Red Hat Security Advisory: kernel-rt security update
🔗 CVE IDs covered (11)
📋 Description
CVE-2023-52522 — kernel: net: fix possible store tearing in neigh_periodic_work() CVE-2024-26640 — kernel: tcp: add sanity checks to rx zerocopy CVE-2024-26656 — kernel: drm/amdgpu: use-after-free vulnerability CVE-2024-26772 — kernel: ext4: avoid allocating blocks from corrupted group in ext4_mb_find_by_goal() CVE-2024-26870 — kernel: NFSv4.2: fix nfs4_listxattr kernel BUG at mm/usercopy.c:102 CVE-2024-26906 — kernel: x86/mm: Disallow vsyscall page read for copy_from_kernel_nofault() CVE-2024-31076 — kernel: genirq/cpuhotplug, x86/vector: Prevent vector leak during CPU offline CVE-2024-40931 — kernel: mptcp: ensure snd_una is properly initialized on connect CVE-2024-41039 — kernel: firmware: cs_dsp: Fix overflow checking of wmfw header CVE-2024-42271 — kernel: net/iucv: fix use after free in iucv_sock_close() CVE-2024-46858 — kernel: mptcp: pm: Fix uaf in __timer_delete_sync
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2024:9498
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267795
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270100
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2272692
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2273242
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2275635
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2275711
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293684
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297515
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2300408
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2315210
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_9498.json