Red Hat Security Advisory: kernel security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2023-52606 — kernel: powerpc/lib: Validate size for vector operations CVE-2023-54114 — kernel: Linux kernel: Denial of Service due to incorrect network packet processing in NSH module CVE-2024-26645 — kernel: tracing: Ensure visibility when inserting an element into tracing_map CVE-2024-26921 — kernel: inet: inet_defrag: prevent sk release while still in use CVE-2024-27042 — kernel: drm/amdgpu: Fix potential out-of-bounds access in 'amdgpu_discovery_reg_base_init()' CVE-2024-35930 — kernel: scsi: lpfc: Fix possible memory leak in lpfc_rcv_padisc() CVE-2024-36933 — kernel: nsh: Restore skb->{protocol,data,mac_header} for outer header in nsh_gso_segment().
🎯 Affected products200
- Red Hat CodeReady Linux Builder EUS (v.9.4)
- Red Hat Enterprise Linux AppStream EUS (v.9.4)
- Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- Red Hat Enterprise Linux Real Time EUS (v.9.4)
- Red Hat Enterprise Linux Real Time for NFV EUS (v.9.4)
- bpftool-0:7.3.0-427.72.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- bpftool-0:7.3.0-427.72.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- bpftool-0:7.3.0-427.72.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- bpftool-0:7.3.0-427.72.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.72.1.el9_4.aarch64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.72.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.72.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.72.1.el9_4.ppc64le as a component of Red Hat CodeReady Linux Builder EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.72.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.72.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.72.1.el9_4.s390x as a component of Red Hat CodeReady Linux Builder EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.72.1.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.72.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.72.1.el9_4.x86_64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.72.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.72.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.72.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.72.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.4)
- kernel-0:5.14.0-427.72.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- kernel-0:5.14.0-427.72.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- kernel-0:5.14.0-427.72.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- kernel-0:5.14.0-427.72.1.el9_4.src as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- kernel-0:5.14.0-427.72.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- kernel-64k-0:5.14.0-427.72.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- kernel-64k-core-0:5.14.0-427.72.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- +170 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2025:8796
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268293
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2271648
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2275928
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278447
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2281519
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2284488
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_8796.json