Security
Headlines
HeadlinesLatestCVEs

Headline

Red Hat Security Advisory 2023-1841-01

Red Hat Security Advisory 2023-1841-01 - The kernel packages contain the Linux kernel, the core of any Linux operating system. Issues addressed include a use-after-free vulnerability.

Packet Storm
#vulnerability#windows#linux#red_hat#js

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================
Red Hat Security Advisory

Synopsis: Important: kernel security and bug fix update
Advisory ID: RHSA-2023:1841-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2023:1841
Issue date: 2023-04-18
CVE Names: CVE-2023-0461
====================================================================

  1. Summary:

An update for kernel is now available for Red Hat Enterprise Linux 8.6
Extended Update Support.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

  1. Relevant releases/architectures:

Red Hat CodeReady Linux Builder EUS (v.8.6) - aarch64, ppc64le, x86_64
Red Hat Enterprise Linux BaseOS EUS (v.8.6) - aarch64, noarch, ppc64le, s390x, x86_64

  1. Description:

The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security Fix(es):

  • kernel: net/ulp: use-after-free in listening ULP sockets (CVE-2023-0461)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Bug Fix(es):

  • xfs_buf deadlock between inode deletion and block allocation (aarch64)
    (BZ#2164266)

  • mlx5:CX6-DX: [IPsec crypto-offload, IPv6, TCP, Tunnel] tcp traffic is
    broken on IPsec crypto-offload over IPv6 (BZ#2165492)

  • Windows Server 2019 guest randomly pauses with “KVM: entry failed,
    hardware error 0x80000021” (BZ#2166369)

  • MSFT MANA NET Patch RHEL-8: Fix accessing freed irq affinity_hint
    (BZ#2175252)

  • Ethernet Port Configuration Tool (EPCT) not supported with in-tree ice
    driver (BZ#2176866)

  • Application Performance impact on cgroup v2 (BZ#2177793)

  • In FIPS mode, kernel does not transition into error state when RCT or APT
    health tests fail (BZ#2181732)

  1. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

The system must be rebooted for this update to take effect.

  1. Bugs fixed (https://bugzilla.redhat.com/):

2176192 - CVE-2023-0461 kernel: net/ulp: use-after-free in listening ULP sockets

  1. Package List:

Red Hat Enterprise Linux BaseOS EUS (v.8.6):

Source:
kernel-4.18.0-372.52.1.el8_6.src.rpm

aarch64:
bpftool-4.18.0-372.52.1.el8_6.aarch64.rpm
bpftool-debuginfo-4.18.0-372.52.1.el8_6.aarch64.rpm
kernel-4.18.0-372.52.1.el8_6.aarch64.rpm
kernel-core-4.18.0-372.52.1.el8_6.aarch64.rpm
kernel-cross-headers-4.18.0-372.52.1.el8_6.aarch64.rpm
kernel-debug-4.18.0-372.52.1.el8_6.aarch64.rpm
kernel-debug-core-4.18.0-372.52.1.el8_6.aarch64.rpm
kernel-debug-debuginfo-4.18.0-372.52.1.el8_6.aarch64.rpm
kernel-debug-devel-4.18.0-372.52.1.el8_6.aarch64.rpm
kernel-debug-modules-4.18.0-372.52.1.el8_6.aarch64.rpm
kernel-debug-modules-extra-4.18.0-372.52.1.el8_6.aarch64.rpm
kernel-debuginfo-4.18.0-372.52.1.el8_6.aarch64.rpm
kernel-debuginfo-common-aarch64-4.18.0-372.52.1.el8_6.aarch64.rpm
kernel-devel-4.18.0-372.52.1.el8_6.aarch64.rpm
kernel-headers-4.18.0-372.52.1.el8_6.aarch64.rpm
kernel-modules-4.18.0-372.52.1.el8_6.aarch64.rpm
kernel-modules-extra-4.18.0-372.52.1.el8_6.aarch64.rpm
kernel-tools-4.18.0-372.52.1.el8_6.aarch64.rpm
kernel-tools-debuginfo-4.18.0-372.52.1.el8_6.aarch64.rpm
kernel-tools-libs-4.18.0-372.52.1.el8_6.aarch64.rpm
perf-4.18.0-372.52.1.el8_6.aarch64.rpm
perf-debuginfo-4.18.0-372.52.1.el8_6.aarch64.rpm
python3-perf-4.18.0-372.52.1.el8_6.aarch64.rpm
python3-perf-debuginfo-4.18.0-372.52.1.el8_6.aarch64.rpm

