Red Hat Security Advisory: kernel security, bug fix, and enhancement update
🔗 CVE IDs covered (162)
📋 Description
CVE-2019-13631 — kernel: OOB writes in parse_hid_report_descriptor in drivers/input/tablet/gtco.c CVE-2019-15505 — kernel: out of bounds read in drivers/media/usb/dvb-usb/technisat-usb2.c CVE-2020-25656 — kernel: use-after-free in read in vt_do_kdgkb_ioctl CVE-2021-3753 — kernel: a race out-of-bound read in vt CVE-2021-4204 — kernel: improper input validation may lead to privilege escalation CVE-2022-0500 — kernel: Linux ebpf logic vulnerability leads to critical memory read and write gaining root privileges CVE-2022-3565 — kernel: use-after-free in l1oip timer handlers CVE-2022-23222 — kernel: local privileges escalation in kernel/bpf/verifier.c CVE-2022-45934 — kernel: integer overflow in l2cap_config_req() in net/bluetooth/l2cap_core.c CVE-2022-48947 — kernel: Bluetooth: L2CAP: Fix u8 overflow CVE-2022-49081 — kernel: highmem: fix checks in _kmap_local_sched{in,out} CVE-2022-49700 — kernel: mm/slub: add missing TID updates on slab deactivation CVE-2022-49759 — kernel: VMCI: Use threaded irqs instead of tasklets CVE-2022-49885 — kernel: ACPI: APEI: Fix integer overflow in ghes_estatus_pool_init() CVE-2022-49940 — kernel: tty: n_gsm: add sanity check for gsm->receive in gsm_receive_buf() CVE-2022-50116 — kernel: tty: n_gsm: fix deadlock and link starvation in outgoing data path CVE-2022-50126 — kernel: jbd2: fix assertion 'jh->b_frozen_data == NULL' failure when journal aborted CVE-2022-50153 — kernel: usb: host: Fix refcount leak in ehci_hcd_ppc_of_probe CVE-2022-50274 — kernel: media: dvbdev: adopts refcnt to avoid UAF CVE-2022-50286 — kernel: ext4: fix delayed allocation bug in ext4_clu_mapped for bigalloc + inline CVE-2022-50327 — kernel: ACPI: processor: idle: Check acpi_fetch_acpi_dev() return value CVE-2022-50344 — kernel: ext4: fix null-ptr-deref in ext4_write_info CVE-2022-50346 — kernel: ext4: init quota for 'old.inode' in 'ext4_rename' CVE-2022-50403 — kernel: ext4: fix undefined behavior in bit shift for ext4_check_flag_values CVE-2022-50423 — kernel: Linux kernel: Information disclosure and denial of service via use-after-free in ACPI subsystem CVE-2022-50485 — kernel: ext4: add EXT4_IGET_BAD flag to prevent unexpected bad inode CVE-2022-50546 — kernel: ext4: fix uninititialized value in 'ext4_evict_inode' CVE-2022-50635 — kernel: powerpc/kprobes: Fix null pointer reference in arch_prepare_kprobe() CVE-2022-50638 — kernel: ext4: fix bug_on in __es_tree_search caused by bad boot loader inode CVE-2022-50668 — kernel: ext4: fix deadlock due to mbcache entry corruption CVE-2022-50717 — kernel: nvmet-tcp: add bounds check on Transfer Tag CVE-2022-50730 — kernel: ext4: silence the warning when evicting inode with dioread_nolock CVE-2022-50782 — kernel: ext4: fix bug_on in __es_tree_search caused by bad quota inode CVE-2023-1513 — kernel: KVM: information leak in KVM_GET_DEBUGREGS ioctl on 32-bit systems CVE-2023-3567 — kernel: use after free in vcs_read in drivers/tty/vt/vc_screen.c due to race CVE-2023-4133 — kernel: cxgb4: use-after-free in ch_flower_stats_cb() CVE-2023-4244 — kernel: Use-after-free in nft_verdict_dump due to a race between set GC and transaction CVE-2023-6121 — kernel: NVMe: info leak due to out-of-bounds read in nvmet_ctrl_find_get CVE-2023-6176 — kernel: local dos vulnerability in scatterwalk_copychunks CVE-2023-6622 — kernel: null pointer dereference vulnerability in nft_dynset_init() CVE-2023-6915 — kernel: Null Pointer Dereference vulnerability in ida_free in lib/idr.c CVE-2023-6932 — kernel: use-after-free in IPv4 IGMP CVE-2023-24023 — kernel: Bluetooth Forward and Future Secrecy Attacks and Defenses CVE-2023-25775 — kernel: irdma: Improper access control CVE-2023-28464 — Kernel: double free in hci_conn_cleanup of the bluetooth subsystem CVE-2023-31083 — kernel: race condition between HCIUARTSETPROTO and HCIUARTGETPROTO in hci_uart_tty_ioctl CVE-2023-37453 — kernel: usb: out-of-bounds read in read_descriptors CVE-2023-38409 — kernel: fbcon: out-of-sync arrays in fbcon_mode_deleted due to wrong con2fb_map assignment CVE-2023-39189 — kernel: netfilter: nftables out-of-bounds read in nf_osf_match_one() CVE-2023-39192 — kernel: netfilter: xtables out-of-bounds read in u32_match_it() CVE-2023-39193 — kernel: netfilter: xtables sctp out-of-bounds read in match_flags() CVE-2023-39194 — kernel: xfrm: out-of-bounds read in __xfrm_state_filter_match() CVE-2023-39198 — kernel: QXL: race condition leading to use-after-free in qxl_mode_dumb_create() CVE-2023-42754 — kernel: ipv4: NULL pointer dereference in ipv4_send_dest_unreach() CVE-2023-42755 — kernel: rsvp: out-of-bounds read in rsvp_classify() CVE-2023-45863 — kernel: lib/kobject.c vulnerable to fill_kobj_path out-of-bounds write CVE-2023-51779 — kernel: bluetooth: bt_sock_ioctl race condition leads to use-after-free in bt_sock_recvmsg CVE-2023-51780 — kernel: use-after-free in net/atm/ioctl.c CVE-2023-52340 — kernel: ICMPv6 “Packet Too Big” packets force a DoS of the Linux kernel by forcing 100% CPU CVE-2023-52434 — kernel: smb: client: fix potential OOBs in smb2_parse_contexts() CVE-2023-52448 — kernel: gfs2: Fix kernel NULL pointer dereference in gfs2_rgrp_dump CVE-2023-52489 — kernel: mm/sparsemem: fix race in accessing memory_section->usage CVE-2023-52574 — kernel: team: NULL pointer dereference when team device type is changed CVE-2023-52580 — kernel: net/core: kernel crash in ETH_P_1588 flow dissector CVE-2023-52581 — kernel: netfilter: nf_tables: memory leak when more than 255 elements expired CVE-2023-52597 — kernel: KVM: s390: fix setting of fpc register CVE-2023-52620 — kernel: netfilter: nf_tables: disallow timeout for anonymous sets CVE-2023-52924 — kernel: netfilter: nf_tables: don't skip expired elements during walk CVE-2023-52973 — kernel: vc_screen: move load of struct vc_data pointer in vcs_read() to avoid UAF CVE-2023-53070 — kernel: ACPI: PPTT: Fix to avoid sleep in the atomic context when PPTT is absent CVE-2023-53072 — kernel: mptcp: use the workqueue to destroy unaccepted sockets CVE-2023-53088 — kernel: mptcp: fix UaF in listener shutdown CVE-2023-53089 — kernel: ext4: fix task hung in ext4_xattr_delete_inode CVE-2023-53103 — kernel: bonding: restore bond's IFF_SLAVE flag if a non-eth dev enslave fails CVE-2023-53134 — kernel: bnxt_en: Avoid order-5 memory allocation for TPA data CVE-2023-53140 — kernel: scsi: core: Remove the /proc/scsi/${proc_name} directory earlier CVE-2023-53148 — kernel: igb: Fix igb_down hung on surprise removal CVE-2023-53150 — kernel: scsi: qla2xxx: Pointer may be dereferenced CVE-2023-53151 — kernel: Linux kernel: md/raid10 soft lockup due to unlimited plugged bio CVE-2023-53182 — kernel: Linux kernel: ACPICA undefined behavior due to zero offset to null pointer CVE-2023-53202 — kernel: PM: domains: fix memory leak with using debugfs_lookup() CVE-2023-53205 — kernel: KVM: s390/diag: fix racy access of physical cpu number in diag 9c handler CVE-2023-53210 — kernel: md/raid5-cache: fix null-ptr-deref for r5l_flush_stripe_to_raid() CVE-2023-53224 — kernel: ext4: Fix function prototype mismatch for ext4_feat_ktype CVE-2023-53266 — kernel: arm64: acpi: Fix possible memory leak of ffh_ctxt CVE-2023-53275 — kernel: ALSA: hda: fix a possible null-pointer dereference due to data race in snd_hdac_regmap_sync() CVE-2023-53280 — kernel: scsi: qla2xxx: Remove unused nvme_ls_waitq wait queue CVE-2023-53322 — kernel: scsi: qla2xxx: Wait for io return on terminate rport CVE-2023-53335 — kernel: RDMA/cxgb4: Fix potential null-ptr-deref in pass_establish() CVE-2023-53343 — kernel: icmp6: Fix null-ptr-deref of ip6_null_entry->rt6i_idev in icmp6_dev() CVE-2023-53354 — kernel: skbuff: skb_segment, Call zero copy functions before using skbuff frags CVE-2023-53365 — kernel: ip6mr: Fix skb_under_panic in ip6mr_cache_report() CVE-2023-53371 — kernel: net/mlx5e: fix memory leak in mlx5e_fs_tt_redirect_any_create CVE-2023-53380 — kernel: md/raid10: fix null-ptr-deref of mreplace in raid10_sync_request CVE-2023-53392 — kernel: HID: intel-ish-hid: Fix kernel panic during warm reset CVE-2023-53441 — kernel: bpf: cpumap: Fix memory leak in cpu_map_update_elem CVE-2023-53442 — kernel: ice: Block switchdev mode when ADQ is active and vice versa CVE-2023-53451 — kernel: scsi: qla2xxx: Fix potential NULL pointer dereference CVE-2023-53476 — kernel: iw_cxgb4: Fix potential NULL dereference in