RHSA-2024:4106HighCVSS 7.0

Red Hat Security Advisory: kernel-rt security update

Published
June 26, 2024
Last Modified
August 4, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2021-47400 — kernel: net: hns3: do not allow call hns3_nic_net_open repeatedly CVE-2024-27393 — kernel: xen-netfront: Add missing skb_mark_for_recycle CVE-2024-27397 — kernel: netfilter: nf_tables: use timestamp to check for set element timeout CVE-2024-27403 — kernel: netfilter: nft_flow_offload: reset dst in route object after setting up flow CVE-2024-35870 — kernel: smb: client: fix UAF in smb2_reconnect_server() CVE-2024-35958 — kernel: net: ena: Fix incorrect descriptor free behavior CVE-2024-35960 — kernel: net/mlx5: Properly link new fs rules into the tree CVE-2024-36957 — kernel: octeontx2-af: avoid off-by-one read from userspace

🎯 Affected products36

  • Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-0:5.14.0-284.71.1.rt14.356.el9_2.src as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-0:5.14.0-284.71.1.rt14.356.el9_2.src as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-core-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-core-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debug-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debug-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debug-core-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debug-core-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debug-debuginfo-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debug-debuginfo-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debug-devel-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debug-devel-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debug-kvm-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debug-modules-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debug-modules-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debug-modules-core-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debug-modules-core-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debug-modules-extra-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debug-modules-extra-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debuginfo-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debuginfo-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debuginfo-common-x86_64-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debuginfo-common-x86_64-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-devel-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-devel-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-kvm-0:5.14.0-284.71.1.rt14.356.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • +6 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: In order to trigger the issue, it requires the ability to create user/net namespaces. On non-containerized deployments of Red Hat Enterprise Linux 8, you can disable user namespaces by setting user.max_user_namespaces to 0: # echo "user.max_user_namespaces=0" > /etc/sysctl.d/userns.conf # sysctl -p /etc/sysctl.d/userns.conf On containerized deployments, such as Red Hat OpenShift Container Platform, do not use this mitigation as the functionality is needed to be enabled. Workaround: To mitigate this issue, prevent module cifs from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.

🔗 References (11)