RHSA-2024:7000HighCVSS 7.8

Red Hat Security Advisory: kernel security update

Published
September 24, 2024
Last Modified
July 8, 2026

🔗 CVE IDs covered (151)

CVE-2021-46984CVE-2023-52840CVE-2024-27042 · pendingCVE-2024-41039CVE-2024-42322CVE-2021-47432CVE-2021-47527CVE-2022-48760CVE-2024-39471CVE-2024-41035CVE-2024-41044CVE-2024-41071 · pendingCVE-2024-41091CVE-2024-41013CVE-2023-52800CVE-2024-26595CVE-2021-47287CVE-2024-26880CVE-2024-42265CVE-2024-40988CVE-2024-42237CVE-2021-47582CVE-2023-52476CVE-2023-52683CVE-2024-26846CVE-2024-38570CVE-2024-42246CVE-2024-43830CVE-2024-38619CVE-2024-39501 · pendingCVE-2024-40929CVE-2024-41056CVE-2024-42124CVE-2021-47497CVE-2021-47338CVE-2021-47455CVE-2023-52522CVE-2024-23848CVE-2024-40901CVE-2024-42226 · pendingCVE-2023-52470CVE-2024-36901CVE-2024-40977CVE-2024-41076CVE-2024-26894CVE-2024-36939CVE-2024-38581CVE-2024-41041CVE-2024-42238CVE-2021-47393CVE-2024-39499CVE-2024-41008CVE-2024-41038CVE-2021-47385CVE-2021-47386CVE-2024-26923CVE-2024-35809CVE-2024-40954CVE-2024-40995CVE-2024-35884CVE-2024-36922CVE-2024-41090CVE-2024-42090CVE-2023-53847CVE-2024-35877CVE-2024-35989CVE-2024-36920CVE-2024-41023CVE-2024-41097CVE-2024-40997CVE-2021-47321CVE-2021-47412CVE-2022-48754CVE-2023-52605 · pendingCVE-2023-52798CVE-2024-26600CVE-2024-26645CVE-2021-47441CVE-2024-36919CVE-2024-38558CVE-2024-40931CVE-2024-40972CVE-2024-41040CVE-2021-47289CVE-2022-49226CVE-2024-26939CVE-2024-39506CVE-2024-40911CVE-2024-42084CVE-2024-42114CVE-2024-26665CVE-2024-36883CVE-2024-36902CVE-2024-40959CVE-2024-26720 · pendingCVE-2022-50072CVE-2024-26717CVE-2024-26855CVE-2024-40958CVE-2021-47466CVE-2021-47560CVE-2021-47383CVE-2021-47609CVE-2024-37356CVE-2021-47097CVE-2024-45026CVE-2024-40960CVE-2024-42131CVE-2024-35944CVE-2024-38579CVE-2024-40998CVE-2024-42096CVE-2024-36953CVE-2024-40978CVE-2024-40941CVE-2024-41060CVE-2024-43871CVE-2024-26769CVE-2022-48836CVE-2021-47101CVE-2024-42152CVE-2022-48619CVE-2021-47352CVE-2024-40904CVE-2024-42154CVE-2024-42240CVE-2023-6040CVE-2024-27013CVE-2024-41007CVE-2024-41064CVE-2024-41065CVE-2022-49316CVE-2023-52817CVE-2023-54269CVE-2024-26638CVE-2024-26649CVE-2024-42225CVE-2022-48866CVE-2024-38559CVE-2024-40912CVE-2024-41012CVE-2023-52478CVE-2023-52809CVE-2024-42094CVE-2024-42228CVE-2024-40989CVE-2024-41005CVE-2021-47384CVE-2022-48804CVE-2024-41014CVE-2024-41055