noarch:
kernel-abi-stablelists-4.18.0-372.52.1.el8_6.noarch.rpm
kernel-doc-4.18.0-372.52.1.el8_6.noarch.rpm

ppc64le:
bpftool-4.18.0-372.52.1.el8_6.ppc64le.rpm
bpftool-debuginfo-4.18.0-372.52.1.el8_6.ppc64le.rpm
kernel-4.18.0-372.52.1.el8_6.ppc64le.rpm
kernel-core-4.18.0-372.52.1.el8_6.ppc64le.rpm
kernel-cross-headers-4.18.0-372.52.1.el8_6.ppc64le.rpm
kernel-debug-4.18.0-372.52.1.el8_6.ppc64le.rpm
kernel-debug-core-4.18.0-372.52.1.el8_6.ppc64le.rpm
kernel-debug-debuginfo-4.18.0-372.52.1.el8_6.ppc64le.rpm
kernel-debug-devel-4.18.0-372.52.1.el8_6.ppc64le.rpm
kernel-debug-modules-4.18.0-372.52.1.el8_6.ppc64le.rpm
kernel-debug-modules-extra-4.18.0-372.52.1.el8_6.ppc64le.rpm
kernel-debuginfo-4.18.0-372.52.1.el8_6.ppc64le.rpm
kernel-debuginfo-common-ppc64le-4.18.0-372.52.1.el8_6.ppc64le.rpm
kernel-devel-4.18.0-372.52.1.el8_6.ppc64le.rpm
kernel-headers-4.18.0-372.52.1.el8_6.ppc64le.rpm
kernel-modules-4.18.0-372.52.1.el8_6.ppc64le.rpm
kernel-modules-extra-4.18.0-372.52.1.el8_6.ppc64le.rpm
kernel-tools-4.18.0-372.52.1.el8_6.ppc64le.rpm
kernel-tools-debuginfo-4.18.0-372.52.1.el8_6.ppc64le.rpm
kernel-tools-libs-4.18.0-372.52.1.el8_6.ppc64le.rpm
perf-4.18.0-372.52.1.el8_6.ppc64le.rpm
perf-debuginfo-4.18.0-372.52.1.el8_6.ppc64le.rpm
python3-perf-4.18.0-372.52.1.el8_6.ppc64le.rpm
python3-perf-debuginfo-4.18.0-372.52.1.el8_6.ppc64le.rpm

