RHSA-2025:3093HighCVSS 7.8

Red Hat Security Advisory: kpatch-patch-4_18_0-305_120_1, kpatch-patch-4_18_0-305_138_1, kpatch-patch-4_18_0-305_145_1, and kpatch-patch-4_18_0-305_150_1 security update

Published
March 20, 2025
Last Modified
September 12, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2023-52922 — kernel: can: bcm: Fix UAF in bcm_proc_show()

🎯 Affected products29

  • Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_120_1-0:1-9.el8_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_120_1-0:1-9.el8_4.src as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_120_1-0:1-9.el8_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_120_1-debuginfo-0:1-9.el8_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_120_1-debuginfo-0:1-9.el8_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_120_1-debugsource-0:1-9.el8_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_120_1-debugsource-0:1-9.el8_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_138_1-0:1-5.el8_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_138_1-0:1-5.el8_4.src as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_138_1-0:1-5.el8_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_138_1-debuginfo-0:1-5.el8_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_138_1-debuginfo-0:1-5.el8_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_138_1-debugsource-0:1-5.el8_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_138_1-debugsource-0:1-5.el8_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_145_1-0:1-3.el8_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_145_1-0:1-3.el8_4.src as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_145_1-0:1-3.el8_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_145_1-debuginfo-0:1-3.el8_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_145_1-debuginfo-0:1-3.el8_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_145_1-debugsource-0:1-3.el8_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_145_1-debugsource-0:1-3.el8_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_150_1-0:1-1.el8_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_150_1-0:1-1.el8_4.src as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_150_1-0:1-1.el8_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_150_1-debuginfo-0:1-1.el8_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_150_1-debuginfo-0:1-1.el8_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_150_1-debugsource-0:1-1.el8_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)
  • kpatch-patch-4_18_0-305_150_1-debugsource-0:1-1.el8_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.8.4)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: To mitigate this vulnerability, prevent the `bcm` kernel module from loading by blacklisting it. Create a file named `/etc/modprobe.d/blacklist-bcm.conf` with the following content: ``` blacklist bcm ``` After creating the file, regenerate the initramfs and reboot the system for the changes to take effect. This mitigation may impact systems that rely on CAN BCM functionality. If CAN BCM is required, this mitigation is not suitable. A system reboot is required for the changes to take effect.

🔗 References (4)