📋 Description

CVE-2021-46984 — kernel: kyber: fix out of bounds access when preempted CVE-2021-47097 — kernel: Input: elantech - fix stack out of bound access in elantech_change_report_id() CVE-2021-47101 — kernel: asix: fix uninit-value in asix_mdio_read() CVE-2021-47287 — kernel: driver core: auxiliary bus: Fix memory leak when driver_register() fail CVE-2021-47289 — kernel: ACPI: fix NULL pointer dereference CVE-2021-47321 — kernel: watchdog: Fix possible use-after-free by calling del_timer_sync() CVE-2021-47338 — kernel: fbmem: Do not delete the mode that is still in use CVE-2021-47352 — kernel: virtio-net: Add validation for used length CVE-2021-47383 — kernel: tty: Fix out-of-bound vmalloc access in imageblit CVE-2021-47384 — kernel: hwmon: (w83793) Fix NULL pointer dereference by removing unnecessary structure field CVE-2021-47385 — kernel: hwmon: (w83792d) Fix NULL pointer dereference by removing unnecessary structure field CVE-2021-47386 — kernel: hwmon: (w83791d) Fix NULL pointer dereference by removing unnecessary structure field CVE-2021-47393 — kernel: hwmon: (mlxreg-fan) Return non-zero value when fan current state is enforced from sysfs CVE-2021-47412 — kernel: block: don't call rq_qos_ops->done_bio if the bio isn't tracked CVE-2021-47432 — kernel: lib/generic-radix-tree.c: Don't overflow in peek() CVE-2021-47441 — kernel: mlxsw: thermal: Fix out-of-bounds memory accesses CVE-2021-47455 — kernel: ptp: Fix possible memory leak in ptp_clock_register() CVE-2021-47466 — kernel: mm, slub: fix potential memoryleak in kmem_cache_open() CVE-2021-47497 — kernel: nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells CVE-2021-47527 — kernel: serial: core: fix transmit-buffer reset and memleak CVE-2021-47560 — kernel: mlxsw: spectrum: Protect driver from buggy firmware CVE-2021-47582 — kernel: USB: core: Make do_proc_control() and do_proc_bulk() killable CVE-2021-47609 — kernel: firmware: arm_scpi: Fix string overflow in SCPI genpd driver CVE-2022-48619 — kernel: event code falling outside of a bitmap in input_set_capability() leads to panic CVE-2022-48754 — kernel: phylib: fix potential use-after-free CVE-2022-48760 — kernel: USB: core: Fix hang in usb_kill_urb by adding memory barriers CVE-2022-48804 — kernel: vt_ioctl: fix array_index_nospec in vt_setactivate CVE-2022-48836 — kernel: Input: aiptek - properly check endpoint type CVE-2022-48866 — kernel: HID: hid-thrustmaster: fix OOB read in thrustmaster_interrupts CVE-2022-49226 — kernel: net: asix: add proper error handling of usb read errors CVE-2022-49316 — kernel: NFSv4: Don't hold the layoutget locks across multiple RPC calls CVE-2022-50072 — kernel: NFSv4/pnfs: Fix a use-after-free bug in open CVE-2023-6040 — kernel: netfilter: nf_tables: out-of-bounds access in nf_tables_newtable() CVE-2023-52470 — kernel: null-ptr-deref in alloc_workqueue CVE-2023-52476 — kernel: perf/x86/lbr: Filter vsyscall addresses CVE-2023-52478 — kernel: HID: logitech-hidpp: Fix kernel crash on receiver USB disconnect CVE-2023-52522 — kernel: net: fix possible store tearing in neigh_periodic_work() CVE-2023-52605 — kernel: ACPI: extlog: fix NULL pointer dereference check CVE-2023-52683 — kernel: ACPI: LPIT: Avoid u32 multiplication overflow CVE-2023-52798 — kernel: wifi: ath11k: fix dfs radar event locking CVE-2023-52800 — kernel: wifi: ath11k: fix htt pktlog locking CVE-2023-52809 — kernel: scsi: libfc: Fix potential NULL pointer dereference in fc_lport_ptp_setup() CVE-2023-52817 — kernel: drm/amdgpu: Fix a null pointer access when the smc_rreg pointer is NULL CVE-2023-52840 — kernel: Input: synaptics-rmi4 - fix use after free in rmi_unregister_function() CVE-2023-53847 — kernel: usb-storage: alauda: Fix uninit-value in alauda_check_media() CVE-2023-54269 — kernel: SUNRPC: double free xprt_ctxt while still in use CVE-2024-23848 — kernel: use-after-free in cec_queue_msg_fh CVE-2024-26595 — kernel: mlxsw: spectrum_acl_tcam: Fix NULL pointer dereference in error path CVE-2024-26600 — kernel: phy: ti: phy-omap-usb2: Fix NULL pointer dereference for SRP CVE-2024-26638 — kernel: nbd: always initialize struct msghdr completely CVE-2024-26645 — kernel: tracing: Ensure visibility when