s390x:
bpftool-4.18.0-372.52.1.el8_6.s390x.rpm
bpftool-debuginfo-4.18.0-372.52.1.el8_6.s390x.rpm
kernel-4.18.0-372.52.1.el8_6.s390x.rpm
kernel-core-4.18.0-372.52.1.el8_6.s390x.rpm
kernel-cross-headers-4.18.0-372.52.1.el8_6.s390x.rpm
kernel-debug-4.18.0-372.52.1.el8_6.s390x.rpm
kernel-debug-core-4.18.0-372.52.1.el8_6.s390x.rpm
kernel-debug-debuginfo-4.18.0-372.52.1.el8_6.s390x.rpm
kernel-debug-devel-4.18.0-372.52.1.el8_6.s390x.rpm
kernel-debug-modules-4.18.0-372.52.1.el8_6.s390x.rpm
kernel-debug-modules-extra-4.18.0-372.52.1.el8_6.s390x.rpm
kernel-debuginfo-4.18.0-372.52.1.el8_6.s390x.rpm
kernel-debuginfo-common-s390x-4.18.0-372.52.1.el8_6.s390x.rpm
kernel-devel-4.18.0-372.52.1.el8_6.s390x.rpm
kernel-headers-4.18.0-372.52.1.el8_6.s390x.rpm
kernel-modules-4.18.0-372.52.1.el8_6.s390x.rpm
kernel-modules-extra-4.18.0-372.52.1.el8_6.s390x.rpm
kernel-tools-4.18.0-372.52.1.el8_6.s390x.rpm
kernel-tools-debuginfo-4.18.0-372.52.1.el8_6.s390x.rpm
kernel-zfcpdump-4.18.0-372.52.1.el8_6.s390x.rpm
kernel-zfcpdump-core-4.18.0-372.52.1.el8_6.s390x.rpm
kernel-zfcpdump-debuginfo-4.18.0-372.52.1.el8_6.s390x.rpm
kernel-zfcpdump-devel-4.18.0-372.52.1.el8_6.s390x.rpm
kernel-zfcpdump-modules-4.18.0-372.52.1.el8_6.s390x.rpm
kernel-zfcpdump-modules-extra-4.18.0-372.52.1.el8_6.s390x.rpm
perf-4.18.0-372.52.1.el8_6.s390x.rpm
perf-debuginfo-4.18.0-372.52.1.el8_6.s390x.rpm
python3-perf-4.18.0-372.52.1.el8_6.s390x.rpm
python3-perf-debuginfo-4.18.0-372.52.1.el8_6.s390x.rpm

x86_64:
bpftool-4.18.0-372.52.1.el8_6.x86_64.rpm
bpftool-debuginfo-4.18.0-372.52.1.el8_6.x86_64.rpm
kernel-4.18.0-372.52.1.el8_6.x86_64.rpm
kernel-core-4.18.0-372.52.1.el8_6.x86_64.rpm
kernel-cross-headers-4.18.0-372.52.1.el8_6.x86_64.rpm
kernel-debug-4.18.0-372.52.1.el8_6.x86_64.rpm
kernel-debug-core-4.18.0-372.52.1.el8_6.x86_64.rpm
kernel-debug-debuginfo-4.18.0-372.52.1.el8_6.x86_64.rpm
kernel-debug-devel-4.18.0-372.52.1.el8_6.x86_64.rpm
kernel-debug-modules-4.18.0-372.52.1.el8_6.x86_64.rpm
kernel-debug-modules-extra-4.18.0-372.52.1.el8_6.x86_64.rpm
kernel-debuginfo-4.18.0-372.52.1.el8_6.x86_64.rpm
kernel-debuginfo-common-x86_64-4.18.0-372.52.1.el8_6.x86_64.rpm
kernel-devel-4.18.0-372.52.1.el8_6.x86_64.rpm
kernel-headers-4.18.0-372.52.1.el8_6.x86_64.rpm
kernel-modules-4.18.0-372.52.1.el8_6.x86_64.rpm
kernel-modules-extra-4.18.0-372.52.1.el8_6.x86_64.rpm
kernel-tools-4.18.0-372.52.1.el8_6.x86_64.rpm
kernel-tools-debuginfo-4.18.0-372.52.1.el8_6.x86_64.rpm
kernel-tools-libs-4.18.0-372.52.1.el8_6.x86_64.rpm
perf-4.18.0-372.52.1.el8_6.x86_64.rpm
perf-debuginfo-4.18.0-372.52.1.el8_6.x86_64.rpm
python3-perf-4.18.0-372.52.1.el8_6.x86_64.rpm
python3-perf-debuginfo-4.18.0-372.52.1.el8_6.x86_64.rpm

