RHSA-2024:5067MediumCVSS 7.1

Red Hat Security Advisory: kernel-rt security update

Published
August 7, 2024
Last Modified
September 27, 2026

🔗 CVE IDs covered (22)

📋 Description

CVE-2022-48637 — kernel: bnxt: prevent skb UAF after handing over to PTP worker CVE-2023-52458 — kernel: block: null pointer dereference in ioctl.c when length and logical block size are misaligned CVE-2023-52635 — kernel: PM / devfreq: Synchronize devfreq_monitor_[start/stop] CVE-2023-52809 — kernel: scsi: libfc: Fix potential NULL pointer dereference in fc_lport_ptp_setup() CVE-2023-52885 — kernel: SUNRPC: Fix UAF in svc_tcp_listen_data_ready() CVE-2024-26601 — kernel: ext4: regenerate buddy after block freeing failed if under fc replay CVE-2024-26737 — kernel: bpf: Fix racing between bpf_timer_cancel_and_free and bpf_timer_cancel CVE-2024-26930 — kernel: scsi: qla2xxx: Fix double free of the ha->vp_map pointer CVE-2024-26947 — kernel: ARM: 9359/1: flush: check if the folio is reserved for no-mapping addresses CVE-2024-27030 — kernel: octeontx2-af: race condition on interupts CVE-2024-27062 — kernel: nouveau: lock the client object tree. CVE-2024-33621 — kernel: ipvlan: Dont Use skb->sk in ipvlan_process_v{4,6}_outbound CVE-2024-35823 — kernel: vt: fix unicode buffer corruption when deleting characters CVE-2024-35885 — kernel: mlxbf_gige: stop interface during shutdown CVE-2024-35896 — kernel: netfilter: validate user input for expected length CVE-2024-35962 — kernel: netfilter: complete validation of user input CVE-2024-36017 — kernel: rtnetlink: Correct nested IFLA_VF_VLAN_LIST attribute validation CVE-2024-36020 — kernel: i40e: fix vf may be used uninitialized in this function warning CVE-2024-36929 — kernel: net: core: reject skb_copy(_expand) for fraglist GSO skbs CVE-2024-36960 — kernel: drm/vmwgfx: Fix invalid reads in fence signaled events CVE-2024-38384 — kernel: blk-cgroup: fix list corruption from reorder of WRITE ->lqueued CVE-2024-38663 — kernel: blk-cgroup: fix list corruption from resetting io stat

🎯 Affected products36

  • Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-0:5.14.0-284.77.1.rt14.362.el9_2.src as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-0:5.14.0-284.77.1.rt14.362.el9_2.src as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-core-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-core-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debug-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debug-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debug-core-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debug-core-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debug-debuginfo-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debug-debuginfo-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debug-devel-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debug-devel-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debug-kvm-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debug-modules-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debug-modules-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debug-modules-core-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debug-modules-core-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debug-modules-extra-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debug-modules-extra-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debuginfo-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debuginfo-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-debuginfo-common-x86_64-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-debuginfo-common-x86_64-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-devel-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.2)
  • kernel-rt-devel-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • kernel-rt-kvm-0:5.14.0-284.77.1.rt14.362.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.2)
  • +6 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: No mitigation is currently available for this vulnerability. Make sure to perform the updates as they become available. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: The default Red Hat Enterprise Linux kernel prevents unprivileged users from being able to use eBPF by the kernel.unprivileged_bpf_disabled sysctl. This would require a privileged user with CAP_SYS_ADMIN or root to be able to abuse this flaw reducing its attack space. For the Red Hat Enterprise Linux 8 to confirm the current state, inspect the sysctl with the command: # cat /proc/sys/kernel/unprivileged_bpf_disabled The setting of 1 would mean that unprivileged users can not use eBPF, mitigating the flaw. Workaround: To mitigate this issue, prevent the i40e module from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to prevent it from loading automatically.

🔗 References (25)