RHSA-2024:4831HighCVSS 7.8

Red Hat Security Advisory: kernel-rt security update

Published
July 24, 2024
Last Modified
August 6, 2026

🔗 CVE IDs covered (46)

📋 Description

CVE-2021-47459 — kernel: can: j1939: j1939_netdev_start(): fix UAF for rx_kref of j1939_priv CVE-2022-36402 — kernel: vmwgfx: integer overflow in vmwgfx_execbuf.c CVE-2022-38457 — kernel: vmwgfx: use-after-free in vmw_cmd_res_check CVE-2022-40133 — kernel: vmwgfx: use-after-free in vmw_execbuf_tie_context CVE-2022-48743 — kernel: net: amd-xgbe: Fix skb data length underflow CVE-2023-5633 — kernel: vmwgfx: reference count issue leads to use-after-free in surface handling CVE-2023-33951 — kernel: vmwgfx: race condition leading to information disclosure vulnerability CVE-2023-33952 — kernel: vmwgfx: double free within the handling of vmw_buffer_object objects CVE-2023-52434 — kernel: smb: client: fix potential OOBs in smb2_parse_contexts() CVE-2023-52439 — kernel: uio: Fix use-after-free in uio_open CVE-2023-52450 — kernel: intel: Fix NULL pointer dereference issue in upi_fill_topology() CVE-2023-52518 — kernel: Bluetooth: hci_codec: Fix leaking content of local_codecs CVE-2023-52578 — kernel: net: bridge: data races indata-races in br_handle_frame_finish() CVE-2023-52707 — kernel: sched/psi: Fix use-after-free in ep_remove_wait_queue() CVE-2023-52811 — kernel: scsi: ibmvfc: Remove BUG_ON in the case of an empty event pool CVE-2024-1151 — kernel: stack overflow problem in Open vSwitch kernel module leading to DoS CVE-2024-26581 — kernel: nftables: nft_set_rbtree skip end interval element from gc CVE-2024-26668 — kernel: netfilter: nft_limit: reject configurations that cause integer overflow CVE-2024-26698 — kernel: hv_netvsc: Fix race condition between netvsc_probe and netvsc_remove CVE-2024-26704 — kernel: ext4: fix double-free of blocks due to wrong extents moved_len CVE-2024-26739 — kernel: net/sched: act_mirred: don't override retval if we already lost the skb CVE-2024-26773 — kernel: ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() CVE-2024-26808 — kernel: netfilter: nft_chain_filter: handle NETDEV_UNREGISTER for inet/ingress basechain CVE-2024-26810 — kernel: vfio/pci: Lock external INTx masking ops CVE-2024-26880 — kernel: dm: call the resume method on internal suspend CVE-2024-26923 — kernel: af_unix: Fix garbage collector racing against connect() CVE-2024-26925 — kernel: netfilter: nf_tables: release mutex after nft_gc_seq_end from abort path CVE-2024-26929 — kernel: scsi: qla2xxx: Fix double free of fcport CVE-2024-26931 — kernel: scsi: qla2xxx: Fix command flush on cable pull CVE-2024-26982 — kernel: Squashfs: check the inode number is not the invalid value of zero CVE-2024-27016 — kernel: netfilter: flowtable: validate pppoe header CVE-2024-27019 — kernel: netfilter: nf_tables: Fix potential data-race in __nft_obj_type_get() CVE-2024-27020 — kernel: netfilter: nf_tables: Fix potential data-race in __nft_expr_type_get() CVE-2024-27065 — kernel: netfilter: nf_tables: do not compare internal table flags on updates CVE-2024-27417 — kernel: ipv6: fix potential "struct net" leak in inet6_rtm_getaddr() CVE-2024-35791 — kernel: KVM: SVM: Flush pages under kvm->lock to fix UAF in svm_register_enc_region() CVE-2024-35897 — kernel: netfilter: nf_tables: discard table flag update with pending basechain deletion CVE-2024-35899 — kernel: netfilter: nf_tables: flush pending destroy work before exit_net release CVE-2024-35950 — kernel: drm/client: Fully protect modes[] with dev->mode_config.mutex CVE-2024-36025 — kernel: scsi: qla2xxx: Fix off by one in qla_edif_app_getstats() CVE-2024-36489 — kernel: tls: fix missing memory barrier in tls_init CVE-2024-36904 — kernel: tcp: Use refcount_inc_not_zero() in tcp_twsk_unique(). CVE-2024-36924 — kernel: scsi: lpfc: Release hbalock before calling lpfc_worker_wake_up() CVE-2024-36952 — kernel: scsi: lpfc: Move NPIV's transport unregistration to after resource clean up CVE-2024-36978 — kernel: net: sched: sch_multiq: fix possible OOB write in multiq_tune() CVE-2024-38596 — kernel: af_unix: Fix data races in unix_release_sock/unix_stream_sendmsg

🎯 Affected products36

  • Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-0:5.14.0-284.75.1.rt14.360.el9_2.src as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-0:5.14.0-284.75.1.rt14.360.el9_2.src as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-core-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-core-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debug-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debug-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debug-core-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debug-core-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debug-debuginfo-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debug-debuginfo-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debug-devel-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debug-devel-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debug-kvm-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debug-modules-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debug-modules-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debug-modules-core-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debug-modules-core-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debug-modules-extra-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debug-modules-extra-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debuginfo-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debuginfo-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debuginfo-common-x86_64-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debuginfo-common-x86_64-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-devel-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-devel-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-kvm-0:5.14.0-284.75.1.rt14.360.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • +6 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, it is possible to prevent the affected code from being loaded by blacklisting the vmwgfx kernel module. For instructions relating to blacklisting a kernel module, please see https://access.redhat.com/solutions/41278. Workaround: This flaw can be mitigated by turning off 3D acceleration in VMware (if possible) or preventing the affected `vmwgfx` kernel module from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278. Workaround: This flaw can be mitigated by preventing the affected `vmwgfx` kernel module from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278. Workaround: To mitigate this issue, prevent module cifs from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent module uio from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: No mitigation is currently available for this vulnerability. Make sure to perform the updates as they become available. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, prevent module openvswitch from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: 1. This flaw can be mitigated by preventing the affected netfilter (nf_tables) kernel module from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278. 2. If the module cannot be disabled, on non-containerized deployments of Red Hat Enterprise Linux, the mitigation is to disable user namespaces: ``` # echo "user.max_user_namespaces=0" > /etc/sysctl.d/userns.conf # sysctl -p /etc/sysctl.d/userns.conf ``` On containerized deployments such as Red Hat OpenShift Container Platform, do not use the second mitigation (disabling user namespaces) as the functionality is needed to be enabled. The first mitigation (blacklisting nf_tables) is still viable for containerized deployments, providing the environment is not using netfilter. Workaround: There are no known mitigations to this issue and updating to the latest Linux kernel version is recommended to address this vulnerability​. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, prevent module sch_multiq from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.

🔗 References (49)