RHSA-2024:5363HighCVSS 7.8

Red Hat Security Advisory: kernel security update

Published
August 15, 2024
Last Modified
June 28, 2026

🔗 CVE IDs covered (47)

📋 Description

CVE-2021-47606 — kernel: net: netlink: af_netlink: Prevent empty skb by adding a check on len. CVE-2023-52651 — kernel: wifi: ath10k: fix NULL pointer dereference in ath10k_wmi_tlv_op_pull_mgmt_tx_compl_ev() CVE-2023-52796 — kernel: ipvlan: add ipvlan_route_v6_outbound() helper CVE-2023-52864 — kernel: platform/x86: wmi: Fix opening of char device CVE-2024-21823 — kernel: dmaengine/idxd: hardware erratum allows potential security problem with direct access by untrusted application CVE-2024-26600 — kernel: phy: ti: phy-omap-usb2: Fix NULL pointer dereference for SRP CVE-2024-26808 — kernel: netfilter: nft_chain_filter: handle NETDEV_UNREGISTER for inet/ingress basechain CVE-2024-26828 — kernel: cifs: fix underflow in parse_server_interfaces() CVE-2024-26853 — kernel: igc: avoid returning frame twice in XDP_REDIRECT CVE-2024-26868 — kernel: nfs: fix panic when nfs4_ff_layout_prepare_ds() fails CVE-2024-26897 — kernel: wifi: ath9k: delay all of ath9k_wmi_event_tasklet() until init is complete CVE-2024-27049 — kernel: wifi: mt76: mt7925e: fix use-after-free in free_irq() CVE-2024-27052 — kernel: wifi: rtl8xxxu: add cancel_work_sync() for c2hcmd_work CVE-2024-27065 — kernel: netfilter: nf_tables: do not compare internal table flags on updates CVE-2024-27417 — kernel: ipv6: fix potential "struct net" leak in inet6_rtm_getaddr() CVE-2024-27434 — kernel: wifi: iwlwifi: mvm: don't set the MFP flag for the GTK CVE-2024-33621 — kernel: ipvlan: Dont Use skb->sk in ipvlan_process_v{4,6}_outbound CVE-2024-35789 — kernel: wifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes CVE-2024-35800 — kernel: efi: fix panic in kdump kernel CVE-2024-35823 — kernel: vt: fix unicode buffer corruption when deleting characters CVE-2024-35845 — kernel: wifi: iwlwifi: dbg-tlv: ensure NUL termination CVE-2024-35848 — kernel: eeprom: at24: fix memory corruption race condition CVE-2024-35852 — kernel: mlxsw: spectrum_acl_tcam: Fix memory leak when canceling rehash work CVE-2024-35899 — kernel: netfilter: nf_tables: flush pending destroy work before exit_net release CVE-2024-35911 — kernel: ice: fix memory corruption bug with suspend and rebuild CVE-2024-35937 — kernel: wifi: cfg80211: check A-MSDU format more carefully CVE-2024-35969 — kernel: ipv6: fix race condition between ipv6_get_ifaddr and ipv6_del_addr CVE-2024-36005 — kernel: netfilter: nf_tables: honor table dormant flag from netdev release event path CVE-2024-36017 — kernel: rtnetlink: Correct nested IFLA_VF_VLAN_LIST attribute validation CVE-2024-36020 — kernel: i40e: fix vf may be used uninitialized in this function warning CVE-2024-36489 — kernel: tls: fix missing memory barrier in tls_init CVE-2024-36903 — kernel: ipv6: Fix potential uninit-value access in __ip6_make_skb() CVE-2024-36921 — kernel: wifi: iwlwifi: mvm: guard against invalid STA ID on removal CVE-2024-36922 — kernel: wifi: iwlwifi: read txq->read_ptr under lock CVE-2024-36929 — kernel: net: core: reject skb_copy(_expand) for fraglist GSO skbs CVE-2024-36941 — kernel: wifi: nl80211: don't free NULL coalescing rule CVE-2024-36971 — kernel: net: kernel: UAF in network route management CVE-2024-37353 — kernel: virtio: delete vq in vp_find_vqs_msix() when request_irq() fails CVE-2024-37356 — kernel: tcp: Fix shift-out-of-bounds in dctcp_update_alpha(). CVE-2024-38391 — kernel: cxl/region: Fix cxlr_pmem leaks CVE-2024-38558 — kernel: net: openvswitch: fix overwriting ct original tuple for ICMPv6 CVE-2024-38575 — kernel: wifi: brcmfmac: pcie: handle randbuf allocation failure CVE-2024-39487 — kernel: bonding: Fix out-of-bounds read in bond_option_arp_ip_targets_set() CVE-2024-40928 — kernel: net: ethtool: fix the error condition in ethtool_get_phy_stats_ethtool() CVE-2024-40954 — kernel: net: do not leave a dangling sk pointer, when socket creation fails CVE-2024-40958 — kernel: netns: Make get_net_ns() handle zero refcount net CVE-2024-40961 — kernel: ipv6: prevent possible NULL deref in fib6_nh_init()

🔗 References (49)