Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 15 articles for you...
100

SUSE: 2025:0650-1 critical fix for Kernel RT media issue update

* bsc#1236783 Cross-References: * CVE-2024-53104 . # Security update for the Linux Kernel RT (Live Patch 5 for SLE 15 SP6) Announcement ID: SUSE-SU-2025:0650-1 Release Date: 2025-02-22T22:03:56Z Rating: important References: * bsc#1236783 Cross-References: * CVE-2024-53104 CVSS scores: * CVE-2024-53104 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53104 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53104 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.3 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Live Patching 15-SP3 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for the Linux Kernel 6.4.0-150600_10_17 fixes one issue. The following security issue was fixed: * CVE-2024-53104: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format (bsc#1236783). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2025-650=1 SUSE-SLE-Live- Patching-12-SP5-2025-649=1 SUSE-SLE-Live-Patching-12-SP5-2025-646=1 SUSE-SLE- Live-Patching-12-SP5-2025-647=1 SUSE-SLE-Live-Patching-12-SP5-2025-648=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-653=1 * SUSE Linux Enterprise Live Patching 15-SP3 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP3-2025-653=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2025-658=1 * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2025-658=1 * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2025-640=1 SUSE-SLE- Module-Live-Patching-15-SP6-2025-641=1 SUSE-SLE-Module-Live- Patching-15-SP6-2025-642=1 SUSE-SLE-Module-Live-Patching-15-SP6-2025-644=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_219-default-8-2.1 * kgraft-patch-4_12_14-122_222-default-6-2.1 * kgraft-patch-4_12_14-122_231-default-4-2.1 * kgraft-patch-4_12_14-122_225-default-5-2.1 * kgraft-patch-4_12_14-122_228-default-4-2.1 * openSUSE Leap 15.3 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP3_Update_49-debugsource-4-150300.2.1 * kernel-livepatch-5_3_18-150300_59_179-default-debuginfo-4-150300.2.1 * kernel-livepatch-5_3_18-150300_59_179-default-4-150300.2.1 * openSUSE Leap 15.3 (x86_64) * kernel-livepatch-5_3_18-150300_59_179-preempt-debuginfo-4-150300.2.1 * kernel-livepatch-5_3_18-150300_59_179-preempt-4-150300.2.1 * SUSE Linux Enterprise Live Patching 15-SP3 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP3_Update_49-debugsource-4-150300.2.1 * kernel-livepatch-5_3_18-150300_59_179-default-debuginfo-4-150300.2.1 * kernel-livepatch-5_3_18-150300_59_179-default-4-150300.2.1 * openSUSE Leap 15.5(ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_73-default-debuginfo-5-150500.2.1 * kernel-livepatch-5_14_21-150500_55_73-default-5-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_17-debugsource-5-150500.2.1 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_73-default-debuginfo-5-150500.2.1 * kernel-livepatch-5_14_21-150500_55_73-default-5-150500.2.1 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le x86_64) * kernel-livepatch-SLE15-SP5_Update_17-debugsource-5-150500.2.1 * SUSE Linux Enterprise Live Patching 15-SP6 (x86_64) * kernel-livepatch-SLE15-SP6-RT_Update_1-debugsource-9-150600.2.1 * kernel-livepatch-6_4_0-150600_10_5-rt-debuginfo-9-150600.2.1 * kernel-livepatch-6_4_0-150600_10_17-rt-3-150600.2.1 * kernel-livepatch-SLE15-SP6-RT_Update_2-debugsource-5-150600.2.1 * kernel-livepatch-6_4_0-150600_10_5-rt-9-150600.2.1 * kernel-livepatch-6_4_0-150600_10_14-rt-debuginfo-4-150600.2.1 * kernel-livepatch-SLE15-SP6-RT_Update_5-debugsource-3-150600.2.1 * kernel-livepatch-6_4_0-150600_10_17-rt-debuginfo-3-150600.2.1 * kernel-livepatch-6_4_0-150600_10_14-rt-4-150600.2.1 * kernel-livepatch-6_4_0-150600_10_8-rt-debuginfo-5-150600.2.1 * kernel-livepatch-SLE15-SP6-RT_Update_4-debugsource-4-150600.2.1 * kernel-livepatch-6_4_0-150600_10_8-rt-5-150600.2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-53104.html * https://bugzilla.suse.com/show_bug.cgi?id=1236783 . An essential software patch targeting a vulnerability in the Linux Kernel RT for SLE 15 SP6, enhancing overall system protection.. Kernel Security Update, SUSE Linux Patch, Media Issue Fix, Live Patching. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 24, 2025 Important SuSE
219

