Red Hat Security Advisory: kernel security, bug fix, and enhancement update
🔗 CVE IDs covered (161)
📋 Description
CVE-2019-13631 — kernel: OOB writes in parse_hid_report_descriptor in drivers/input/tablet/gtco.c CVE-2019-15505 — kernel: out of bounds read in drivers/media/usb/dvb-usb/technisat-usb2.c CVE-2020-25656 — kernel: use-after-free in read in vt_do_kdgkb_ioctl CVE-2021-3753 — kernel: a race out-of-bound read in vt CVE-2021-4204 — kernel: improper input validation may lead to privilege escalation CVE-2022-0500 — kernel: Linux ebpf logic vulnerability leads to critical memory read and write gaining root privileges CVE-2022-3565 — kernel: use-after-free in l1oip timer handlers CVE-2022-23222 — kernel: local privileges escalation in kernel/bpf/verifier.c CVE-2022-45934 — kernel: integer overflow in l2cap_config_req() in net/bluetooth/l2cap_core.c CVE-2022-48947 — kernel: Bluetooth: L2CAP: Fix u8 overflow CVE-2022-49081 — kernel: highmem: fix checks in _kmap_local_sched{in,out} CVE-2022-49700 — kernel: mm/slub: add missing TID updates on slab deactivation CVE-2022-49759 — kernel: VMCI: Use threaded irqs instead of tasklets CVE-2022-49885 — kernel: ACPI: APEI: Fix integer overflow in ghes_estatus_pool_init() CVE-2022-49940 — kernel: tty: n_gsm: add sanity check for gsm->receive in gsm_receive_buf() CVE-2022-50116 — kernel: tty: n_gsm: fix deadlock and link starvation in outgoing data path CVE-2022-50126 — kernel: jbd2: fix assertion 'jh->b_frozen_data == NULL' failure when journal aborted CVE-2022-50153 — kernel: usb: host: Fix refcount leak in ehci_hcd_ppc_of_probe CVE-2022-50274 — kernel: media: dvbdev: adopts refcnt to avoid UAF CVE-2022-50286 — kernel: ext4: fix delayed allocation bug in ext4_clu_mapped for bigalloc + inline CVE-2022-50327 — kernel: ACPI: processor: idle: Check acpi_fetch_acpi_dev() return value CVE-2022-50344 — kernel: ext4: fix null-ptr-deref in ext4_write_info CVE-2022-50346 — kernel: ext4: init quota for 'old.inode' in 'ext4_rename' CVE-2022-50403 — kernel: ext4: fix undefined behavior in bit shift for ext4_check_flag_values CVE-2022-50423 — kernel: Linux kernel: Information disclosure and denial of service via use-after-free in ACPI subsystem CVE-2022-50485 — kernel: ext4: add EXT4_IGET_BAD flag to prevent unexpected bad inode CVE-2022-50546 — kernel: ext4: fix uninititialized value in 'ext4_evict_inode' CVE-2022-50635 — kernel: powerpc/kprobes: Fix null pointer reference in arch_prepare_kprobe() CVE-2022-50638 — kernel: ext4: fix bug_on in __es_tree_search caused by bad boot loader inode CVE-2022-50668 — kernel: ext4: fix deadlock due to mbcache entry corruption CVE-2022-50717 — kernel: nvmet-tcp: add bounds check on Transfer Tag CVE-2022-50730 — kernel: ext4: silence the warning when evicting inode with dioread_nolock CVE-2022-50782 — kernel: ext4: fix bug_on in __es_tree_search caused by bad quota inode CVE-2023-1513 — kernel: KVM: information leak in KVM_GET_DEBUGREGS ioctl on 32-bit systems CVE-2023-3567 — kernel: use after free in vcs_read in drivers/tty/vt/vc_screen.c due to race CVE-2023-4133 — kernel: cxgb4: use-after-free in ch_flower_stats_cb() CVE-2023-4244 — kernel: Use-after-free in nft_verdict_dump due to a race between set GC and transaction CVE-2023-6121 — kernel: NVMe: info leak due to out-of-bounds read in nvmet_ctrl_find_get CVE-2023-6176 — kernel: local dos vulnerability in scatterwalk_copychunks CVE-2023-6622 — kernel: null pointer dereference vulnerability in nft_dynset_init() CVE-2023-6915 — kernel: Null Pointer Dereference vulnerability in ida_free in lib/idr.c CVE-2023-6932 — kernel: use-after-free in IPv4 IGMP CVE-2023-24023 — kernel: Bluetooth Forward and Future Secrecy Attacks and Defenses CVE-2023-25775 — kernel: irdma: Improper access control CVE-2023-28464 — Kernel: double free in hci_conn_cleanup of the bluetooth subsystem CVE-2023-31083 — kernel: race condition between HCIUARTSETPROTO and HCIUARTGETPROTO in hci_uart_tty_ioctl CVE-2023-37453 — kernel: usb: out-of-bounds read in read_descriptors CVE-2023-38409 — kernel: fbcon: out-of-sync arrays in fbcon_mode_deleted due to wrong con2fb_map assignment CVE-2023-39189 — kernel: netfilter: nftables out-of-bounds read in nf_osf_match_one() CVE-2023-39192 — kernel: netfilter: xtables out-of-bounds