Red Hat CodeReady Linux Builder EUS (v.8.6):

aarch64:
bpftool-debuginfo-4.18.0-372.52.1.el8_6.aarch64.rpm
kernel-debug-debuginfo-4.18.0-372.52.1.el8_6.aarch64.rpm
kernel-debuginfo-4.18.0-372.52.1.el8_6.aarch64.rpm
kernel-debuginfo-common-aarch64-4.18.0-372.52.1.el8_6.aarch64.rpm
kernel-tools-debuginfo-4.18.0-372.52.1.el8_6.aarch64.rpm
kernel-tools-libs-devel-4.18.0-372.52.1.el8_6.aarch64.rpm
perf-debuginfo-4.18.0-372.52.1.el8_6.aarch64.rpm
python3-perf-debuginfo-4.18.0-372.52.1.el8_6.aarch64.rpm

ppc64le:
bpftool-debuginfo-4.18.0-372.52.1.el8_6.ppc64le.rpm
kernel-debug-debuginfo-4.18.0-372.52.1.el8_6.ppc64le.rpm
kernel-debuginfo-4.18.0-372.52.1.el8_6.ppc64le.rpm
kernel-debuginfo-common-ppc64le-4.18.0-372.52.1.el8_6.ppc64le.rpm
kernel-tools-debuginfo-4.18.0-372.52.1.el8_6.ppc64le.rpm
kernel-tools-libs-devel-4.18.0-372.52.1.el8_6.ppc64le.rpm
perf-debuginfo-4.18.0-372.52.1.el8_6.ppc64le.rpm
python3-perf-debuginfo-4.18.0-372.52.1.el8_6.ppc64le.rpm

x86_64:
bpftool-debuginfo-4.18.0-372.52.1.el8_6.x86_64.rpm
kernel-debug-debuginfo-4.18.0-372.52.1.el8_6.x86_64.rpm
kernel-debuginfo-4.18.0-372.52.1.el8_6.x86_64.rpm
kernel-debuginfo-common-x86_64-4.18.0-372.52.1.el8_6.x86_64.rpm
kernel-tools-debuginfo-4.18.0-372.52.1.el8_6.x86_64.rpm
kernel-tools-libs-devel-4.18.0-372.52.1.el8_6.x86_64.rpm
perf-debuginfo-4.18.0-372.52.1.el8_6.x86_64.rpm
python3-perf-debuginfo-4.18.0-372.52.1.el8_6.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

  1. References:

https://access.redhat.com/security/cve/CVE-2023-0461
https://access.redhat.com/security/updates/classification/#important

  1. Contact:

The Red Hat security contact is [email protected]. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBZD8akNzjgjWX9erEAQi38BAAiHpf2dYcgntj4qzDKJf77Du2wCnSHMWY
v54cySUEjArA9NKaDJYGY6sD+JNrN60DWMBvb2hdSWd5cOAddvNs0J98vRbCrWkL
fvJzeHcBv/vJ2CVjBIgb73p/ssDj1/ZDCy0ef11bk0xqtjc/fsVlBBl7wegp7Hki
A0ryRDmYK/Q4o3qU0ufw7l5J0bm9dYIEruxjBDHi6nasaIjOK0BblVU5HydQoxJD
9F9j2DL/OgP4D8oqQwjqhb4iARC+Khv2VVOmFT7249vz9Q6bKugTwZFzQ9VpOkqj
p85iM5QbQ4jVJZaoizigC9zfxpRSuUxiFqWiMTlYP+C70YXzIUqExBiip6soc7B8
rjwImYdB5xPqTI27kbPovE8m7iNZjyuyn4Bc/rEw8Eeib1Bn7LDvM/N/m8GSgrfZ
rJQpa5DuK0kM7Y3MS/LylrlVXjgP0u5imkmRvhC320rtrXzrtQ8MNI0wnINHDkdv
/KOSNh4Qn2V+UH3JgxCjsa9ZzyW1ZMU8K8zlU0Iw+0aOm63B8r3dBXM74esgbgHc
A1fYUhq3GdmxHAKFZ8AVHfQTbAVor61Ge4gtW13YCnuBM75reqRRdG6T8Csromxf
zcenGUrgKGlU3Vx81VOYiG0zpFxDyoJ0a7yJYrgxOk88M1NXYPxN8/dK5PE1J9my
9IDQYrJQosc=SGnt
-----END PGP SIGNATURE-----