Rocky Linux 8 RLSA-2024:10944 moderate: kernel-rt security update

Moderate: kernel-rt security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:10944", "synopsis": "Moderate: kernel-rt security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for kernel-rt.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.\n\nSecurity Fix(es):\n\n* kernel: selinux,smack: don't bypass permissions check in inode_setsecctx hook (CVE-2024-46695)\n\n* kernel: net: avoid potential underflow in qdisc_pkt_len_init() with UFO (CVE-2024-49949)\n\n* kernel: blk-rq-qos: fix crash on rq_qos_wait vs. rq_qos_wake_function race (CVE-2024-50082)\n\n* kernel: arm64: probes: Remove broken LDR (literal) uprobe support (CVE-2024-50099)\n\n* kernel: xfrm: fix one more kernel-infoleak in algo dumping (CVE-2024-50110)\n\n* kernel: xfrm: validate new SA's prefixlen using SA family when sel.family is unset (CVE-2024-50142)\n\n* kernel: irqchip/gic-v4: Don't allow a VMOVP on a dying VPE (CVE-2024-50192)\n\n* kernel: netfilter: nf_reject_ipv6: fix potential crash in nf_send_reset6() (CVE-2024-50256)\n\n* kernel: vsock/virtio: Initialization of the dangling pointer occurring in vsk-> trans (CVE-2024-50264)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2312083", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2312083", "description": ""}, {"ticket": "2320505", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2320505", "description": ""}, {"ticket": "2322308", "sourceBy": "Red Hat","sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2322308", "description": ""}, {"ticket": "2323904", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2323904", "description": ""}, {"ticket": "2323930", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2323930", "description": ""}, {"ticket": "2324315", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2324315", "description": ""}, {"ticket": "2324612", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2324612", "description": ""}, {"ticket": "2324889", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2324889", "description": ""}, {"ticket": "2327168", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2327168", "description": ""}], "cves": [{"name": "CVE-2024-46695", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-46695", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-49949", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-49949", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-50082", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-50082", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-50099", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-50099", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-50110", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-50110", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-50142", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-50142", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN","cwe": "UNKNOWN"}, {"name": "CVE-2024-50192", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-50192", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-50256", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-50256", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-50264", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-50264", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-12-19T04:18:13.579534Z", "rpms": {"Rocky Linux 8": {"nvras": ["kernel-rt-0:4.18.0-553.32.1.rt7.373.el8_10.src.rpm", "kernel-rt-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64.rpm", "kernel-rt-core-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64.rpm", "kernel-rt-debug-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64.rpm", "kernel-rt-debug-core-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64.rpm", "kernel-rt-debug-debuginfo-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64.rpm", "kernel-rt-debug-devel-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64.rpm", "kernel-rt-debuginfo-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64.rpm", "kernel-rt-debuginfo-common-x86_64-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64.rpm", "kernel-rt-debug-kvm-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64.rpm", "kernel-rt-debug-modules-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64.rpm", "kernel-rt-debug-modules-extra-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64.rpm", "kernel-rt-devel-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64.rpm", "kernel-rt-kvm-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64.rpm", "kernel-rt-modules-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64.rpm", "kernel-rt-modules-extra-0:4.18.0-553.32.1.rt7.373.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important kernel-rt security patch for Rocky Linux 8 addresses multiple vulnerabilities. It's crucial to install these updates quickly to ensure system protection.. kernel-rt update, Rocky Linux security, kernel securitypatch. . LinuxSecurity.com Team