read in u32_match_it() CVE-2023-39193 — kernel: netfilter: xtables sctp out-of-bounds read in match_flags() CVE-2023-39194 — kernel: xfrm: out-of-bounds read in __xfrm_state_filter_match() CVE-2023-39198 — kernel: QXL: race condition leading to use-after-free in qxl_mode_dumb_create() CVE-2023-42754 — kernel: ipv4: NULL pointer dereference in ipv4_send_dest_unreach() CVE-2023-42755 — kernel: rsvp: out-of-bounds read in rsvp_classify() CVE-2023-45863 — kernel: lib/kobject.c vulnerable to fill_kobj_path out-of-bounds write CVE-2023-51779 — kernel: bluetooth: bt_sock_ioctl race condition leads to use-after-free in bt_sock_recvmsg CVE-2023-51780 — kernel: use-after-free in net/atm/ioctl.c CVE-2023-52340 — kernel: ICMPv6 “Packet Too Big” packets force a DoS of the Linux kernel by forcing 100% CPU CVE-2023-52434 — kernel: smb: client: fix potential OOBs in smb2_parse_contexts() CVE-2023-52448 — kernel: gfs2: Fix kernel NULL pointer dereference in gfs2_rgrp_dump CVE-2023-52489 — kernel: mm/sparsemem: fix race in accessing memory_section->usage CVE-2023-52574 — kernel: team: NULL pointer dereference when team device type is changed CVE-2023-52580 — kernel: net/core: kernel crash in ETH_P_1588 flow dissector CVE-2023-52581 — kernel: netfilter: nf_tables: memory leak when more than 255 elements expired CVE-2023-52597 — kernel: KVM: s390: fix setting of fpc register CVE-2023-52620 — kernel: netfilter: nf_tables: disallow timeout for anonymous sets CVE-2023-52973 — kernel: vc_screen: move load of struct vc_data pointer in vcs_read() to avoid UAF CVE-2023-53070 — kernel: ACPI: PPTT: Fix to avoid sleep in the atomic context when PPTT is absent CVE-2023-53072 — kernel: mptcp: use the workqueue to destroy unaccepted sockets CVE-2023-53088 — kernel: mptcp: fix UaF in listener shutdown CVE-2023-53089 — kernel: ext4: fix task hung in ext4_xattr_delete_inode CVE-2023-53103 — kernel: bonding: restore bond's IFF_SLAVE flag if a non-eth dev enslave fails CVE-2023-53134 — kernel: bnxt_en: Avoid order-5 memory allocation for TPA data CVE-2023-53140 — kernel: scsi: core: Remove the /proc/scsi/${proc_name} directory earlier CVE-2023-53148 — kernel: igb: Fix igb_down hung on surprise removal CVE-2023-53150 — kernel: scsi: qla2xxx: Pointer may be dereferenced CVE-2023-53151 — kernel: Linux kernel: md/raid10 soft lockup due to unlimited plugged bio CVE-2023-53182 — kernel: Linux kernel: ACPICA undefined behavior due to zero offset to null pointer CVE-2023-53202 — kernel: PM: domains: fix memory leak with using debugfs_lookup() CVE-2023-53205 — kernel: KVM: s390/diag: fix racy access of physical cpu number in diag 9c handler CVE-2023-53210 — kernel: md/raid5-cache: fix null-ptr-deref for r5l_flush_stripe_to_raid() CVE-2023-53224 — kernel: ext4: Fix function prototype mismatch for ext4_feat_ktype CVE-2023-53266 — kernel: arm64: acpi: Fix possible memory leak of ffh_ctxt CVE-2023-53275 — kernel: ALSA: hda: fix a possible null-pointer dereference due to data race in snd_hdac_regmap_sync() CVE-2023-53280 — kernel: scsi: qla2xxx: Remove unused nvme_ls_waitq wait queue CVE-2023-53322 — kernel: scsi: qla2xxx: Wait for io return on terminate rport CVE-2023-53335 — kernel: RDMA/cxgb4: Fix potential null-ptr-deref in pass_establish() CVE-2023-53343 — kernel: icmp6: Fix null-ptr-deref of ip6_null_entry->rt6i_idev in icmp6_dev() CVE-2023-53354 — kernel: skbuff: skb_segment, Call zero copy functions before using skbuff frags CVE-2023-53365 — kernel: ip6mr: Fix skb_under_panic in ip6mr_cache_report() CVE-2023-53371 — kernel: net/mlx5e: fix memory leak in mlx5e_fs_tt_redirect_any_create CVE-2023-53380 — kernel: md/raid10: fix null-ptr-deref of mreplace in raid10_sync_request CVE-2023-53392 — kernel: HID: intel-ish-hid: Fix kernel panic during warm reset CVE-2023-53441 — kernel: bpf: cpumap: Fix memory leak in cpu_map_update_elem CVE-2023-53442 — kernel: ice: Block switchdev mode when ADQ is active and vice versa CVE-2023-53451 — kernel: scsi: qla2xxx: Fix potential NULL pointer dereference CVE-2023-53476 — kernel: iw_cxgb4: Fix potential NULL dereference in c4iw_fill_res_cm_id_entry() CVE-2023-53483 — kernel: ACPI: processor: Check for null return of devm_kzalloc() in fch_misc_setup() CVE-2023-53496 — kernel: x86/platform/uv: Use alternate