inserting an element into tracing_map CVE-2024-26649 — kernel: null pointer when load rlc firmware CVE-2024-26665 — kernel: tunnels: fix out of bounds access when building IPv6 PMTU error CVE-2024-26717 — kernel: HID: i2c-hid-of: fix NULL-deref on failed power up CVE-2024-26720 — kernel: mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again CVE-2024-26769 — kernel: nvmet-fc: avoid deadlock on delete association path CVE-2024-26846 — kernel: nvme-fc: do not wait in vain when unloading module CVE-2024-26855 — kernel: net: ice: Fix potential NULL pointer dereference in ice_bridge_setlink() CVE-2024-26880 — kernel: dm: call the resume method on internal suspend CVE-2024-26894 — kernel: ACPI: processor_idle: Fix memory leak in acpi_processor_power_exit() CVE-2024-26923 — kernel: af_unix: Fix garbage collector racing against connect() CVE-2024-26939 — kernel: drm/i915/vma: Fix UAF on destroy against retire race CVE-2024-27013 — kernel: tun: limit printing rate when illegal packet received by tun dev CVE-2024-27042 — kernel: drm/amdgpu: Fix potential out-of-bounds access in 'amdgpu_discovery_reg_base_init()' CVE-2024-35809 — kernel: PCI/PM: Drain runtime-idle callbacks before driver removal CVE-2024-35877 — kernel: x86/mm/pat: fix VM_PAT handling in COW mappings CVE-2024-35884 — kernel: udp: do not accept non-tunnel GSO skbs landing in a tunnel CVE-2024-35944 — kernel: VMCI: Fix memcpy() run-time warning in dg_dispatch_as_host() CVE-2024-35989 — kernel: dmaengine: idxd: Fix oops during rmmod on single-CPU platforms CVE-2024-36883 — kernel: net: fix out-of-bounds access in ops_init CVE-2024-36901 — kernel: ipv6: prevent NULL dereference in ip6_output() CVE-2024-36902 — kernel: ipv6: fib6_rules: avoid possible NULL dereference in fib6_rule_action() CVE-2024-36919 — kernel: scsi: bnx2fc: Remove spin_lock_bh while releasing resources after upload CVE-2024-36920 — kernel: scsi: mpi3mr: Avoid memcpy field-spanning write WARNING CVE-2024-36922 — kernel: wifi: iwlwifi: read txq->read_ptr under lock CVE-2024-36939 — kernel: nfs: Handle error of rpc_proc_register() in nfs_net_init(). CVE-2024-36953 — kernel: KVM: arm64: vgic-v2: Check for non-NULL vCPU in vgic_v2_parse_attr() CVE-2024-37356 — kernel: tcp: Fix shift-out-of-bounds in dctcp_update_alpha(). CVE-2024-38558 — kernel: net: openvswitch: fix overwriting ct original tuple for ICMPv6 CVE-2024-38559 — kernel: scsi: qedf: Ensure the copied buf is NUL terminated CVE-2024-38570 — kernel: gfs2: Fix potential glock use-after-free on unmount CVE-2024-38579 — kernel: crypto: bcm - Fix pointer arithmetic CVE-2024-38581 — kernel: drm/amdgpu/mes: fix use-after-free issue CVE-2024-38619 — kernel: usb-storage: alauda: Check whether the media is initialized CVE-2024-39471 — kernel: drm/amdgpu: add error handle to avoid out-of-bounds CVE-2024-39499 — kernel: vmci: prevent speculation leaks by sanitizing event in event_deliver() CVE-2024-39501 — kernel: drivers: core: synchronize really_probe() and dev_uevent() CVE-2024-39506 — kernel: liquidio: Adjust a NULL pointer handling path in lio_vf_rep_copy_packet CVE-2024-40901 — kernel: scsi: mpt3sas: Avoid test/set_bit() operating in non-allocated memory CVE-2024-40904 — kernel: USB: class: cdc-wdm: Fix CPU lockup caused by excessive log messages CVE-2024-40911 — kernel: wifi: cfg80211: Lock wiphy in cfg80211_get_station CVE-2024-40912 — kernel: wifi: mac80211: Fix deadlock in ieee80211_sta_ps_deliver_wakeup() CVE-2024-40929 — kernel: wifi: iwlwifi: mvm: check n_ssids before accessing the ssids CVE-2024-40931 — kernel: mptcp: ensure snd_una is properly initialized on connect CVE-2024-40941 — kernel: wifi: iwlwifi: mvm: don't read past the mfuart notifcation CVE-2024-40954 — kernel: net: do not leave a dangling sk pointer, when socket creation fails CVE-2024-40958 — kernel: netns: Make get_net_ns() handle zero refcount net CVE-2024-40959 — kernel: xfrm6: check ip6_dst_idev() return value in xfrm6_get_saddr() CVE-2024-40960 — kernel: ipv6: prevent possible NULL dereference in rt6_probe() CVE-2024-40972 — kernel: ext4: do not create EA inode under buffer lock CVE-2024-40977 — kernel: wifi: mt76: mt7921s: fix potential hung tasks during chip recovery