Red Hat Security Advisory: kernel security and bug fix update
🔗 CVE IDs covered (8)
📋 Description
CVE-2021-47400 — kernel: net: hns3: do not allow call hns3_nic_net_open repeatedly CVE-2023-52626 — kernel: net/mlx5e: Fix operation precedence bug in port timestamping napi_poll context CVE-2023-52667 — kernel: net/mlx5e: fix a potential double-free in fs_any_create_groups CVE-2024-26801 — kernel: Bluetooth: Avoid potential use-after-free in hci_error_reset CVE-2024-26974 — kernel: crypto: qat - resolve race condition during AER recovery CVE-2024-27393 — kernel: xen-netfront: Add missing skb_mark_for_recycle CVE-2024-35870 — kernel: smb: client: fix UAF in smb2_reconnect_server() CVE-2024-35960 — kernel: net/mlx5: Properly link new fs rules into the tree
🎯 Affected products200
- Red Hat Enterprise Linux AppStream (v. 9)
- Red Hat Enterprise Linux BaseOS (v. 9)
- Red Hat Enterprise Linux CRB (v. 9)
- Red Hat Enterprise Linux NFV (v. 9)
- Red Hat Enterprise Linux RT (v. 9)
- bpftool-0:7.3.0-427.24.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- bpftool-0:7.3.0-427.24.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- bpftool-0:7.3.0-427.24.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- bpftool-0:7.3.0-427.24.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- bpftool-debuginfo-0:7.3.0-427.24.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- bpftool-debuginfo-0:7.3.0-427.24.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- bpftool-debuginfo-0:7.3.0-427.24.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux CRB (v. 9)
- bpftool-debuginfo-0:7.3.0-427.24.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- bpftool-debuginfo-0:7.3.0-427.24.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- bpftool-debuginfo-0:7.3.0-427.24.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux CRB (v. 9)
- bpftool-debuginfo-0:7.3.0-427.24.1.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
- bpftool-debuginfo-0:7.3.0-427.24.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- bpftool-debuginfo-0:7.3.0-427.24.1.el9_4.s390x as a component of Red Hat Enterprise Linux CRB (v. 9)
- bpftool-debuginfo-0:7.3.0-427.24.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- bpftool-debuginfo-0:7.3.0-427.24.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- bpftool-debuginfo-0:7.3.0-427.24.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux CRB (v. 9)
- bpftool-debuginfo-0:7.3.0-427.24.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 9)
- bpftool-debuginfo-0:7.3.0-427.24.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux RT (v. 9)
- kernel-0:5.14.0-427.24.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-0:5.14.0-427.24.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-0:5.14.0-427.24.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-0:5.14.0-427.24.1.el9_4.src as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-0:5.14.0-427.24.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-64k-0:5.14.0-427.24.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-64k-core-0:5.14.0-427.24.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- +170 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this issue, prevent module mlx5_core from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent module cifs from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2024:4349
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2271680
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2273429
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278354
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2280745
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2281350
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2281740
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2281920
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2282336
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4349.json