flaw for the root or users with CAP_SYS_ADMIN (or CAP_BPF) capabilities. Workaround: To mitigate this issue, prevent the l1oip module from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate these vulnerabilities on the operating system level, disable the Bluetooth functionality via blocklisting kernel modules in the Linux kernel. The kernel modules can be prevented from being loaded by using system-wide modprobe rules. Instructions on how to disable Bluetooth modules are available on the customer portal at https://access.redhat.com/solutions/2682931. Alternatively, bluetooth can be disabled within the hardware or at the BIOS level, which will also provide effective mitigation as the kernel will not detect Bluetooth hardware on the system. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is to skip loading the affected module "nftables" onto the system till we have a fix available, this can be done by a blacklist mechanism, this will ensure the driver is not loaded at the boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: This flaw can be mitigated by explicitly setting the kernel parameter to restrict unprivileged users from using dmesg: ``` sudo sysctl -w kernel.dmesg_restrict=1 ``` To make it persistent between system reboots: ``` echo 'kernel.dmesg_restrict=1' | sudo tee -a /etc/sysctl.conf ``` Workaround: Mitigation for this issue is to skip loading the affected module "netfilter" onto the system till we have a fix available, this can be done by a blacklist mechanism, this will ensure the driver is not loaded at the boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 Workaround: To mitigate this issue, prevent module hci_uart from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: Mitigation for this issue is to skip loading the affected module "fbcon" onto the system until we have a fix available. This can be done by a blacklist mechanism and will ensure the driver is not loaded at boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: This flaw can be mitigated by preventing the affected Passive OS Fingerprinting match module (`xt_osf`) from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278. Workaround: This flaw can be mitigated by preventing the affected `xt_u32` kernel module from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278. Workaround: This flaw can be mitigated by preventing the affected `xt_sctp` kernel module from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: This flaw can be mitigated by preventing the affected `cls_rsvp` kernel module from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278. Workaround: To mitigate this issue, prevent module atm from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent module cifs from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: No mitigation is currently available for this vulnerability. Make sure to perform the updates as they become available. Workaround: Mitigation for this issue is to skip loading the affected module "nftables" onto the system until we have an available fix. This can be done by a blacklist mechanism and will ensure the driver is not loaded at the boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (51)
- selfhttps://access.redhat.com/errata/RHSA-2024:2950
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.10_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1731000
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1746732
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1888726
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1999589
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2039178
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2043520
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2044578
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2150953
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2151959
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2177759
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2179892
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2213132
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2218332
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2219359
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221039
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221463
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221702
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2226777
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2226784
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2226787
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2226788
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2230042
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2231410
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2235306
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2239845
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2239847
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2244720
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2250043
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2253632
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254961
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254982
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255283
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2256490
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2256822
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257682
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257979
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265285
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265653
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267695
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267750
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267760
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267761
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2269189
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2269217
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270836
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270883
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2272811
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2950.json