Calendar%202 Dec 19, 2024 Rocky Linux
219

Rocky Linux 8: RLSA-2024:8870 moderate: kernel-rt security fixes

Moderate: kernel-rt security update. {"type":"TYPE_SECURITY","shortCode":"RL","name":"RLSA-2024:8870","synopsis":"Moderate: kernel-rt security update","severity":"SEVERITY_MODERATE","topic":"An update is available for kernel-rt.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list","description":"The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.\n\nSecurity Fix(es):\n\n* kernel: net\/bluetooth: race condition in conn_info_{min,max}_age_set() (CVE-2024-24857)\n\n* kernel: dmaengine: fix NULL pointer in channel unregistration function (CVE-2023-52492)\n\n* kernel: netfilter: nf_conntrack_h323: Add protection for bmp length out of range (CVE-2024-26851)\n\n* kernel: netfilter: nft_set_pipapo: do not free live element (CVE-2024-26924)\n\n* kernel: netfilter: nft_set_pipapo: walk over current view on netlink dump (CVE-2024-27017)\n\n* kernel: KVM: Always flush async #PF workqueue when vCPU is being destroyed (CVE-2024-26976)\n\n* kernel: nouveau: lock the client object tree. (CVE-2024-27062)\n\n* kernel: netfilter: bridge: replace physindev with physinif in nf_bridge_info (CVE-2024-35839)\n\n* kernel: netfilter: nf_tables: Fix potential data-race in __nft_flowtable_type_get() (CVE-2024-35898)\n\n* kernel: dma-direct: Leak pages on dma_set_decrypted() failure (CVE-2024-35939)\n\n* kernel: net\/mlx5e: Fix netif state handling (CVE-2024-38608)\n\n* kernel: r8169: Fix possible ring buffer corruption on fragmented Tx packets. (CVE-2024-38586)\n\n* kernel: of: module: add buffer overflow check in of_modalias() (CVE-2024-38541)\n\n* kernel: bnxt_re: avoid shift undefined behavior in bnxt_qplib_alloc_init_hwq (CVE-2024-38540)\n\n* kernel: netfilter: ipset: Fix race between namespace cleanup and gc in the list:set type (CVE-2024-39503)\n\n* kernel: drm\/i915\/dpt: Make DPT object unshrinkable(CVE-2024-40924)\n\n* kernel: ipv6: prevent possible NULL deref in fib6_nh_init() (CVE-2024-40961)\n\n* kernel: tipc: force a dst refcount before doing decryption (CVE-2024-40983)\n\n* kernel: ACPICA: Revert "ACPICA: avoid Info: mapping multiple BARs. Your kernel is fine." (CVE-2024-40984)\n\n* kernel: xprtrdma: fix pointer derefs in error cases of rpcrdma_ep_create (CVE-2022-48773)\n\n* kernel: bpf: Fix overrunning reservations in ringbuf (CVE-2024-41009)\n\n* kernel: netfilter: nf_tables: prefer nft_chain_validate (CVE-2024-41042)\n\n* kernel: ibmvnic: Add tx check to prevent skb leak (CVE-2024-41066)\n\n* kernel: drm\/i915\/gt: Fix potential UAF by revoke of fence registers (CVE-2024-41092)\n\n* kernel: drm\/amdgpu: avoid using null object of framebuffer (CVE-2024-41093)\n\n* kernel: netfilter: nf_tables: fully validate NFT_DATA_VALUE on store to data registers (CVE-2024-42070)\n\n* kernel: gfs2: Fix NULL pointer dereference in gfs2_log_flush (CVE-2024-42079)\n\n* kernel: USB: serial: mos7840: fix crash on resume (CVE-2024-42244)\n\n* kernel: tipc: Return non-zero value from tipc_udp_addr2str() on error (CVE-2024-42284)\n\n* kernel: kobject_uevent: Fix OOB access within zap_modalias_env() (CVE-2024-42292)\n\n* kernel: dev\/parport: fix the array out-of-bounds risk (CVE-2024-42301)\n\n* kernel: block: initialize integrity buffer to zero before writing it to media (CVE-2024-43854)\n\n* kernel: mlxsw: spectrum_acl_erp: Fix object nesting warning (CVE-2024-43880)\n\n* kernel: gso: do not skip outer ip header in case of ipip and net_failover (CVE-2022-48936)\n\n* kernel: padata: Fix possible divide-by-0 panic in padata_mt_helper() (CVE-2024-43889)\n\n* kernel: memcg: protect concurrent access to mem_cgroup_idr (CVE-2024-43892)\n\n* kernel: sctp: Fix null-ptr-deref in reuseport_add_sock(). (CVE-2024-44935)\n\n* kernel: bonding: fix xfrm real_dev null pointer dereference (CVE-2024-44989)\n\n* kernel: bonding: fix null pointer deref in bond_ipsec_offload_ok (CVE-2024-44990)\n\n* kernel: netfilter: flowtable:initialise extack before use (CVE-2024-45018)\n\n* kernel: ELF: fix kernel.randomize_va_space double read (CVE-2024-46826)\n\n* kernel: lib\/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc() (CVE-2024-47668)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.","solution":null,"affectedProducts":["Rocky Linux 8"],"fixes":[{"ticket":"2266247","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2266247","description":""},{"ticket":"2269183","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2269183","description":""},{"ticket":"2275750","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2275750","description":""},{"ticket":"2277168","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2277168","description":""},{"ticket":"2278262","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2278262","description":""},{"ticket":"2278350","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2278350","description":""},{"ticket":"2278387","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2278387","description":""},{"ticket":"2281284","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2281284","description":""},{"ticket":"2281669","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2281669","description":""},{"ticket":"2281817","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2281817","description":""},{"ticket":"2293356","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2293356","description":""},{"ticket":"2293402","sourceBy":"RedHat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2293402","description":""},{"ticket":"2293458","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2293458","description":""},{"ticket":"2293459","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2293459","description":""},{"ticket":"2297475","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2297475","description":""},{"ticket":"2297508","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2297508","description":""},{"ticket":"2297545","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2297545","description":""},{"ticket":"2297567","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2297567","description":""},{"ticket":"2297568","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2297568","description":""},{"ticket":"2298109","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2298109","description":""},{"ticket":"2298412","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2298412","description":""},{"ticket":"2300412","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2300412","description":""},{"ticket":"2300442","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2300442","description":""},{"ticket":"2300487","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2300487","description":""},{"ticket":"2300488","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2300488","description":""},{"ticket":"2300508","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2300508","description":""},{"ticket":"2300517","sourceBy":"RedHat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2300517","description":""},{"ticket":"2307862","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2307862","description":""},{"ticket":"2307865","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2307865","description":""},{"ticket":"2307892","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2307892","description":""},{"ticket":"2309852","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2309852","description":""},{"ticket":"2309853","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2309853","description":""},{"ticket":"2311715","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2311715","description":""},{"ticket":"2315178","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2315178","description":""},{"ticket":"2317601","sourceBy":"RedHat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2317601","description":""}],"cves":[{"name":"CVE-2022-48773","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2022-48773","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2022-48936","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2022-48936","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2023-52492","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2023-52492","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-24857","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-24857","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-26851","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-26851","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-26924","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-26924","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-26976","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-26976","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-27017","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-27017","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-27062","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-27062","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-35839","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-35839","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-35898","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-35898","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-35939","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-35939","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-38540","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-38540","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-38541","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-38541","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-38586","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-38586","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-38608","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-38608","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-39503","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-39503","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-40924","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-40924","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-40961","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-40961","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-40983","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-40983","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-40984","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-40984","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-41009","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-41009","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-41042","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-41042","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-41066","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-41066","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-41092","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-41092","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-41093","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-41093","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-42070","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-42070","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-42079","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-42079","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-42244","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-42244","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-42284","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-42284","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-42292","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-42292","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-42301","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-42301","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-43854","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-43854","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-43880","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-43880","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-43889","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-43889","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-43892","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-43892","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-44935","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-44935","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-44989","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-44989","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-44990","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-44990","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-45018","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-45018","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-46826","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-46826","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-47668","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-47668","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"}],"references":[],"publishedAt":"2024-11-08T15:56:55.343367Z","rpms":{"Rocky Linux 8":{"nvras":["kernel-rt-0:4.18.0-553.27.1.rt7.368.el8_10.src.rpm","kernel-rt-0:4.18.0-553.27.1.rt7.368.el8_10.x86_64.rpm","kernel-rt-core-0:4.18.0-553.27.1.rt7.368.el8_10.x86_64.rpm","kernel-rt-debug-0:4.18.0-553.27.1.rt7.368.el8_10.x86_64.rpm","kernel-rt-debug-core-0:4.18.0-553.27.1.rt7.368.el8_10.x86_64.rpm","kernel-rt-debug-debuginfo-0:4.18.0-553.27.1.rt7.368.el8_10.x86_64.rpm","kernel-rt-debug-devel-0:4.18.0-553.27.1.rt7.368.el8_10.x86_64.rpm","kernel-rt-debuginfo-0:4.18.0-553.27.1.rt7.368.el8_10.x86_64.rpm","kernel-rt-debuginfo-common-x86_64-0:4.18.0-553.27.1.rt7.368.el8_10.x86_64.rpm","kernel-rt-debug-kvm-0:4.18.0-553.27.1.rt7.368.el8_10.x86_64.rpm","kernel-rt-debug-modules-0:4.18.0-553.27.1.rt7.368.el8_10.x86_64.rpm","kernel-rt-debug-modules-extra-0:4.18.0-553.27.1.rt7.368.el8_10.x86_64.rpm","kernel-rt-devel-0:4.18.0-553.27.1.rt7.368.el8_10.x86_64.rpm","kernel-rt-kvm-0:4.18.0-553.27.1.rt7.368.el8_10.x86_64.rpm","kernel-rt-modules-0:4.18.0-553.27.1.rt7.368.el8_10.x86_64.rpm","kernel-rt-modules-extra-0:4.18.0-553.27.1.rt7.368.el8_10.x86_64.rpm"]}},"rebootSuggested":false,"buildReferences":[]}. Routine security patch released for kernel-rt in Rocky Linux. Addresses several vulnerabilities, particularly race condition flaws.. kernel-rt security update, Rocky Linux vulnerabilities, security fixes, kernel updates. . LinuxSecurity.com Team