CVE-2024-40978 — kernel: scsi: qedi: Fix crash while reading debugfs attribute CVE-2024-40988 — kernel: drm/radeon: fix UBSAN warning in kv_dpm.c CVE-2024-40989 — kernel: KVM: arm64: Disassociate vcpus from redistributor region on teardown CVE-2024-40995 — kernel: net/sched: act_api: fix possible infinite loop in tcf_idr_check_alloc() CVE-2024-40997 — kernel: cpufreq: amd-pstate: fix memory leak on CPU EPP exit CVE-2024-40998 — kernel: ext4: fix uninitialized ratelimit_state->lock access in __ext4_fill_super() CVE-2024-41005 — kernel: netpoll: Fix race condition in netpoll_owner_active CVE-2024-41007 — kernel: tcp: avoid too many retransmit packets CVE-2024-41008 — kernel: drm/amdgpu: change vm->task_info handling CVE-2024-41012 — kernel: filelock: Remove locks reliably when fcntl/close race is detected CVE-2024-41013 — kernel: xfs: don't walk off the end of a directory data block CVE-2024-41014 — kernel: xfs: add bounds checking to xlog_recover_process_data CVE-2024-41023 — kernel: sched/deadline: Fix task_struct reference leak CVE-2024-41035 — kernel: USB: core: Fix duplicate endpoint bug by clearing reserved bits in the descriptor CVE-2024-41038 — kernel: firmware: cs_dsp: Prevent buffer overrun when processing V2 alg headers CVE-2024-41039 — kernel: firmware: cs_dsp: Fix overflow checking of wmfw header CVE-2024-41040 — kernel: net/sched: Fix UAF when resolving a clash CVE-2024-41041 — kernel: udp: Set SOCK_RCU_FREE earlier in udp_lib_get_port() CVE-2024-41044 — kernel: ppp: reject claimed-as-LCP but actually malformed packets CVE-2024-41055 — kernel: mm: prevent derefencing NULL ptr in pfn_section_valid() CVE-2024-41056 — kernel: firmware: cs_dsp: Use strnlen() on name fields in V1 wmfw files CVE-2024-41060 — kernel: drm/radeon: check bo_va->bo is non-NULL before using it CVE-2024-41064 — kernel: powerpc/eeh: avoid possible crash when edev->pdev changes CVE-2024-41065 — kernel: powerpc/pseries: Whitelist dtl slub object for copying to userspace CVE-2024-41071 — kernel: wifi: mac80211: Avoid address calculations via out of bounds array indexing CVE-2024-41076 — kernel: NFSv4: Fix memory leak in nfs4_set_security_label CVE-2024-41090 — kernel: virtio-net: tap: mlx5_core short frame denial of service CVE-2024-41091 — kernel: virtio-net: tun: mlx5_core short frame denial of service CVE-2024-41097 — kernel: usb: atm: cxacru: fix endpoint checking in cxacru_bind() CVE-2024-42084 — kernel: ftruncate: pass a signed offset CVE-2024-42090 — kernel: pinctrl: fix deadlock in create_pinctrl() when handling -EPROBE_DEFER CVE-2024-42094 — kernel: net/iucv: Avoid explicit cpumask var allocation on stack CVE-2024-42096 — kernel: x86: stop playing stack games in profile_pc() CVE-2024-42114 — kernel: wifi: cfg80211: restrict NL80211_ATTR_TXQ_QUANTUM values CVE-2024-42124 — kernel: scsi: qedf: Make qedf_execute_tmf() non-preemptible CVE-2024-42131 — kernel: mm: avoid overflows in dirty throttling logic CVE-2024-42152 — kernel: nvmet: fix a possible leak when destroy a ctrl during qp establishment CVE-2024-42154 — kernel: tcp_metrics: validate source addr length CVE-2024-42225 — kernel: wifi: mt76: replace skb_put with skb_put_zero CVE-2024-42226 — kernel: usb: xhci: prevent potential failure in handle_tx_event() for Transfer events without TRB CVE-2024-42228 — kernel: drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc CVE-2024-42237 — kernel: firmware: cs_dsp: Validate payload length before processing block CVE-2024-42238 — kernel: firmware: cs_dsp: Return error if block header overflows file CVE-2024-42240 — kernel: x86/bhi: Avoid warning in #DB handler due to BHI mitigation CVE-2024-42246 — kernel: net, sunrpc: Remap EPERM in case of connection failure in xs_tcp_setup_socket CVE-2024-42265 — kernel: protect the fetch of ->fd[fd] in do_dup2() from mispredictions CVE-2024-42322 — kernel: ipvs: properly dereference pe in ip_vs_add_service CVE-2024-43830 — kernel: leds: trigger: Unregister sysfs attributes before calling deactivate() CVE-2024-43871 — kernel: devres: Fix memory leakage caused by driver API devm_free_percpu() CVE-2024-45026 — kernel: s390/dasd: fix error recovery leading to data corruption on ESE devices

🔗 References (141)