MGASA-2024-0141 - Updated kernel, kmod-xtables-addons, kmod-virtualbox  packages fix security vulnerabilities

Publication date: 23 Apr 2024
URL: https://advisories.mageia.org/MGASA-2024-0141.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2024-26809,
     CVE-2024-26651,
     CVE-2023-7042,
     CVE-2024-22099,
     CVE-2023-6270,
     CVE-2024-24861,
     CVE-2024-26656,
     CVE-2024-26642,
     CVE-2024-26643,
     CVE-2023-47233,
     CVE-2024-26654,
     CVE-2024-23307,
     CVE-2024-26921,
     CVE-2024-26817,
     CVE-2024-24858,
     CVE-2024-24857

Upstream kernel version 6.6.28 fix bugs and vulnerabilities.
The kmod-virtualbox and kmod-xtables-addons packages have been updated
to work with this new kernel.
dwarves is a new requirement to build the kernel.
For information about the vulnerabilities see the links.

References:
- https://bugs.mageia.org/show_bug.cgi?id=33107
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.23
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.24
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.25
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.26
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.27
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.28
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26809
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26651
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-7042
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-22099
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6270
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24861
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26656
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26642
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26643
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-47233
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26654
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-23307
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26921
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26817
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24858
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24857

SRPMS:
- 9/core/kernel-6.6.28-1.mga9
- 9/core/kmod-xtables-addons-3.24-57.mga9
- 9/core/kmod-virtualbox-7.0.14-47.mga9
- 9/core/dwarves-1.26-2.mga9

Mageia 2024-0141: kernel, kmod-xtables-addons, kmod-virtualbox Security Advisory Updates

Upstream kernel version 6.6.28 fix bugs and vulnerabilities

Summary

Upstream kernel version 6.6.28 fix bugs and vulnerabilities. The kmod-virtualbox and kmod-xtables-addons packages have been updated to work with this new kernel. dwarves is a new requirement to build the kernel. For information about the vulnerabilities see the links.

References

- https://bugs.mageia.org/show_bug.cgi?id=33107

- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.23

- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.24

- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.25

- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.26

- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.27

- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.28

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26809

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26651

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-7042

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-22099

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6270

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24861

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26656

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26642

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26643

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-47233

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26654

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-23307

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26921

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26817

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24858

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24857

Resolution

MGASA-2024-0141 - Updated kernel, kmod-xtables-addons, kmod-virtualbox packages fix security vulnerabilities

SRPMS

- 9/core/kernel-6.6.28-1.mga9

- 9/core/kmod-xtables-addons-3.24-57.mga9

- 9/core/kmod-virtualbox-7.0.14-47.mga9

- 9/core/dwarves-1.26-2.mga9

Severity
Publication date: 23 Apr 2024
URL: https://advisories.mageia.org/MGASA-2024-0141.html
Type: security
CVE: CVE-2024-26809, CVE-2024-26651, CVE-2023-7042, CVE-2024-22099, CVE-2023-6270, CVE-2024-24861, CVE-2024-26656, CVE-2024-26642, CVE-2024-26643, CVE-2023-47233, CVE-2024-26654, CVE-2024-23307, CVE-2024-26921, CVE-2024-26817, CVE-2024-24858, CVE-2024-24857

Related News