c4iw_fill_res_cm_id_entry() CVE-2023-53483 — kernel: ACPI: processor: Check for null return of devm_kzalloc() in fch_misc_setup() CVE-2023-53496 — kernel: x86/platform/uv: Use alternate source for socket to node data CVE-2023-53501 — kernel: Linux kernel: Denial of Service due to race condition in IOMMU pasid unbinding CVE-2023-53525 — kernel: RDMA/cma: Allow UD qp_type to join multicast only CVE-2023-53530 — kernel: scsi: qla2xxx: Use raw_smp_processor_id() instead of smp_processor_id() CVE-2023-53546 — kernel: net/mlx5: DR, fix memory leak in mlx5dr_cmd_create_reformat_ctx CVE-2023-53550 — kernel: cpufreq: amd-pstate: fix global sysfs attribute type CVE-2023-53559 — kernel: ip_vti: fix potential slab-use-after-free in decode_session6 CVE-2023-53576 — kernel: null_blk: Always check queue mode setting from configfs CVE-2023-53577 — kernel: bpf, cpumap: Make sure kthread is running before map update returns CVE-2023-53581 — kernel: net/mlx5e: Check for NOT_READY flag state after locking CVE-2023-53586 — kernel: scsi: target: Fix multiple LUN_RESET handling CVE-2023-53611 — kernel: ipmi_si: fix a memleak in try_smi_init() CVE-2023-53615 — kernel: scsi: qla2xxx: Fix deletion race condition CVE-2023-53623 — kernel: mm/swap: fix swap_info_struct race between swapoff and get_swap_pages() CVE-2023-53648 — kernel: ALSA: ac97: Fix possible NULL dereference in snd_ac97_mixer CVE-2023-53657 — kernel: ice: Don't tx before switchdev is fully configured CVE-2023-53661 — kernel: bnxt: avoid overflow in bnxt_get_nvram_directory() CVE-2023-53696 — kernel: scsi: qla2xxx: Fix memory leak in qla2x00_probe_one() CVE-2023-53698 — kernel: xsk: fix refcount underflow in error path CVE-2023-53705 — kernel: ipv6: Fix out-of-bounds access in ipv6_find_tlv() CVE-2023-53722 — kernel: md: raid1: fix potential OOB in raid1_remove_disk() CVE-2023-53746 — kernel: s390/vfio-ap: fix memory leak in vfio_ap device driver CVE-2023-53761 — kernel: USB: usbtmc: Fix direction for 0-length ioctl control messages CVE-2023-53798 — kernel: ethtool: Fix uninitialized number of lanes CVE-2023-53821 — kernel: ip6_vti: fix slab-use-after-free in decode_session6 CVE-2023-53843 — kernel: net: openvswitch: reject negative ifindex CVE-2023-53848 — kernel: md/raid5-cache: fix a deadlock in r5l_exit_log() CVE-2023-53867 — kernel: ceph: fix potential use-after-free bug when trimming caps CVE-2023-53995 — kernel: Linux kernel: Denial of Service due to memory leak in IP address deletion CVE-2023-53996 — kernel: x86/sev: Make enc_dec_hypercall() accept a size instead of npages CVE-2023-53999 — kernel: Linux kernel: Denial of Service due to memory leak in mlx5e driver CVE-2023-54003 — kernel: Linux kernel: RDMA/core GID entry leak causes Denial of Service CVE-2023-54004 — kernel: Linux kernel UDPLITE: Denial of Service via null pointer dereference CVE-2023-54010 — kernel: Linux kernel: Denial of Service via null pointer dereference in ACPI CVE-2023-54014 — kernel: scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport() CVE-2023-54057 — kernel: iommu/amd: Add a length limitation for the ivrs_acpihid command-line parameter CVE-2023-54064 — kernel: Kernel: Memory leak in IPMI SSIF module leads to Denial of Service CVE-2023-54070 — kernel: Linux kernel igb driver: Denial of Service due to improper SR-IOV cleanup CVE-2023-54072 — kernel: Linux kernel: Denial of service or memory corruption due to a data race in ALSA PCM memory allocation CVE-2023-54090 — kernel: ixgbe: Fix panic during XDP_TX with > 64 CPUs CVE-2023-54096 — kernel: Linux kernel (soundwire): Memory corruption due to incorrect device enumeration completion CVE-2023-54100 — kernel: scsi: qedi: Fix use after free bug in qedi_remove() CVE-2023-54106 — kernel: Linux kernel: Denial of Service via memory leak in mlx5e_init_rep_rx CVE-2023-54148 — kernel: net/mlx5e: Move representor neigh cleanup to profile cleanup_tx CVE-2023-54166 — kernel: igc: Fix Kernel Panic during ndo_tx_timeout callback CVE-2023-54169 — kernel: net/mlx5e: fix memory leak in mlx5e_ptp_open CVE-2023-54179 — kernel: scsi: qla2xxx: Array index may go out of bound CVE-2023-54184 — kernel: scsi: target: iscsit: Free cmds before session free CVE-2023-54186 — kernel: usb: typec: altmodes/displayport: fix pin_assignment_show CVE-2023-54201 — kernel: RDMA/efa: Fix wrong resources deallocation order CVE-2023-54244 — kernel: ACPI: EC: Fix oops when removing custom query handlers CVE-2023-54274 — kernel: RDMA/srpt: Add a check for valid 'mad_agent' pointer CVE-2023-54289 — kernel: scsi: qedf: Fix NULL dereference in error handling CVE-2023-54320 — kernel: platform/x86/amd: pmc: Fix memory leak in amd_pmc_stb_debugfs_open_v2() CVE-2023-54324 — kernel: dm: fix a race condition in retrieve_deps CVE-2024-0841 — kernel: hugetlbfs: Null pointer dereference in hugetlbfs_fill_super function CVE-2024-25742 — hw: amd: Instruction raise #VC exception at exit CVE-2024-25743 — hw: amd: Instruction raise #VC exception at exit CVE-2024-26602 — kernel: sched/membarrier: reduce the ability to hammer on sys_membarrier CVE-2024-26609 — kernel: netfilter: nf_tables: reject QUEUE/DROP verdict parameters CVE-2024-26671 — kernel: blk-mq: fix IO hang from sbitmap wakeup race CVE-2024-26830 — kernel: i40e: Do not allow untrusted VF to remove administratively set MAC
🎯 Affected products122
- Red Hat Enterprise Linux BaseOS (v. 8)
- Red Hat Enterprise Linux CRB (v. 8)
- bpftool-0:4.18.0-553.el8_10.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bpftool-0:4.18.0-553.el8_10.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bpftool-0:4.18.0-553.el8_10.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bpftool-0:4.18.0-553.el8_10.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bpftool-debuginfo-0:4.18.0-553.el8_10.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bpftool-debuginfo-0:4.18.0-553.el8_10.aarch64 as a component of Red Hat Enterprise Linux CRB (v. 8)
- bpftool-debuginfo-0:4.18.0-553.el8_10.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bpftool-debuginfo-0:4.18.0-553.el8_10.ppc64le as a component of Red Hat Enterprise Linux CRB (v. 8)
- bpftool-debuginfo-0:4.18.0-553.el8_10.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bpftool-debuginfo-0:4.18.0-553.el8_10.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- bpftool-debuginfo-0:4.18.0-553.el8_10.x86_64 as a component of Red Hat Enterprise Linux CRB (v. 8)
- kernel-0:4.18.0-553.el8_10.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-0:4.18.0-553.el8_10.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-0:4.18.0-553.el8_10.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-0:4.18.0-553.el8_10.src as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-0:4.18.0-553.el8_10.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-abi-stablelists-0:4.18.0-553.el8_10.noarch as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-core-0:4.18.0-553.el8_10.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-core-0:4.18.0-553.el8_10.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-core-0:4.18.0-553.el8_10.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-core-0:4.18.0-553.el8_10.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-debug-0:4.18.0-553.el8_10.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-debug-0:4.18.0-553.el8_10.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-debug-0:4.18.0-553.el8_10.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-debug-0:4.18.0-553.el8_10.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-debug-core-0:4.18.0-553.el8_10.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-debug-core-0:4.18.0-553.el8_10.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- kernel-debug-core-0:4.18.0-553.el8_10.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- +92 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: It is possible to prevent the kernel from loading the affected code by blacklisting the gtco kernel module. Visit https://access.redhat.com/solutions/41278 for specifics. Workaround: Mitigation for this issue is to skip loading the affected module technisat_usb2 onto the system till we have a fix available, this can be done by a blacklist mechanism, this will ensure the driver is not loaded at the boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: For the Red Hat Enterprise Linux 7 the eBPF for unprivileged users is always disabled. For the Red Hat Enterprise Linux 8 to confirm the current state, inspect the sysctl