Calendar%202 Nov 08, 2024 Rocky Linux
219

Rocky Linux 8 RLSA-2023:3819 Moderate: Kernel-RT Security Update

Moderate: kernel-rt security and bug fix update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:3819", "synopsis": "Moderate: kernel-rt security and bug fix update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for kernel-rt.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.\n\nSecurity Fix(es):\n\n* kernel: tls: race condition in do_tls_getsockopt may lead to use-after-free or NULL pointer dereference (CVE-2023-28466)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nBug Fix(es):\n\n* kernel-rt: update RT source tree to the Rocky Linux-8.8.z1 source tree. (BZ#2210299)", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2179000", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2179000", "description": ""}], "cves": [{"name": "CVE-2023-28466", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-28466", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.0", "cwe": "CWE-416"}], "references": [], "publishedAt": "2023-08-31T16:54:43.486628Z", "rpms": {"Rocky Linux 8": {"nvras": ["kernel-rt-0:4.18.0-477.15.1.rt7.278.el8_8.src.rpm", "kernel-rt-0:4.18.0-477.15.1.rt7.278.el8_8.x86_64.rpm", "kernel-rt-core-0:4.18.0-477.15.1.rt7.278.el8_8.x86_64.rpm", "kernel-rt-debug-0:4.18.0-477.15.1.rt7.278.el8_8.x86_64.rpm", "kernel-rt-debug-core-0:4.18.0-477.15.1.rt7.278.el8_8.x86_64.rpm", "kernel-rt-debug-debuginfo-0:4.18.0-477.15.1.rt7.278.el8_8.x86_64.rpm", "kernel-rt-debug-devel-0:4.18.0-477.15.1.rt7.278.el8_8.x86_64.rpm","kernel-rt-debuginfo-0:4.18.0-477.15.1.rt7.278.el8_8.x86_64.rpm", "kernel-rt-debuginfo-common-x86_64-0:4.18.0-477.15.1.rt7.278.el8_8.x86_64.rpm", "kernel-rt-debug-kvm-0:4.18.0-477.15.1.rt7.278.el8_8.x86_64.rpm", "kernel-rt-debug-modules-0:4.18.0-477.15.1.rt7.278.el8_8.x86_64.rpm", "kernel-rt-debug-modules-extra-0:4.18.0-477.15.1.rt7.278.el8_8.x86_64.rpm", "kernel-rt-devel-0:4.18.0-477.15.1.rt7.278.el8_8.x86_64.rpm", "kernel-rt-kvm-0:4.18.0-477.15.1.rt7.278.el8_8.x86_64.rpm", "kernel-rt-modules-0:4.18.0-477.15.1.rt7.278.el8_8.x86_64.rpm", "kernel-rt-modules-extra-0:4.18.0-477.15.1.rt7.278.el8_8.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. The patch for kernel-rt security in Rocky Linux 8 resolves serious vulnerabilities and enhances overall system stability.. kernel-rt update, Rocky Linux security, performance fixes, bug updates. . LinuxSecurity.com Team

