Red Hat Security Advisory: kernel security and bug fix update
🔗 CVE IDs covered (13)
📋 Description
CVE-2021-47013 — kernel: net:emac/emac-mac: Fix a use after free in emac_mac_tx_buf_send CVE-2022-50717 — kernel: nvmet-tcp: add bounds check on Transfer Tag CVE-2023-1118 — kernel: use-after-free in drivers/media/rc/ene_ir.c due to race condition CVE-2023-1998 — kernel: Spectre v2 SMT mitigations problem CVE-2023-6356 — kernel: NULL pointer dereference in nvmet_tcp_build_iovec CVE-2023-6535 — kernel: NULL pointer dereference in nvmet_tcp_execute_request CVE-2023-6536 — kernel: NULL pointer dereference in __nvmet_req_complete CVE-2023-52578 — kernel: net: bridge: data races indata-races in br_handle_frame_finish() CVE-2024-25742 — hw: amd: Instruction raise #VC exception at exit CVE-2024-25743 — hw: amd: Instruction raise #VC exception at exit CVE-2024-26586 — kernel: mlxsw: spectrum_acl_tcam: Fix stack corruption CVE-2024-26602 — kernel: sched/membarrier: reduce the ability to hammer on sys_membarrier CVE-2024-26642 — kernel: netfilter: nf_tables: disallow anonymous set with timeout flag
🎯 Affected products122
- Red Hat CodeReady Linux Builder EUS (v.8.8)
- Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- bpftool-0:4.18.0-477.58.1.el8_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- bpftool-0:4.18.0-477.58.1.el8_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- bpftool-0:4.18.0-477.58.1.el8_8.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- bpftool-0:4.18.0-477.58.1.el8_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- bpftool-debuginfo-0:4.18.0-477.58.1.el8_8.aarch64 as a component of Red Hat CodeReady Linux Builder EUS (v.8.8)
- bpftool-debuginfo-0:4.18.0-477.58.1.el8_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- bpftool-debuginfo-0:4.18.0-477.58.1.el8_8.ppc64le as a component of Red Hat CodeReady Linux Builder EUS (v.8.8)
- bpftool-debuginfo-0:4.18.0-477.58.1.el8_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- bpftool-debuginfo-0:4.18.0-477.58.1.el8_8.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- bpftool-debuginfo-0:4.18.0-477.58.1.el8_8.x86_64 as a component of Red Hat CodeReady Linux Builder EUS (v.8.8)
- bpftool-debuginfo-0:4.18.0-477.58.1.el8_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-0:4.18.0-477.58.1.el8_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-0:4.18.0-477.58.1.el8_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-0:4.18.0-477.58.1.el8_8.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-0:4.18.0-477.58.1.el8_8.src as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-0:4.18.0-477.58.1.el8_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-abi-stablelists-0:4.18.0-477.58.1.el8_8.noarch as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-core-0:4.18.0-477.58.1.el8_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-core-0:4.18.0-477.58.1.el8_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-core-0:4.18.0-477.58.1.el8_8.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-core-0:4.18.0-477.58.1.el8_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-debug-0:4.18.0-477.58.1.el8_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-debug-0:4.18.0-477.58.1.el8_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-debug-0:4.18.0-477.58.1.el8_8.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-debug-0:4.18.0-477.58.1.el8_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-debug-core-0:4.18.0-477.58.1.el8_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-debug-core-0:4.18.0-477.58.1.el8_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- kernel-debug-core-0:4.18.0-477.58.1.el8_8.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.8.8)
- +92 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: To mitigate this issue, prevent module ene_ir from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: This flaw can be mitigated by disabling Simultaneous Multithreading (SMT). For instructions on how to disable SMT in RHEL, please see https://access.redhat.com/solutions/rhel-smt. Workaround: To mitigate this issue, prevent module nvmet-tcp from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent the mlxsw_spectrum module from being loaded. Please see https://access.redhat.com/solutions/41278 for information on blacklisting a kernel module to prevent it from loading automatically.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2024:3810
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2174400
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2187257
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254052
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254053
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254054
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265645
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2266841
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267695
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267758
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270836
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270881
- externalhttps://issues.redhat.com/browse/RHEL-27235
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_3810.json