Red Hat Security Advisory: kernel security update
🔗 CVE IDs covered (45)
📋 Description
CVE-2022-48773 — kernel: xprtrdma: fix pointer derefs in error cases of rpcrdma_ep_create CVE-2022-48936 — kernel: gso: do not skip outer ip header in case of ipip and net_failover CVE-2022-50341 — kernel: cifs: fix oops during encryption CVE-2023-52492 — kernel: dmaengine: fix NULL pointer in channel unregistration function CVE-2023-53621 — kernel: memcontrol: ensure memcg acquired by id is properly set up CVE-2024-24857 — kernel: net/bluetooth: race condition in conn_info_{min,max}_age_set() CVE-2024-26851 — kernel: netfilter: nf_conntrack_h323: Add protection for bmp length out of range CVE-2024-26924 — kernel: netfilter: nft_set_pipapo: do not free live element CVE-2024-26976 — kernel: KVM: Always flush async #PF workqueue when vCPU is being destroyed CVE-2024-27017 — kernel: netfilter: nft_set_pipapo: walk over current view on netlink dump CVE-2024-27062 — kernel: nouveau: lock the client object tree. CVE-2024-35839 — kernel: netfilter: bridge: replace physindev with physinif in nf_bridge_info CVE-2024-35898 — kernel: netfilter: nf_tables: Fix potential data-race in __nft_flowtable_type_get() CVE-2024-35939 — kernel: dma-direct: Leak pages on dma_set_decrypted() failure CVE-2024-38540 — kernel: bnxt_re: avoid shift undefined behavior in bnxt_qplib_alloc_init_hwq CVE-2024-38541 — kernel: of: module: add buffer overflow check in of_modalias() CVE-2024-38586 — kernel: r8169: Fix possible ring buffer corruption on fragmented Tx packets. CVE-2024-38608 — kernel: net/mlx5e: Fix netif state handling CVE-2024-39503 — kernel: netfilter: ipset: Fix race between namespace cleanup and gc in the list:set type CVE-2024-40924 — kernel: drm/i915/dpt: Make DPT object unshrinkable CVE-2024-40961 — kernel: ipv6: prevent possible NULL deref in fib6_nh_init() CVE-2024-40983 — kernel: tipc: force a dst refcount before doing decryption CVE-2024-40984 — kernel: ACPICA: Revert "ACPICA: avoid Info: mapping multiple BARs. Your kernel is fine." CVE-2024-41009 — kernel: bpf: Fix overrunning reservations in ringbuf CVE-2024-41042 — kernel: netfilter: nf_tables: prefer nft_chain_validate CVE-2024-41066 — kernel: ibmvnic: Add tx check to prevent skb leak CVE-2024-41092 — kernel: drm/i915/gt: Fix potential UAF by revoke of fence registers CVE-2024-41093 — kernel: drm/amdgpu: avoid using null object of framebuffer CVE-2024-42070 — kernel: netfilter: nf_tables: fully validate NFT_DATA_VALUE on store to data registers CVE-2024-42079 — kernel: gfs2: Fix NULL pointer dereference in gfs2_log_flush CVE-2024-42244 — kernel: USB: serial: mos7840: fix crash on resume CVE-2024-42284 — kernel: tipc: Return non-zero value from tipc_udp_addr2str() on error CVE-2024-42292 — kernel: kobject_uevent: Fix OOB access within zap_modalias_env() CVE-2024-42301 — kernel: dev/parport: fix the array out-of-bounds risk CVE-2024-43854 — kernel: block: initialize integrity buffer to zero before writing it to media CVE-2024-43880 — kernel: mlxsw: spectrum_acl_erp: Fix object nesting warning CVE-2024-43889 — kernel: padata: Fix possible divide-by-0 panic in padata_mt_helper() CVE-2024-43892 — kernel: memcg: protect concurrent access to mem_cgroup_idr CVE-2024-44935 — kernel: sctp: Fix null-ptr-deref in reuseport_add_sock(). CVE-2024-44989 — kernel: bonding: fix xfrm real_dev null pointer dereference CVE-2024-44990 — kernel: bonding: fix null pointer deref in bond_ipsec_offload_ok CVE-2024-45018 — kernel: netfilter: flowtable: initialise extack before use CVE-2024-46679 — kernel: ethtool: check device is present when getting link settings CVE-2024-46826 — kernel: ELF: fix kernel.randomize_va_space double read CVE-2024-47668 — kernel: lib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc()
🔗 References (39)
- selfhttps://access.redhat.com/errata/RHSA-2024:8856
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2266247
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2269183
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2275750
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2277168
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278262
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278350
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278387
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2281284
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2281669
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2281817
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293356
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293402
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293458
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293459
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297475
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297508
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297545
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297567
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297568
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2298109
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2298412
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2300412
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2300442
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2300487
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2300488
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2300508
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2300517
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2305446
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2307862
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2307865
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2307892
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2309852
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2309853
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2311715
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2315178
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2317601
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8856.json