Calendar%202 Aug 31, 2023 Rocky Linux
98

Red Hat 8.4 RHSA-2023:4255-01 Important: Kernel-RT Privilege Escalation

An update for kernel-rt is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel-rt security and bug fix update Advisory ID: RHSA-2023:4255-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:4255 Issue date: 2023-07-25 CVE Names: CVE-2023-1281 CVE-2023-32233 ===================================================================== 1. Summary: An update for kernel-rt is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux NFV E4S (v.8.4) - x86_64 Red Hat Enterprise Linux NFV TUS (v.8.4) - x86_64 Red Hat Enterprise Linux RT TUS (v.8.4) - x86_64 3. Description: The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: tcindex: use-after-free vulnerability in traffic control index filter allows privilege escalation (CVE-2023-1281) * kernel: netfilter: use-after-free in nf_tables when processing batch requests can lead to privilege escalation (CVE-2023-32233) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and otherrelated information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * kernel-rt: update RT source tree to the latest RHEL-8.4z18 Batch (BZ#2209986) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2181847 - CVE-2023-1281 kernel: tcindex: use-after-free vulnerability in traffic control index filter allows privilege escalation 2196105 - CVE-2023-32233 kernel: netfilter: use-after-free in nf_tables when processing batch requests can lead to privilege escalation 6. Package List: Red Hat Enterprise Linux NFV E4S (v.8.4): Source: kernel-rt-4.18.0-305.97.1.rt7.172.el8_4.src.rpm x86_64: kernel-rt-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-core-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debug-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debug-core-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debug-debuginfo-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debug-devel-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debug-kvm-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debug-modules-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debug-modules-extra-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debuginfo-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debuginfo-common-x86_64-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-devel-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-kvm-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-modules-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-modules-extra-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm Red Hat Enterprise Linux NFV TUS(v.8.4): Source: kernel-rt-4.18.0-305.97.1.rt7.172.el8_4.src.rpm x86_64: kernel-rt-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-core-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debug-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debug-core-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debug-debuginfo-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debug-devel-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debug-kvm-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debug-modules-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debug-modules-extra-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debuginfo-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debuginfo-common-x86_64-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-devel-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-kvm-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-modules-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-modules-extra-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm Red Hat Enterprise Linux RT TUS (v.8.4): Source: kernel-rt-4.18.0-305.97.1.rt7.172.el8_4.src.rpm x86_64: kernel-rt-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-core-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debug-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debug-core-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debug-debuginfo-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debug-devel-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debug-modules-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debug-modules-extra-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debuginfo-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-debuginfo-common-x86_64-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-devel-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-modules-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm kernel-rt-modules-extra-4.18.0-305.97.1.rt7.172.el8_4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are availablefrom https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-1281 https://access.redhat.com/security/cve/CVE-2023-32233 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJkv4WTAAoJENzjgjWX9erE+9wP+wXbVrxPwbxBBjGpruRSsyN8 Lb0hMdTeOmdOcbMPrFsAlbVZemqM7WD5YEdLG2RY3ZFXb7COuqMLqXV3meUulE+y Rku0A5MUvcNw4xF/o4Uv9/iv119VK15dYoL4p8iZiErXje7qm6zqFlX2hyPtzx5d 3iPWMAP/9Dx7uVnVfFeK7GNsmRDd9kZrdelJaO0TWbBgZcNqSY68GrxMfb0q3GU0 LoG633JJf0QizXVNZKucA1NZIobpUv1/WIDIsXs8OAhI1jff25ePLi2WjdsD0agw 9lkUGew0y4JfSrM5Henap9UMSO7VweL8mNea1b2xVS5wUFLPj8RJR3IGv6E0Dtt+ KR0qWVujkOkO0Ji1uyhZfwlvSCxOrAIBDvf/wO9ATDjbE5Ly6sspbj9GiWFFsh3/ VyGRRvh6cnEET+qT4LvyqYfGiiTEU8I3mS/oRoBr5pX1p7XriO0xWQtvyXdltRip p+b/bwaaD3R4cY16PVJiYYP48S0N5FbCqMmgDlw7P0RSdfBHru6h6qSye493JXuu u+55hWCG7/0OPnV47/RoZgZnvnGowz0WqSFCBVE+kpNpyU3QR0/YaEkdu4Sis/V9 Ut8zOmjqBJDnpkvLde2dBP8sGjqcEj0IvQFT5if394ccER1WITbqs1cP+amm4Pc5 0OCuTyEFiR3HwglK1oMk =6M34 -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A significant revision for the kernel-rt in Red Hat Enterprise Linux 8.4 targets vulnerabilities related to privilege elevation and overall system robustness.. Kernel-RT Update, Red Hat Security, Enterprise Linux, System Stability, Privilege Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 25, 2023 Important Red Hat
98