with the command: # cat /proc/sys/kernel/unprivileged_bpf_disabled The setting of 1 would mean that unprivileged users can not use eBPF, mitigating the flaw. A kernel update will be required to mitigate the flaw for the root or users with CAP_SYS_ADMIN capabilities. Workaround: The default Red Hat Enterprise Linux kernel prevents unprivileged users from being able to use eBPF by the kernel.unprivileged_bpf_disabled sysctl. This would require a privileged user with CAP_SYS_ADMIN or root to be able to abuse this flaw reducing its attack space. For Red Hat Enterprise Linux 7 the eBPF for unprivileged users is always disabled. For Red Hat Enterprise Linux 8 to confirm the current state, inspect the sysctl with the command: ``` # cat /proc/sys/kernel/unprivileged_bpf_disabled ``` The setting of 1 would mean that unprivileged users can not use eBPF, mitigating the flaw. A kernel update will be required to mitigate the flaw for the root or users with CAP_SYS_ADMIN (or CAP_BPF) capabilities. Workaround: To mitigate this issue, prevent the l1oip module from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate these vulnerabilities on the operating system level, disable the Bluetooth functionality via blocklisting kernel modules in the Linux kernel. The kernel modules can be prevented from being loaded by using system-wide modprobe rules. Instructions on how to disable Bluetooth modules are available on the customer portal at https://access.redhat.com/solutions/2682931. Alternatively, bluetooth can be disabled within the hardware or at the BIOS level, which will also provide effective mitigation as the kernel will not detect Bluetooth hardware on the system. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is to skip loading the affected module "nftables" onto the system till we have a fix available, this can be done by a blacklist mechanism, this will ensure the driver is not loaded at the boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: This flaw can be mitigated by explicitly setting the kernel parameter to restrict unprivileged users from using dmesg: ``` sudo sysctl -w kernel.dmesg_restrict=1 ``` To make it persistent between system reboots: ``` echo 'kernel.dmesg_restrict=1' | sudo tee -a /etc/sysctl.conf ``` Workaround: Mitigation for this issue is to skip loading the affected module "netfilter" onto the system till we have a fix available, this can be done by a blacklist mechanism, this will ensure the driver is not loaded at the boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 Workaround: To mitigate this issue, prevent module hci_uart from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: Mitigation for this issue is to skip loading the affected module "fbcon" onto the system until we have a fix available. This can be done by a blacklist mechanism and will ensure the driver is not loaded at boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: This flaw can be mitigated by preventing the affected Passive OS Fingerprinting match module (`xt_osf`) from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278. Workaround: This flaw can be mitigated by preventing the affected `xt_u32` kernel module from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278. Workaround: This flaw can be mitigated by preventing the affected `xt_sctp` kernel module from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: This flaw can be mitigated by preventing the affected `cls_rsvp` kernel module from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278. Workaround: To mitigate this issue, prevent module atm from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent module cifs from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: No mitigation is currently available for this vulnerability. Make sure to perform the updates as they become available. Workaround: Mitigation for this issue is to skip loading the affected module "nftables" onto the system until we have an available fix. This can be done by a blacklist mechanism and will ensure the driver is not loaded at the boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~ Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this issue, prevent the null_blk module from loading. See