Red Hat Security Advisory: kernel security update
🔗 CVE IDs covered (21)
📋 Description
CVE-2023-52439 — kernel: uio: Fix use-after-free in uio_open CVE-2023-52884 — kernel: Input: cyapa - add missing input core locking to suspend/resume functions CVE-2024-26739 — kernel: net/sched: act_mirred: don't override retval if we already lost the skb CVE-2024-26929 — kernel: scsi: qla2xxx: Fix double free of fcport CVE-2024-26930 — kernel: scsi: qla2xxx: Fix double free of the ha->vp_map pointer CVE-2024-26931 — kernel: scsi: qla2xxx: Fix command flush on cable pull CVE-2024-26947 — kernel: ARM: 9359/1: flush: check if the folio is reserved for no-mapping addresses CVE-2024-26991 — kernel: KVM: x86/mmu: x86: Don't overflow lpage_info when checking attributes CVE-2024-27022 — kernel: fork: defer linking file vma until vma is fully initialized CVE-2024-35895 — kernel: bpf, sockmap: Prevent lock inversion deadlock in map delete elem CVE-2024-36016 — kernel: tty: n_gsm: fix possible out-of-bounds in gsm0_receive() CVE-2024-36899 — kernel: gpiolib: cdev: Fix use after free in lineinfo_changed_notify CVE-2024-38562 — kernel: wifi: nl80211: Avoid address calculations via out of bounds array indexing CVE-2024-38570 — kernel: gfs2: Fix potential glock use-after-free on unmount CVE-2024-38573 — kernel: cppc_cpufreq: Fix possible null pointer dereference CVE-2024-38601 — kernel: ring-buffer: Fix a race between readers and resize checks CVE-2024-38615 — kernel: cpufreq: exit() callback is optional CVE-2024-40984 — kernel: ACPICA: Revert "ACPICA: avoid Info: mapping multiple BARs. Your kernel is fine." CVE-2024-41071 — kernel: wifi: mac80211: Avoid address calculations via out of bounds array indexing CVE-2024-42225 — kernel: wifi: mt76: replace skb_put with skb_put_zero CVE-2024-42246 — kernel: net, sunrpc: Remap EPERM in case of connection failure in xs_tcp_setup_socket
🎯 Affected products200
- Red Hat Enterprise Linux AppStream (v. 9)
- Red Hat Enterprise Linux BaseOS (v. 9)
- Red Hat Enterprise Linux CRB (v. 9)
- Red Hat Enterprise Linux NFV (v. 9)
- Red Hat Enterprise Linux RT (v. 9)
- bpftool-0:7.3.0-427.37.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- bpftool-0:7.3.0-427.37.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- bpftool-0:7.3.0-427.37.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- bpftool-0:7.3.0-427.37.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- bpftool-debuginfo-0:7.3.0-427.37.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- bpftool-debuginfo-0:7.3.0-427.37.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- bpftool-debuginfo-0:7.3.0-427.37.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux CRB (v. 9)
- bpftool-debuginfo-0:7.3.0-427.37.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- bpftool-debuginfo-0:7.3.0-427.37.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- bpftool-debuginfo-0:7.3.0-427.37.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux CRB (v. 9)
- bpftool-debuginfo-0:7.3.0-427.37.1.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
- bpftool-debuginfo-0:7.3.0-427.37.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- bpftool-debuginfo-0:7.3.0-427.37.1.el9_4.s390x as a component of Red Hat Enterprise Linux CRB (v. 9)
- bpftool-debuginfo-0:7.3.0-427.37.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- bpftool-debuginfo-0:7.3.0-427.37.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- bpftool-debuginfo-0:7.3.0-427.37.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux CRB (v. 9)
- bpftool-debuginfo-0:7.3.0-427.37.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 9)
- bpftool-debuginfo-0:7.3.0-427.37.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux RT (v. 9)
- kernel-0:5.14.0-427.37.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-0:5.14.0-427.37.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-0:5.14.0-427.37.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-0:5.14.0-427.37.1.el9_4.src as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-0:5.14.0-427.37.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-64k-0:5.14.0-427.37.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-64k-core-0:5.14.0-427.37.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- +170 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: To mitigate this issue, prevent module uio from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: There are no mitigations for the flaw. Please update your system for fixes. Workaround: To mitigate this issue, prevent module mt76 from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.
🔗 References (23)
- selfhttps://access.redhat.com/errata/RHSA-2024:6997
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265271
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2273270
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278167
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278245
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278248
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278250
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278252
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278318
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2281677
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2283894
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2284549
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293348
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293364
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293420
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293423
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293431
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293685
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297568
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2300448
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2301543
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_6997.json