Red Hat 9.0 Kernel-RT Update: RHSA-2023:4138 Critical Security Fix

An update for kernel-rt is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel-rt security and bug fix update Advisory ID: RHSA-2023:4138-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:4138 Issue date: 2023-07-18 CVE Names: CVE-2022-1016 CVE-2022-42703 CVE-2022-42896 CVE-2023-2002 CVE-2023-2124 CVE-2023-2235 ==================================================================== 1. Summary: An update for kernel-rt is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Real Time EUS (v.9.0) - x86_64 Red Hat Enterprise Linux Real Time for NFV EUS (v.9.0) - x86_64 3. Description: The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: use-after-free in l2cap_connect and l2cap_le_connect_req in net/bluetooth/l2cap_core.c (CVE-2022-42896) * kernel: use-after-free vulnerability in the perf_group_detach function of the Linux Kernel Performance Events (CVE-2023-2235) * kernel: uninitialized registers on stack in nft_do_chain can cause kernel pointer leakage to UM (CVE-2022-1016) * kernel: use-after-free related to leaf anon_vma double reuse (CVE-2022-42703) * Kernel: bluetooth: Unauthorizedmanagement command execution (CVE-2023-2002) * kernel: OOB access in the Linux kernel's XFS subsystem (CVE-2023-2124) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * kernel-rt: update RT source tree to the latest RHEL-9.0.z10 Batch (BZ#2209984) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2066614 - CVE-2022-1016 kernel: uninitialized registers on stack in nft_do_chain can cause kernel pointer leakage to UM 2133483 - CVE-2022-42703 kernel: use-after-free related to leaf anon_vma double reuse 2147364 - CVE-2022-42896 kernel: use-after-free in l2cap_connect and l2cap_le_connect_req in net/bluetooth/l2cap_core.c 2187308 - CVE-2023-2002 Kernel: bluetooth: Unauthorized management command execution 2187439 - CVE-2023-2124 kernel: OOB access in the Linux kernel's XFS subsystem 2192589 - CVE-2023-2235 kernel: use-after-free vulnerability in the perf_group_detach function of the Linux Kernel Performance Events 6. Package List: Red Hat Enterprise Linux Real Time for NFV EUS(v.9.0): Source: kernel-rt-5.14.0-70.64.1.rt21.135.el9_0.src.rpm x86_64: kernel-rt-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-core-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-debug-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-debug-core-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-debug-debuginfo-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-debug-devel-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-debug-kvm-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-debug-modules-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-debug-modules-extra-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-debuginfo-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-debuginfo-common-x86_64-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-devel-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-kvm-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-modules-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-modules-extra-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm Red Hat Enterprise Linux Real Time EUS (v.9.0): Source: kernel-rt-5.14.0-70.64.1.rt21.135.el9_0.src.rpm x86_64: kernel-rt-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-core-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-debug-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-debug-core-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-debug-debuginfo-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-debug-devel-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-debug-modules-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-debug-modules-extra-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-debuginfo-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-debuginfo-common-x86_64-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-devel-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-modules-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm kernel-rt-modules-extra-5.14.0-70.64.1.rt21.135.el9_0.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are availablefrom https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-1016 https://access.redhat.com/security/cve/CVE-2022-42703 https://access.redhat.com/security/cve/CVE-2022-42896 https://access.redhat.com/security/cve/CVE-2023-2002 https://access.redhat.com/security/cve/CVE-2023-2124 https://access.redhat.com/security/cve/CVE-2023-2235 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJktmwGAAoJENzjgjWX9erEkE0P/jfzPJ5Ii7eIYAmKXZQdTSEP FpJp7cvUx+L4/B6h9WaPXz/qJGbBnLpqGcXn2RgzWkyJXCwVbM/MQat32cCBoyLZ pz4h3kUonDj3QVS43ytHwg7RNT1TTvu6FYoBNtzTIRHTEIfn3jUuh980liO0O/cf 4jeNydlGB34mPtNaVgSRWFsPxvXjYJQORXS/0IQ2BZ9i1N6X7ifvOHLGTd8EbkBQ XMVLh67LDXf5RiPnMxYYNkzbzzGZkyTwjW+oNA45jJL2DxpE4au43VPQA+aelOpl TwWCxlMoGbOHy5ZTd6fSKmDU21kdXZEPg7gGv1IT8mhYMf5G6LAQ4+ZUjJFfGbSF hTsu6HY6rthOiZ/VS+PNeC6J3k+5sepaSMiy2Z6ZuJVzMYH0EJ8jKJBKi/xTOk29 Q72doQDUnOnczQKpSAfU7vC9F6De3sDFXOzCcGuy/1QWV7a2xTp1EKPy63LT9uLy bY2ZnOxGRSomao8YyVlMY/JxA3PyTE6/RP+XSAT7PmfqwkxPO77FmOmNQ1mkSLLw w3UNIBS1kAz9096b8TKedxFif1ZWjNQI53/zTlAPnlF7pZuixb3Gv8Gieu1XQPz3 0+fm59WS03bq+9M3tRA0zOaWEkqNF16ZoyLqZVqTStcQ/tz87EVXll2x4iapCKTa IDz+8UxDBDA1hw50cBcY =k9cm -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The kernel-rt upgrade for Red Hat Enterprise Linux 9.0 includes critical security patches and comprehensive details on resolved issues.. Kernel Security Update, Red Hat Advisory, Linux Kernel Fixes, Real Time Kernel. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 18, 2023 Important Red Hat
98

