RHSA-2024:3627MediumCVSS 7.8

Red Hat Security Advisory: kernel-rt security and bug fix update

Published
June 5, 2024
Last Modified
August 6, 2026

🔗 CVE IDs covered (53)

📋 Description

CVE-2019-25162 — kernel: use after free in i2c CVE-2020-36777 — kernel: media: dvbdev: Fix memory leak in dvb_media_device_free() CVE-2021-46934 — kernel: i2c: validate user data in compat ioctl CVE-2021-47013 — kernel: net:emac/emac-mac: Fix a use after free in emac_mac_tx_buf_send CVE-2021-47055 — kernel: mtd: require write permissions for locking and badblock ioctls CVE-2021-47118 — kernel: pid: take a reference when initializing cad_pid CVE-2021-47153 — kernel: i2c: i801: Don't generate an interrupt on bus reset CVE-2021-47171 — kernel: net: usb: fix memory leak in smsc75xx_bind CVE-2021-47185 — kernel: tty: tty_buffer: Fix the softlockup issue in flush_to_ldisc CVE-2022-48627 — kernel: vt: fix memory overlapping when deleting chars in the buffer CVE-2023-6240 — kernel: Marvin vulnerability side-channel leakage in the RSA decryption operation CVE-2023-52439 — kernel: uio: Fix use-after-free in uio_open CVE-2023-52445 — kernel: pvrusb2: fix use after free on context disconnection CVE-2023-52477 — kernel: usb: hub: Guard against accesses to uninitialized BOS descriptors CVE-2023-52513 — kernel: RDMA/siw: Fix connection failure handling CVE-2023-52520 — kernel: platform/x86: think-lmi: Fix reference leak CVE-2023-52528 — kernel: net: usb: smsc75xx: Fix uninit-value access in __smsc75xx_read_reg CVE-2023-52565 — kernel: media: uvcvideo: out-of-bounds read in uvc_query_v4l2_menu() CVE-2023-52578 — kernel: net: bridge: data races indata-races in br_handle_frame_finish() CVE-2023-52594 — kernel: wifi: ath9k: Fix potential array-index-out-of-bounds read in ath9k_htc_txstatus() CVE-2023-52595 — kernel: wifi: rt2x00: restart beacon queue when hardware reset CVE-2023-52610 — kernel: net/sched: act_ct: fix skb leak and crash on ooo frags CVE-2024-0340 — kernel: Information disclosure in vhost/vhost.c:vhost_new_msg() CVE-2024-23307 — kernel: Integer Overflow in raid5_cache_count CVE-2024-25744 — kernel: untrusted VMM can trigger int80 syscall handling CVE-2024-26593 — kernel: i2c: i801: Fix block process call transactions CVE-2024-26603 — kernel: x86/fpu: Stop relying on userspace for info to fault in xsave buffer that cause loop forever CVE-2024-26610 — kernel: wifi: iwlwifi: fix a memory corruption CVE-2024-26615 — kernel: net/smc: fix illegal rmb_desc access in SMC-D connection dump CVE-2024-26642 — kernel: netfilter: nf_tables: disallow anonymous set with timeout flag CVE-2024-26643 — kernel: netfilter: nf_tables: mark set as dead when unbinding anonymous set with timeout CVE-2024-26659 — kernel: xhci: handle isoc Babble and Buffer Overrun events properly CVE-2024-26664 — kernel: hwmon: (coretemp) Fix out-of-bounds memory access CVE-2024-26693 — kernel: wifi: iwlwifi: mvm: fix a crash when we run out of stations CVE-2024-26694 — kernel: wifi: iwlwifi: fix double-free bug CVE-2024-26743 — kernel: RDMA/qedr: Fix qedr_create_user_qp error flow CVE-2024-26744 — kernel: RDMA/srpt: Support specifying the srpt_service_guid parameter CVE-2024-26779 — kernel: wifi: mac80211: fix race condition on enabling fast-xmit CVE-2024-26872 — kernel: RDMA/srpt: Do not register event handler until srpt device is fully setup CVE-2024-26892 — kernel: wifi: mt76: mt7921e: fix use-after-free in free_irq() CVE-2024-26897 — kernel: wifi: ath9k: delay all of ath9k_wmi_event_tasklet() until init is complete CVE-2024-26901 — kernel: do_sys_name_to_handle(): use kzalloc() to fix kernel-infoleak CVE-2024-26919 — kernel: usb: ulpi: Fix debugfs directory leak CVE-2024-26933 — kernel: USB: core: Fix deadlock in port "disable" sysfs attribute CVE-2024-26934 — kernel: USB: core: Fix deadlock in usb_deauthorize_interface() CVE-2024-26964 — kernel: usb: xhci: Add error handling in xhci_map_urb_for_dma CVE-2024-26973 — kernel: fat: fix uninitialized field in nostale filehandles CVE-2024-26993 — kernel: fs: sysfs: Fix reference leak in sysfs_break_active_protection() CVE-2024-27014 — kernel: net/mlx5e: Prevent deadlock while disabling aRFS CVE-2024-27048 — kernel: wifi: brcm80211: handle pmk_op allocation failure CVE-2024-27052 — kernel: wifi: rtl8xxxu: add cancel_work_sync() for c2hcmd_work CVE-2024-27056 — kernel: wifi: iwlwifi: mvm: ensure offloading TID queue exists CVE-2024-27059 — kernel: USB: usb-storage: Prevent divide-by-0 error in isd200_ata_command

🎯 Affected products32

  • Red Hat Enterprise Linux NFV (v. 8)
  • Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-0:4.18.0-553.5.1.rt7.346.el8_10.src as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-0:4.18.0-553.5.1.rt7.346.el8_10.src as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-core-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-core-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-debug-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debug-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-debug-core-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debug-core-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-debug-debuginfo-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debug-debuginfo-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-debug-devel-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debug-devel-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-debug-kvm-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debug-modules-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debug-modules-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-debug-modules-extra-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debug-modules-extra-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-debuginfo-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debuginfo-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-debuginfo-common-x86_64-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debuginfo-common-x86_64-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-devel-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-devel-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-kvm-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-modules-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-modules-0:4.18.0-553.5.1.rt7.346.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • +2 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this issue, prevent module uio from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: No mitigation is currently available for this vulnerability. Make sure to perform the updates as they become available. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, prevent the Conntrack module from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically. Workaround: This vulnerability can be mitigated by disabling 32-bit emulation by default for TDX and SEV. The user can override it with the ia32_emulation=y command line option. Workaround: To mitigate this issue, prevent module i2c-i801 from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, prevent the iwlwifi module from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: There is no known mitigation to this problem. Red Hat recommends updating to the latest kernel version to fix the problem.

🔗 References (56)