RHSA-announce mailing list
[email protected]
https://listman.redhat.com/mailman/listinfo/rhsa-announce

Related news

RHSA-2023:4126: Red Hat Security Advisory: kernel-rt security and bug fix update

An update for kernel-rt is now available for Red Hat Enterprise Linux 8.2 Telecommunications Update Service. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2023-0461: A use-after-free flaw was found in the Linux kernel’s TLS protocol functionality in how a user installs a tls context (struct tls_context) on a connected TCP socket. This flaw allows a local user to crash or potentially escalate their privileges on the system. * CVE-2023-1281: A use-after-free vulnerability w...

RHSA-2023:3495: Red Hat Security Advisory: Logging Subsystem 5.7.2 - Red Hat OpenShift security update

Logging Subsystem 5.7.2 - Red Hat OpenShift Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2022-41723: A flaw was found in golang. A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests. * CVE-2023-27539: A denial of service vulnerability was found in rubygem-rack in how it parses headers. A carefully crafted input can cause header parsing to take an unexpe...

RHSA-2023:3470: Red Hat Security Advisory: kernel-rt security and bug fix update

An update for kernel-rt is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2023-0461: A use-after-free flaw was found in the Linux kernel’s TLS protocol functionality in how a user installs a tls context (struct tls_context) on a connected TCP socket. This flaw allows a local user to crash or potentially escalate their privileges on the system. * CVE-2023-2008: A flaw was found in the Linux kernel's udm...

Red Hat Security Advisory 2023-3326-01

Red Hat Security Advisory 2023-3326-01 - Red Hat Advanced Cluster Management for Kubernetes 2.6.6 images. This advisory contains the container images for Red Hat Advanced Cluster Management for Kubernetes, which fix several bugs.

RHSA-2023:3191: Red Hat Security Advisory: kpatch-patch security update

An update for kpatch-patch is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2023-0461: A use-after-free flaw was found in the Linux kernel’s TLS protocol functionality in how a user installs a tls context (struct tls_context) on a connected TCP socket. This flaw allows a local user to crash or potentially escalate their privileges on the system. * CVE-2023-1390: A remote denial of service vu...

RHSA-2023:2736: Red Hat Security Advisory: kernel-rt security and bug fix update

An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2021-26341: A flaw was found in hw. This issue can cause AMD CPUs to transiently execute beyond unconditional direct branches. * CVE-2021-33655: An out-of-bounds write flaw was found in the Linux kernel’s framebuffer-based console driver functionality in the way a user triggers ioctl FBIOPUT_VSCREENINFO with malicious data. This flaw allows a local user t...

Red Hat Security Advisory 2023-2458-01

Red Hat Security Advisory 2023-2458-01 - The kernel packages contain the Linux kernel, the core of any Linux operating system. Issues addressed include buffer overflow, bypass, denial of service, double free, memory leak, null pointer, out of bounds read, privilege escalation, traversal, and use-after-free vulnerabilities.

RHSA-2023:2458: Red Hat Security Advisory: kernel security, bug fix, and enhancement update

An update for kernel is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2021-26341: A flaw was found in hw. This issue can cause AMD CPUs to transiently execute beyond unconditional direct branches. * CVE-2021-33655: An out-of-bounds write flaw was found in the Linux kernel’s framebuffer-based console driver functionality in the way a user triggers ioctl FBIOPUT_VSCREENINFO with malicious data. This flaw allows a local user to c...

RHSA-2023:1923: Red Hat Security Advisory: kpatch-patch security update

An update for kpatch-patch is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2023-0461: A use-after-free flaw was found in the Linux kernel’s TLS protocol functionality in how a user installs a tls context (struct tls_context) on a connected TCP socket. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Red Hat Security Advisory 2023-1662-01

Red Hat Security Advisory 2023-1662-01 - This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel. Issues addressed include a use-after-free vulnerability.