Red Hat Enterprise Linux 8 RHSA-2023-1584-01 Important Kernel-Rt Fix

An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel-rt security and bug fix update Advisory ID: RHSA-2023:1584-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:1584 Issue date: 2023-04-04 CVE Names: CVE-2022-4269 CVE-2022-4378 CVE-2023-0266 CVE-2023-0386 ==================================================================== 1. Summary: An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Real Time for NFV (v. 8) - x86_64 Red Hat Enterprise Linux for Real Time (v. 8) - x86_64 3. Description: The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: stack overflow in do_proc_dointvec and proc_skip_spaces (CVE-2022-4378) * ALSA: pcm: Move rwsem lock inside snd_ctl_elem_read to prevent UAF (CVE-2023-0266) * kernel: FUSE filesystem low-privileged user privileges escalation (CVE-2023-0386) * kernel: net: CPU soft lockup in TC mirred egress-to-ingress action (CVE-2022-4269) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to theCVE page(s) listed in the References section. Bug Fix(es): * Lazy irq_work does not raise softirq on PREEMPT_RT [rhel-8] (BZ#2172163) * The latest RHEL 8.7.z3 kernel changes need to be merged into the RT source tree to keep source parity between the two kernels. (BZ#2172278) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2150272 - CVE-2022-4269 kernel: net: CPU soft lockup in TC mirred egress-to-ingress action 2152548 - CVE-2022-4378 kernel: stack overflow in do_proc_dointvec and proc_skip_spaces 2159505 - CVE-2023-0386 kernel: FUSE filesystem low-privileged user privileges escalation 2163379 - CVE-2023-0266 ALSA: pcm: Move rwsem lock inside snd_ctl_elem_read to prevent UAF 6. Package List: Red Hat Enterprise Linux Real Time for NFV (v. 8): Source: kernel-rt-4.18.0-425.19.2.rt7.230.el8_7.src.rpm x86_64: kernel-rt-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-core-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-debug-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-debug-core-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-debug-debuginfo-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-debug-devel-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-debug-kvm-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-debug-modules-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-debug-modules-extra-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-debuginfo-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-debuginfo-common-x86_64-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-devel-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-kvm-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-modules-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-modules-extra-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm Red Hat Enterprise Linux for Real Time (v.8): Source: kernel-rt-4.18.0-425.19.2.rt7.230.el8_7.src.rpm x86_64: kernel-rt-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-core-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-debug-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-debug-core-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-debug-debuginfo-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-debug-devel-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-debug-modules-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-debug-modules-extra-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-debuginfo-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-debuginfo-common-x86_64-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-devel-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-modules-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm kernel-rt-modules-extra-4.18.0-425.19.2.rt7.230.el8_7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-4269 https://access.redhat.com/security/cve/CVE-2022-4378 https://access.redhat.com/security/cve/CVE-2023-0266 https://access.redhat.com/security/cve/CVE-2023-0386 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBZCvqnNzjgjWX9erEAQgO7xAAglvNvHFI3epmKU111EvmTKXC0pG+hx0X LQvI15YI6cOjzF8iJi0jeJjC5N+fayb5iytJixf0FCJSexfKNARRP+NGW/NDy68L iRFD1/3C3w96QbpPO3FWnC0fYKF+LroRMmE0e/Ynag3Zvi3wzAka8cXgtY1+ZIrV Y8pF48oUl9JTBFDtUw3O521RKN8fsr8+nM3eqyFSGSuirdqOTSElM+Tc8UOYqWUk JoBbmGY7Zgb0rmUfbHQxxjZFTlH90cLeRcDgnLByccnVTD751vFxPw87FkNnz6GT HwaPFTHyj4hB/9UTO425I7+InPIbQeP+qq9bpttZ+p11zo7j9sNDV0ia/k2WxCG6 P7ZRl+dzawq8ef6RMnL59zt1aslaB85qEY/x0g6IZ0zoCZuspuy1K/ENzS3M/BNL Dk/hsTu/roSW3J8DbAihcwnZ7KTbEZ7IoJB98H1N2B9qk3FlQUFMy6OFRsB2qm3V ZVmSYCTx0pZrvm+o1mLvVdEGOTyZZOgVPoAwSAfVCmXwQVX5xMsiG5BrIHKCi7+r 5bzhpeQ7TtYomXIAzZ1Kcqy0I10kjFcJGZlYJgKDSjk4RAGIYWnXcxTaWIgdlMRz Ow5LJf5PW+fybI5tiNyH2jrDbyhb8DptscAchjvKdHKUJNwt3BYWWBX/8gZhsDVH GDJkuc1r28A=WzR7 -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent kernel-rt upgrade resolves critical vulnerabilities in Red Hat Enterprise Linux 8, introducing a variety of improvements and corrections.. Kernel Rt Update, Red Hat Security Advisory, Real Time Linux Kernel. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 04, 2023 Important Red Hat
98

