Red Hat Security Advisory: kernel-rt security and bug fix update
🔗 CVE IDs covered (53)
📋 Description
CVE-2019-25162 — kernel: use after free in i2c
CVE-2020-36777 — kernel: media: dvbdev: Fix memory leak in dvb_media_device_free()
CVE-2021-46934 — kernel: i2c: validate user data in compat ioctl
CVE-2021-47013 — kernel: net:emac/emac-mac: Fix a use after free in emac_mac_tx_buf_send
CVE-2021-47055 — kernel: mtd: require write permissions for locking and badblock ioctls
CVE-2021-47118 — kernel: pid: take a reference when initializing cad_pid
CVE-2021-47153 — kernel: i2c: i801: Don't generate an interrupt on bus reset
CVE-2021-47171 — kernel: net: usb: fix memory leak in smsc75xx_bind
CVE-2021-47185 — kernel: tty: tty_buffer: Fix the softlockup issue in flush_to_ldisc
CVE-2022-48627 — kernel: vt: fix memory overlapping when deleting chars in the buffer
CVE-2023-6240 — kernel: Marvin vulnerability side-channel leakage in the RSA decryption operation
CVE-2023-52439 — kernel: uio: Fix use-after-free in uio_open
CVE-2023-52445 — kernel: pvrusb2: fix use after free on context disconnection
CVE-2023-52477 — kernel: usb: hub: Guard against accesses to uninitialized BOS descriptors
CVE-2023-52513 — kernel: RDMA/siw: Fix connection failure handling
CVE-2023-52520 — kernel: platform/x86: think-lmi: Fix reference leak
CVE-2023-52528 — kernel: net: usb: smsc75xx: Fix uninit-value access in __smsc75xx_read_reg
CVE-2023-52565 — kernel: media: uvcvideo: out-of-bounds read in uvc_query_v4l2_menu()
CVE-2023-52578 — kernel: net: bridge: data races indata-races in br_handle_frame_finish()
CVE-2023-52594 — kernel: wifi: ath9k: Fix potential array-index-out-of-bounds read in ath9k_htc_txstatus()
CVE-2023-52595 — kernel: wifi: rt2x00: restart beacon queue when hardware reset
CVE-2023-52610 — kernel: net/sched: act_ct: fix skb leak and crash on ooo frags
CVE-2024-0340 — kernel: Information disclosure in vhost/vhost.c:vhost_new_msg()
CVE-2024-23307 — kernel: Integer Overflow in raid5_cache_count
CVE-2024-25744 — kernel: untrusted VMM can trigger int80 syscall handling
CVE-2024-26593 — kernel: i2c: i801: Fix block process call transactions
CVE-2024-26603 — kernel: x86/fpu: Stop relying on userspace for info to fault in xsave buffer that cause loop forever
CVE-2024-26610 — kernel: wifi: iwlwifi: fix a memory corruption
CVE-2024-26615 — kernel: net/smc: fix illegal rmb_desc access in SMC-D connection dump
CVE-2024-26642 — kernel: netfilter: nf_tables: disallow anonymous set with timeout flag
CVE-2024-26643 — kernel: netfilter: nf_tables: mark set as dead when unbinding anonymous set with timeout
CVE-2024-26659 — kernel: xhci: handle isoc Babble and Buffer Overrun events properly
CVE-2024-26664 — kernel: hwmon: (coretemp) Fix out-of-bounds memory access
CVE-2024-26693 — kernel: wifi: iwlwifi: mvm: fix a crash when we run out of stations
CVE-2024-26694 — kernel: wifi: iwlwifi: fix double-free bug
CVE-2024-26743 — kernel: RDMA/qedr: Fix qedr_create_user_qp error flow
CVE-2024-26744 — kernel: RDMA/srpt: Support specifying the srpt_service_guid parameter
CVE-2024-26779 — kernel: wifi: mac80211: fix race condition on enabling fast-xmit
CVE-2024-26872 — kernel: RDMA/srpt: Do not register event handler until srpt device is fully setup
CVE-2024-26892 — kernel: wifi: mt76: mt7921e: fix use-after-free in free_irq()
CVE-2024-26897 — kernel: wifi: ath9k: delay all of ath9k_wmi_event_tasklet() until init is complete
CVE-2024-26901 — kernel: do_sys_name_to_handle(): use kzalloc() to fix kernel-infoleak
CVE-2024-26919 — kernel: usb: ulpi: Fix debugfs directory leak
CVE-2024-26933 — kernel: USB: core: Fix deadlock in port "disable" sysfs attribute
CVE-2024-26934 — kernel: USB: core: Fix deadlock in usb_deauthorize_interface()
CVE-2024-26964 — kernel: usb: xhci: Add error handling in xhci_map_urb_for_dma
CVE-2024-26973 — kernel: fat: fix uninitialized field in nostale filehandles
CVE-2024-26993 — kernel: fs: sysfs: Fix reference leak in sysfs_break_active_protection()
CVE-2024-27014 — kernel: net/mlx5e: Prevent deadlock while disabling aRFS
CVE-2024-27048 — kernel: wifi: brcm80211: handle pmk_op allocation failure
CVE-2024-27052 — kernel: wifi: rtl8xxxu: add cancel_work_sync() for c2hcmd_work
CVE-2024-27056 — kernel: wifi: iwlwifi: mvm: ensure offloading TID queue exists
CVE-2024-27059 — kernel: USB: usb-storage: Prevent divide-by-0 error in isd200_ata_command
🎯 Affected products32
- Red Hat Enterprise Linux NFV (v. 8)
- Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-0:4.18.0-553.5.1.rt7.346.el8_10.src as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-0:4.18.0-553.5.1.rt7.346.el8_10.src as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-core-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-core-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-core-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-core-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-debuginfo-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-debuginfo-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-devel-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-devel-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-kvm-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-modules-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-modules-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-modules-extra-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-modules-extra-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debuginfo-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debuginfo-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debuginfo-common-x86_64-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debuginfo-common-x86_64-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-devel-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-devel-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-kvm-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-modules-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-modules-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- +2 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this issue, prevent module uio from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: No mitigation is currently available for this vulnerability. Make sure to perform the updates as they become available. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, prevent the Conntrack module from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically. Workaround: This vulnerability can be mitigated by disabling 32-bit emulation by default for TDX and SEV. The user can override it with the ia32_emulation=y command line option. Workaround: To mitigate this issue, prevent module i2c-i801 from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, prevent the iwlwifi module from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: There is no known mitigation to this problem. Red Hat recommends updating to the latest kernel version to fix the problem.
🔗 References (56)
- selfhttps://access.redhat.com/errata/RHSA-2024:3627
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2250843
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257406
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2263875
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265271
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265646
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265654
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265833
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2266296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2266446
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2266746
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2266841
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267038
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267185
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267355
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267509
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267705
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267724
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267758
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267789
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267797
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267804
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268315
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268317
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2269213
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2269856
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270080
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270879
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270881
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2271469
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2271476
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2272780
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2272791
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2273092
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2273094
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2273223
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2273260
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2273262
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2274624
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2275645
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2275655
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2275666
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2275707
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2275777
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278169
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278237
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278240
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278268
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278314
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278356
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278398
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278409
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278417
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278431
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_3627.json