Red Hat Security Advisory: kernel security update
🔗 CVE IDs covered (12)
📋 Description
CVE-2021-47393 — kernel: hwmon: (mlxreg-fan) Return non-zero value when fan current state is enforced from sysfs CVE-2023-52486 — kernel: drm: Don't unref the same fb many times by mistake due to deadlock handling CVE-2024-26640 — kernel: tcp: add sanity checks to rx zerocopy CVE-2024-26810 — kernel: vfio/pci: Lock external INTx masking ops CVE-2024-26826 — kernel: mptcp: fix data re-injection from stale subflow CVE-2024-26870 — kernel: NFSv4.2: fix nfs4_listxattr kernel BUG at mm/usercopy.c:102 CVE-2024-26961 — kernel: mac802154: fix llsec key resources release in mac802154_llsec_key_del CVE-2024-33621 — kernel: ipvlan: Dont Use skb->sk in ipvlan_process_v{4,6}_outbound CVE-2024-35789 — kernel: wifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes CVE-2024-36000 — kernel: mm/hugetlb: fix missing hugetlb_lock for resv uncharge CVE-2024-36489 — kernel: tls: fix missing memory barrier in tls_init CVE-2024-38555 — kernel: net/mlx5: Discard command completions in internal error
🎯 Affected products149
- Red Hat Enterprise Linux BaseOS AUS (v.8.6)
- Red Hat Enterprise Linux BaseOS E4S (v.8.6)
- Red Hat Enterprise Linux BaseOS TUS (v.8.6)
- bpftool-0:4.18.0-372.115.1.el8_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.6)
- bpftool-0:4.18.0-372.115.1.el8_6.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.6)
- bpftool-0:4.18.0-372.115.1.el8_6.s390x as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.6)
- bpftool-0:4.18.0-372.115.1.el8_6.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
- bpftool-0:4.18.0-372.115.1.el8_6.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.6)
- bpftool-0:4.18.0-372.115.1.el8_6.x86_64 as a component of Red Hat Enterprise Linux BaseOS TUS (v.8.6)
- bpftool-debuginfo-0:4.18.0-372.115.1.el8_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.6)
- bpftool-debuginfo-0:4.18.0-372.115.1.el8_6.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.6)
- bpftool-debuginfo-0:4.18.0-372.115.1.el8_6.s390x as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.6)
- bpftool-debuginfo-0:4.18.0-372.115.1.el8_6.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
- bpftool-debuginfo-0:4.18.0-372.115.1.el8_6.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.6)
- bpftool-debuginfo-0:4.18.0-372.115.1.el8_6.x86_64 as a component of Red Hat Enterprise Linux BaseOS TUS (v.8.6)
- kernel-0:4.18.0-372.115.1.el8_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.6)
- kernel-0:4.18.0-372.115.1.el8_6.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.6)
- kernel-0:4.18.0-372.115.1.el8_6.s390x as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.6)
- kernel-0:4.18.0-372.115.1.el8_6.src as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
- kernel-0:4.18.0-372.115.1.el8_6.src as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.6)
- kernel-0:4.18.0-372.115.1.el8_6.src as a component of Red Hat Enterprise Linux BaseOS TUS (v.8.6)
- kernel-0:4.18.0-372.115.1.el8_6.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
- kernel-0:4.18.0-372.115.1.el8_6.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.6)
- kernel-0:4.18.0-372.115.1.el8_6.x86_64 as a component of Red Hat Enterprise Linux BaseOS TUS (v.8.6)
- kernel-abi-stablelists-0:4.18.0-372.115.1.el8_6.noarch as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
- kernel-abi-stablelists-0:4.18.0-372.115.1.el8_6.noarch as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.6)
- kernel-abi-stablelists-0:4.18.0-372.115.1.el8_6.noarch as a component of Red Hat Enterprise Linux BaseOS TUS (v.8.6)
- kernel-core-0:4.18.0-372.115.1.el8_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.6)
- kernel-core-0:4.18.0-372.115.1.el8_6.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.6)
- kernel-core-0:4.18.0-372.115.1.el8_6.s390x as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.6)
- +119 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2024:5065
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2269070
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270100
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2273654
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2275604
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2275711
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278176
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2281057
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2281968
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2282345
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293444
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293657
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293687
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_5065.json