Red Hat: RHSA-2023:1220-01 Important Update for Kernel-RT

An update for kernel-rt is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel-rt security and bug fix update Advisory ID: RHSA-2023:1220-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:1220 Issue date: 2023-03-14 CVE Names: CVE-2022-3564 CVE-2022-4269 CVE-2022-4378 ==================================================================== 1. Summary: An update for kernel-rt is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Real Time EUS (v.8.4) - x86_64 Red Hat Enterprise Linux Real Time for NFV EUS (v.8.4) - x86_64 3. Description: The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: use-after-free caused by l2cap_reassemble_sdu() in net/bluetooth/l2cap_core.c (CVE-2022-3564) * kernel: stack overflow in do_proc_dointvec and proc_skip_spaces (CVE-2022-4378) * kernel: net: CPU soft lockup in TC mirred egress-to-ingress action (CVE-2022-4269) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * kernel-rt: update RT source tree to the RHEL-8.4.z15source tree. (BZ#2162415) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2150272 - CVE-2022-4269 kernel: net: CPU soft lockup in TC mirred egress-to-ingress action 2150999 - CVE-2022-3564 kernel: use-after-free caused by l2cap_reassemble_sdu() in net/bluetooth/l2cap_core.c 2152548 - CVE-2022-4378 kernel: stack overflow in do_proc_dointvec and proc_skip_spaces 6. Package List: Red Hat Enterprise Linux Real Time for NFV EUS (v.8.4): Source: kernel-rt-4.18.0-305.82.1.rt7.154.el8_4.src.rpm x86_64: kernel-rt-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-core-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-debug-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-debug-core-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-debug-debuginfo-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-debug-devel-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-debug-kvm-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-debug-modules-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-debug-modules-extra-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-debuginfo-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-debuginfo-common-x86_64-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-devel-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-kvm-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-modules-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-modules-extra-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm Red Hat Enterprise Linux Real Time EUS(v.8.4): Source: kernel-rt-4.18.0-305.82.1.rt7.154.el8_4.src.rpm x86_64: kernel-rt-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-core-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-debug-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-debug-core-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-debug-debuginfo-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-debug-devel-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-debug-modules-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-debug-modules-extra-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-debuginfo-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-debuginfo-common-x86_64-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-devel-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-modules-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm kernel-rt-modules-extra-4.18.0-305.82.1.rt7.154.el8_4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-3564 https://access.redhat.com/security/cve/CVE-2022-4269 https://access.redhat.com/security/cve/CVE-2022-4378 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBZBCPc9zjgjWX9erEAQhVyw/+NvNJ3IuRZTKxm06qw770U5gqGg9uRSqi vbyJmpoc/mqvE0wsVwHNdkZPhGRTnX1P8lsf65KwLvpLUP9b7K9UpiYKmR1iBd3R nwT2NHqLjIk3pNPdolHre7PNhvNbPj0zZlkXPH/UTkCl7+ZLbsQaJtOlsT2UBZ8h TeWOtBfCeJ6phqoH9Oe8HTol11MvSzvZ7rZKiTSRg1tjeCPzNDGH3U8MM+iNUqfK y3aS1lsZrvumM3sgdlu4Mv917BB4i2W3DgtHVgpd3BYcT/aHRkSIrr5oWXi89vfj ykjHhZGh/7bFYbcF+9hEaQ9MbYUHngJKEV/ElBxwo/HjdcwE8znePpmbHFF83t/7 sxUozRzh4QmJwnZrgzPa/nyKZlLf0rpRaEPR7ZPSTu7iyU69KhBC9KrQquDIx41a aCEDX3rQjskVQ6LIvTAuffH0hqNRNuq0h+cMqNT92ffVrHqr2O6ZFjdG+f5iXsPw 4xqlzE685jwxXi0qVsUceJFKssoHCmuOBTJtGa0FRcw11JymfNfTm8ZZ+QSBKnlp t7XiwYUwEf7AGgWLlf8ncLF8fED5nbc18N1UiBXTIVfD+6PwOCPCb8Y4jfM9ZqWH fi6RG7QlDG++8YeVCBJP3gjgHRETUzpeIADI3b66Em4/+do64kltE11NQ+Ju6AcG CtYbshT1kYU=R5q4 -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu's essential security notice outlines required upgrades for kernel-lt, tackling significant vulnerabilities and threats.. Red Hat Enterprise Linux, Linux kernel updates, Important kernel patches. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 14, 2023 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200