https://access.redhat.com/solutions/41278 for instructions on blacklisting kernel modules. Workaround: To mitigate this issue, prevent the mlx5_core module from loading. See https://access.redhat.com/solutions/41278 for instructions on blacklisting kernel modules. Workaround: To mitigate this issue, prevent the ipmi_si module from being loaded. See https://access.redhat.com/solutions/41278 for instructions on blacklisting kernel modules. Workaround: To mitigate this issue, prevent the `igb` kernel module from loading with SR-IOV enabled. If the `igb` driver is not in use, blacklist the module by creating a file `/etc/modprobe.d/blacklist-igb.conf` with the content `blacklist igb`. Regenerate the initramfs and reboot the system for the changes to take effect. If the `igb` driver is require…
🔗 References (58)
- selfhttps://access.redhat.com/errata/RHSA-2024:3138
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.10_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1731000
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1746732
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1888726
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1930388
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1999589
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2039178
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2043520
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2044578
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2150953
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2151959
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2177759
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2179892
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2213132
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2218332
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2219359
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221039
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221463
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221702
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2226777
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2226784
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2226787
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2226788
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2230042
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2231130
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2231410
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2235306
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2239845
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2239847
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2244720
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2250043
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2253632
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254961
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254982
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255283
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2256490
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2256822
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257682
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257979
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265285
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265653
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267695
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267750
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267760
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267761
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2269189
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2269217
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270836
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270883
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2272811
- externalhttps://issues.redhat.com/browse/RHEL-15148
- externalhttps://issues.redhat.com/browse/RHEL-15311
- externalhttps://issues.redhat.com/browse/RHEL-6030
- externalhttps://issues.redhat.com/browse/RHEL-7994
- externalhttps://issues.redhat.com/browse/RHEL-9128
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_3138.json