Red Hat Security Advisory: kernel security update
🔗 CVE IDs covered (42)
📋 Description
CVE-2022-50495 — kernel: x86/xen: Fix memory leak in xen_smp_intr_init{_pv}() CVE-2023-52771 — kernel: cxl/port: Fix delete_endpoint() vs parent unregistration race CVE-2023-52880 — kernel: tty: n_gsm: require CAP_NET_ADMIN to attach N_GSM0710 ldisc CVE-2024-26581 — kernel: nftables: nft_set_rbtree skip end interval element from gc CVE-2024-26668 — kernel: netfilter: nft_limit: reject configurations that cause integer overflow CVE-2024-26810 — kernel: vfio/pci: Lock external INTx masking ops CVE-2024-26855 — kernel: net: ice: Fix potential NULL pointer dereference in ice_bridge_setlink() CVE-2024-26908 — kernel: x86/xen: Add some null pointer checking to smp.c CVE-2024-26925 — kernel: netfilter: nf_tables: release mutex after nft_gc_seq_end from abort path CVE-2024-27016 — kernel: netfilter: flowtable: validate pppoe header CVE-2024-27019 — kernel: netfilter: nf_tables: Fix potential data-race in __nft_obj_type_get() CVE-2024-27020 — kernel: netfilter: nf_tables: Fix potential data-race in __nft_expr_type_get() CVE-2024-27415 — kernel: netfilter: bridge: confirm multicast packets before passing them up the stack CVE-2024-35839 — kernel: netfilter: bridge: replace physindev with physinif in nf_bridge_info CVE-2024-35896 — kernel: netfilter: validate user input for expected length CVE-2024-35897 — kernel: netfilter: nf_tables: discard table flag update with pending basechain deletion CVE-2024-35898 — kernel: netfilter: nf_tables: Fix potential data-race in __nft_flowtable_type_get() CVE-2024-35962 — kernel: netfilter: complete validation of user input CVE-2024-36003 — kernel: ice: fix LAG and VF lock dependency in ice_reset_vf() CVE-2024-36025 — kernel: scsi: qla2xxx: Fix off by one in qla_edif_app_getstats() CVE-2024-38538 — kernel: net: bridge: xmit: make sure we have at least eth header len bytes CVE-2024-38540 — kernel: bnxt_re: avoid shift undefined behavior in bnxt_qplib_alloc_init_hwq CVE-2024-38544 — kernel: RDMA/rxe: Fix seg fault in rxe_comp_queue_pkt CVE-2024-38579 — kernel: crypto: bcm - Fix pointer arithmetic CVE-2024-38608 — kernel: net/mlx5e: Fix netif state handling CVE-2024-39476 — kernel: md/raid5: fix deadlock that raid5d() wait for itself to clear MD_SB_CHANGE_PENDING CVE-2024-40905 — kernel: ipv6: fix possible race in __fib6_drop_pcpu_from() CVE-2024-40911 — kernel: wifi: cfg80211: Lock wiphy in cfg80211_get_station CVE-2024-40912 — kernel: wifi: mac80211: Fix deadlock in ieee80211_sta_ps_deliver_wakeup() CVE-2024-40914 — kernel: mm/huge_memory: don't unpoison huge_zero_folio CVE-2024-40929 — kernel: wifi: iwlwifi: mvm: check n_ssids before accessing the ssids CVE-2024-40939 — kernel: net: wwan: iosm: Fix tainted pointer delete is case of region creation fail CVE-2024-40941 — kernel: wifi: iwlwifi: mvm: don't read past the mfuart notifcation CVE-2024-40957 — kernel: seg6: fix parameter passing when calling NF_HOOK() in End.DX4 and End.DX6 behaviors CVE-2024-40978 — kernel: scsi: qedi: Fix crash while reading debugfs attribute CVE-2024-40983 — kernel: tipc: force a dst refcount before doing decryption CVE-2024-41041 — kernel: udp: Set SOCK_RCU_FREE earlier in udp_lib_get_port() CVE-2024-41076 — kernel: NFSv4: Fix memory leak in nfs4_set_security_label CVE-2024-41090 — kernel: virtio-net: tap: mlx5_core short frame denial of service CVE-2024-41091 — kernel: virtio-net: tun: mlx5_core short frame denial of service CVE-2024-42110 — kernel: net: ntb_netdev: Move ntb_netdev_rx_handler() to call netif_rx() from __netif_rx() CVE-2024-42152 — kernel: nvmet: fix a possible leak when destroy a ctrl during qp establishment
🎯 Affected products200
- Red Hat Enterprise Linux AppStream (v. 9)
- Red Hat Enterprise Linux BaseOS (v. 9)
- Red Hat Enterprise Linux CRB (v. 9)
- Red Hat Enterprise Linux NFV (v. 9)
- Red Hat Enterprise Linux RT (v. 9)
- bpftool-0:7.3.0-427.33.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- bpftool-0:7.3.0-427.33.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- bpftool-0:7.3.0-427.33.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- bpftool-0:7.3.0-427.33.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- bpftool-debuginfo-0:7.3.0-427.33.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- bpftool-debuginfo-0:7.3.0-427.33.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- bpftool-debuginfo-0:7.3.0-427.33.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux CRB (v. 9)
- bpftool-debuginfo-0:7.3.0-427.33.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- bpftool-debuginfo-0:7.3.0-427.33.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- bpftool-debuginfo-0:7.3.0-427.33.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux CRB (v. 9)
- bpftool-debuginfo-0:7.3.0-427.33.1.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
- bpftool-debuginfo-0:7.3.0-427.33.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- bpftool-debuginfo-0:7.3.0-427.33.1.el9_4.s390x as a component of Red Hat Enterprise Linux CRB (v. 9)
- bpftool-debuginfo-0:7.3.0-427.33.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- bpftool-debuginfo-0:7.3.0-427.33.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- bpftool-debuginfo-0:7.3.0-427.33.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux CRB (v. 9)
- bpftool-debuginfo-0:7.3.0-427.33.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 9)
- bpftool-debuginfo-0:7.3.0-427.33.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux RT (v. 9)
- kernel-0:5.14.0-427.33.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-0:5.14.0-427.33.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-0:5.14.0-427.33.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-0:5.14.0-427.33.1.el9_4.src as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-0:5.14.0-427.33.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-64k-0:5.14.0-427.33.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-64k-core-0:5.14.0-427.33.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- +170 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: 1. This flaw can be mitigated by preventing the affected netfilter (nf_tables) kernel module from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278. 2. If the module cannot be disabled, on non-containerized deployments of Red Hat Enterprise Linux, the mitigation is to disable user namespaces: ``` # echo "user.max_user_namespaces=0" > /etc/sysctl.d/userns.conf # sysctl -p /etc/sysctl.d/userns.conf ``` On containerized deployments such as Red Hat OpenShift Container Platform, do not use the second mitigation (disabling user namespaces) as the functionality is needed to be enabled. The first mitigation (blacklisting nf_tables) is still viable for containerized deployments, providing the environment is not using netfilter. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (44)
- selfhttps://access.redhat.com/errata/RHSA-2024:5928
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265185
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2272797
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2273654
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2275742
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2275744
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2277166
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278256
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278258
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278264
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2281101
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2281284
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2281669
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2281672
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2281675
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2281916
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2281958
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2282720
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2283468
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2284421
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293356
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293414
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293455
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293459
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293461
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2295914
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297489
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297495
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297496
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297498
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297513
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297523
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297525
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297541
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297562
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297567
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2299240
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2299336
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2300410
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2300453
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2301473
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2301519
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_5928.json