RHSA-2023:1662: Red Hat Security Advisory: kpatch-patch security update

An update for kpatch-patch is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2023-0266: A use-after-free flaw was found in snd_ctl_elem_read in sound/core/control.c in Advanced Linux Sound Architecture (ALSA) subsystem in the Linux kernel. In this flaw a normal privileged, local attacker may impact the system due to a locking issue in the compat path, leading to a kernel information leak problem. * CVE...

Red Hat Security Advisory 2023-1556-01

Red Hat Security Advisory 2023-1556-01 - The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Issues addressed include a use-after-free vulnerability.

Red Hat Security Advisory 2023-1557-01

Red Hat Security Advisory 2023-1557-01 - The kernel packages contain the Linux kernel, the core of any Linux operating system. Issues addressed include a use-after-free vulnerability.

RHSA-2023:1557: Red Hat Security Advisory: kernel security and bug fix update

An update for kernel is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2023-0266: A use-after-free flaw was found in the ALSA subsystem in sound/core/control.c in the Linux kernel. This flaw allows a local attacker to cause a use-after-free issue. * CVE-2023-0461: A use-after-free flaw was found in the Linux kernel’s TLS protocol functionality in how a user installs a tls context (struct tls_context) o...

Ubuntu Security Notice USN-5950-1

Ubuntu Security Notice 5950-1 - It was discovered that the Upper Level Protocol subsystem in the Linux kernel did not properly handle sockets entering the LISTEN state in certain protocols, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. Davide Ornaghi discovered that the netfilter subsystem in the Linux kernel did not properly handle VLAN headers in some situations. A local attacker could use this to cause a denial of service or possibly execute arbitrary code.

Ubuntu Security Notice USN-5929-1

Ubuntu Security Notice 5929-1 - It was discovered that the Upper Level Protocol subsystem in the Linux kernel did not properly handle sockets entering the LISTEN state in certain protocols, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. Davide Ornaghi discovered that the netfilter subsystem in the Linux kernel did not properly handle VLAN headers in some situations. A local attacker could use this to cause a denial of service or possibly execute arbitrary code.

Ubuntu Security Notice USN-5911-1

Ubuntu Security Notice 5911-1 - It was discovered that the Upper Level Protocol subsystem in the Linux kernel did not properly handle sockets entering the LISTEN state in certain protocols, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. Davide Ornaghi discovered that the netfilter subsystem in the Linux kernel did not properly handle VLAN headers in some situations. A local attacker could use this to cause a denial of service or possibly execute arbitrary code.

CVE-2023-0461

There is a use-after-free vulnerability in the Linux Kernel which can be exploited to achieve local privilege escalation. To reach the vulnerability kernel configuration flag CONFIG_TLS or CONFIG_XFRM_ESPINTCP has to be configured, but the operation does not require any privilege. There is a use-after-free bug of icsk_ulp_data of a struct inet_connection_sock. When CONFIG_TLS is enabled, user can install a tls context (struct tls_context) on a connected tcp socket. The context is not cleared if this socket is disconnected and reused as a listener. If a new socket is created from the listener, the context is inherited and vulnerable. The setsockopt TCP_ULP operation does not require any privilege. We recommend upgrading past commit 2c02d41d71f90a5168391b6a5f2954112ba2307c

Ubuntu Security Notice USN-5883-1

Ubuntu Security Notice 5883-1 - Kyle Zeng discovered that the sysctl implementation in the Linux kernel contained a stack-based buffer overflow. A local attacker could use this to cause a denial of service or execute arbitrary code. It was discovered that an out-of-bounds write vulnerability existed in the Video for Linux 2 implementation in the Linux kernel. A local attacker could use this to cause a denial of service or possibly execute arbitrary code.

Packet Storm: Latest News

Zeek 6.0.9