source for socket to node data CVE-2023-53501 — kernel: Linux kernel: Denial of Service due to race condition in IOMMU pasid unbinding CVE-2023-53525 — kernel: RDMA/cma: Allow UD qp_type to join multicast only CVE-2023-53530 — kernel: scsi: qla2xxx: Use raw_smp_processor_id() instead of smp_processor_id() CVE-2023-53546 — kernel: net/mlx5: DR, fix memory leak in mlx5dr_cmd_create_reformat_ctx CVE-2023-53550 — kernel: cpufreq: amd-pstate: fix global sysfs attribute type CVE-2023-53559 — kernel: ip_vti: fix potential slab-use-after-free in decode_session6 CVE-2023-53576 — kernel: null_blk: Always check queue mode setting from configfs CVE-2023-53577 — kernel: bpf, cpumap: Make sure kthread is running before map update returns CVE-2023-53581 — kernel: net/mlx5e: Check for NOT_READY flag state after locking CVE-2023-53586 — kernel: scsi: target: Fix multiple LUN_RESET handling CVE-2023-53611 — kernel: ipmi_si: fix a memleak in try_smi_init() CVE-2023-53615 — kernel: scsi: qla2xxx: Fix deletion race condition CVE-2023-53623 — kernel: mm/swap: fix swap_info_struct race between swapoff and get_swap_pages() CVE-2023-53648 — kernel: ALSA: ac97: Fix possible NULL dereference in snd_ac97_mixer CVE-2023-53657 — kernel: ice: Don't tx before switchdev is fully configured CVE-2023-53661 — kernel: bnxt: avoid overflow in bnxt_get_nvram_directory() CVE-2023-53696 — kernel: scsi: qla2xxx: Fix memory leak in qla2x00_probe_one() CVE-2023-53698 — kernel: xsk: fix refcount underflow in error path CVE-2023-53705 — kernel: ipv6: Fix out-of-bounds access in ipv6_find_tlv() CVE-2023-53722 — kernel: md: raid1: fix potential OOB in raid1_remove_disk() CVE-2023-53746 — kernel: s390/vfio-ap: fix memory leak in vfio_ap device driver CVE-2023-53761 — kernel: USB: usbtmc: Fix direction for 0-length ioctl control messages CVE-2023-53798 — kernel: ethtool: Fix uninitialized number of lanes CVE-2023-53821 — kernel: ip6_vti: fix slab-use-after-free in decode_session6 CVE-2023-53843 — kernel: net: openvswitch: reject negative ifindex CVE-2023-53848 — kernel: md/raid5-cache: fix a deadlock in r5l_exit_log() CVE-2023-53867 — kernel: ceph: fix potential use-after-free bug when trimming caps CVE-2023-53995 — kernel: Linux kernel: Denial of Service due to memory leak in IP address deletion CVE-2023-53996 — kernel: x86/sev: Make enc_dec_hypercall() accept a size instead of npages CVE-2023-53999 — kernel: Linux kernel: Denial of Service due to memory leak in mlx5e driver CVE-2023-54003 — kernel: Linux kernel: RDMA/core GID entry leak causes Denial of Service CVE-2023-54004 — kernel: Linux kernel UDPLITE: Denial of Service via null pointer dereference CVE-2023-54010 — kernel: Linux kernel: Denial of Service via null pointer dereference in ACPI CVE-2023-54014 — kernel: scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport() CVE-2023-54057 — kernel: iommu/amd: Add a length limitation for the ivrs_acpihid command-line parameter CVE-2023-54064 — kernel: Kernel: Memory leak in IPMI SSIF module leads to Denial of Service CVE-2023-54070 — kernel: Linux kernel igb driver: Denial of Service due to improper SR-IOV cleanup CVE-2023-54072 — kernel: Linux kernel: Denial of service or memory corruption due to a data race in ALSA PCM memory allocation CVE-2023-54090 — kernel: ixgbe: Fix panic during XDP_TX with > 64 CPUs CVE-2023-54096 — kernel: Linux kernel (soundwire): Memory corruption due to incorrect device enumeration completion CVE-2023-54100 — kernel: scsi: qedi: Fix use after free bug in qedi_remove() CVE-2023-54106 — kernel: Linux kernel: Denial of Service via memory leak in mlx5e_init_rep_rx CVE-2023-54148 — kernel: net/mlx5e: Move representor neigh cleanup to profile cleanup_tx CVE-2023-54166 — kernel: igc: Fix Kernel Panic during ndo_tx_timeout callback CVE-2023-54169 — kernel: net/mlx5e: fix memory leak in mlx5e_ptp_open CVE-2023-54179 — kernel: scsi: qla2xxx: Array index may go out of bound CVE-2023-54184 — kernel: scsi: target: iscsit: Free cmds before session free CVE-2023-54186 — kernel: usb: typec: altmodes/displayport: fix pin_assignment_show CVE-2023-54201 — kernel: RDMA/efa: Fix wrong resources deallocation order CVE-2023-54244 — kernel: ACPI: EC: Fix oops when removing custom query handlers CVE-2023-54274 — kernel: RDMA/srpt: Add a check for valid 'mad_agent' pointer CVE-2023-54289 — kernel: scsi: qedf: Fix NULL dereference in error handling CVE-2023-54320 — kernel: platform/x86/amd: pmc: Fix memory leak in amd_pmc_stb_debugfs_open_v2() CVE-2023-54324 — kernel: dm: fix a race condition in retrieve_deps CVE-2024-0841 — kernel: hugetlbfs: Null pointer dereference in hugetlbfs_fill_super function CVE-2024-25742 — hw: amd: Instruction raise #VC exception at exit CVE-2024-25743 — hw: amd: Instruction raise #VC exception at exit CVE-2024-26602 — kernel: sched/membarrier: reduce the ability to hammer on sys_membarrier CVE-2024-26609 — kernel: netfilter: nf_tables: reject QUEUE/DROP verdict parameters CVE-2024-26671 — kernel: blk-mq: fix IO hang from sbitmap wakeup race CVE-2024-26830 — kernel: i40e: Do not allow untrusted VF to remove administratively set MAC
🔗 References (58)
- selfhttps://access.redhat.com/errata/RHSA-2024:3138
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.10_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1731000
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1746732
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1888726
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1930388
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1999589
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2039178
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2043520
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2044578
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2150953
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2151959
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2177759
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2179892
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2213132
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2218332
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2219359
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221039
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221463
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221702
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2226777
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2226784
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2226787
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2226788
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2230042
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2231130
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2231410
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2235306
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2239845
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2239847
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2244720
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2250043
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2253632
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254961
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254982
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255283
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2256490
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2256822
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257682
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257979
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265285
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265653
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267695
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267750
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267760
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267761
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2269189
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2269217
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270836
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270883
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2272811
- externalhttps://issues.redhat.com/browse/RHEL-15148
- externalhttps://issues.redhat.com/browse/RHEL-15311
- externalhttps://issues.redhat.com/browse/RHEL-6030
- externalhttps://issues.redhat.com/browse/RHEL-7994
- externalhttps://issues.redhat.com/browse/RHEL-9128
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_3138.json