Security
Headlines
HeadlinesLatestCVEs

Headline

RHSA-2023:1466: Red Hat Security Advisory: kpatch-patch security update

An update for kpatch-patch is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

Related CVEs:

  • CVE-2022-4744: A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the device when the register_netdevice function fails (NETDEV_REGISTER notifier). This flaw allows a local user to crash or potentially escalate their privileges on the system.
Red Hat Security Data
#vulnerability#web#linux#red_hat#nodejs#js#java#kubernetes#aws#rpm#sap

Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Containers
  • Support Cases

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Virtualization
  • Red Hat Identity Management
  • Red Hat Directory Server
  • Red Hat Certificate System
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Update Infrastructure
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat CloudForms
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Data Science
  • Red Hat OpenShift Online
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat Single Sign On
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Thorntail
  • Red Hat build of Eclipse Vert.x
  • Red Hat build of OpenJDK
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Process Automation
  • Red Hat Process Automation Manager
  • Red Hat Decision Manager

All Products

Issued:

2023-03-27

Updated:

2023-03-27

RHSA-2023:1466 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: kpatch-patch security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for kpatch-patch is now available for Red Hat Enterprise Linux 9.0 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.

Security Fix(es):

  • kernel: tun: avoid double free in tun_free_netdev (CVE-2022-4744)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.0 x86_64
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.0 ppc64le
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64

Fixes

  • BZ - 2156322 - CVE-2022-4744 kernel: tun: avoid double free in tun_free_netdev

Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.0

SRPM

kpatch-patch-5_14_0-70_26_1-1-6.el9_0.src.rpm

SHA-256: ecfbe57fee9e212177deeaa29f587d00a1bc2db96075e5324b69b6577d13f6d7

kpatch-patch-5_14_0-70_30_1-1-4.el9_0.src.rpm

SHA-256: 187a242e71686f5e84cd6f9d8c8d50d147901f1c3f97322bec88dbcba2ee91bb

kpatch-patch-5_14_0-70_36_1-1-3.el9_0.src.rpm

SHA-256: cbf65c0a0339ab57866b51ba69a8060fbc0cce9d253f95e1696d550bbd9e10cf

kpatch-patch-5_14_0-70_43_1-1-2.el9_0.src.rpm

SHA-256: 223dd5cbe2e97e6e31aa55be4782989fcbc1d7d8681f9f3befb5b760044055e7

kpatch-patch-5_14_0-70_49_1-1-1.el9_0.src.rpm

SHA-256: d551094c052ef64adb374ef1eccedcd7bee613e803804298091d2bf6a6588425

x86_64

kpatch-patch-5_14_0-70_26_1-1-6.el9_0.x86_64.rpm

SHA-256: 2e203b4ea87ba09587a131ee01039eb336a8f5fe88230f1078d8ea1744e90539

kpatch-patch-5_14_0-70_26_1-debuginfo-1-6.el9_0.x86_64.rpm

SHA-256: 50f2e93be180572b8e60d576d61c571d2d03ef3654ef285a6b30ee61f0a1e189

kpatch-patch-5_14_0-70_26_1-debugsource-1-6.el9_0.x86_64.rpm

SHA-256: ee90416f0df756750e961de6680cfd8bc1e5b4425a07ce4c5241e35ba70ca200

kpatch-patch-5_14_0-70_30_1-1-4.el9_0.x86_64.rpm

SHA-256: 3166275bf38dc573783cfa1c60184712407f28618d034c66a4abb281dcaa21db

kpatch-patch-5_14_0-70_30_1-debuginfo-1-4.el9_0.x86_64.rpm

SHA-256: e280d8fc5ff55547194ed9132e0e8d31cddf3380e0f20eb838530b41c6cb0adc

kpatch-patch-5_14_0-70_30_1-debugsource-1-4.el9_0.x86_64.rpm

SHA-256: 4dae0fcf107c5981b3332a69441292ccfa1683fee47b4bccc38d4012bbefc123

kpatch-patch-5_14_0-70_36_1-1-3.el9_0.x86_64.rpm

SHA-256: 9df3a27da658d78dd9c2ca1438989643d4d5d9adc886700cf3481a59da6f3fa8

kpatch-patch-5_14_0-70_36_1-debuginfo-1-3.el9_0.x86_64.rpm

SHA-256: 737c4e75148ef9ede01c232de74cdf3da0b1c67ab9be9b88df042867b1fa4684

kpatch-patch-5_14_0-70_36_1-debugsource-1-3.el9_0.x86_64.rpm

SHA-256: 2dfc043ed9b8ca2dc417e0cc37ae0d03f7366371e7c00f0f93d413e2961af41b

kpatch-patch-5_14_0-70_43_1-1-2.el9_0.x86_64.rpm

SHA-256: 82fdf30cc4b04778bb29ca98a876acd74dac4cd2cd0d721bbc58b8b98df78c37

kpatch-patch-5_14_0-70_43_1-debuginfo-1-2.el9_0.x86_64.rpm

SHA-256: 245fa4b01f2783d848d95412cfe001d9f9fddc9a08d7af44195f839fe0d3819c

kpatch-patch-5_14_0-70_43_1-debugsource-1-2.el9_0.x86_64.rpm

SHA-256: c7446ec0519ca1eb69a079e49efc8fa8675a9211f658c213adfa217895da8ecc

kpatch-patch-5_14_0-70_49_1-1-1.el9_0.x86_64.rpm

SHA-256: 0cad296422422550f56b5a1e91a410dc63d26386b333d13605b246a72c817784

kpatch-patch-5_14_0-70_49_1-debuginfo-1-1.el9_0.x86_64.rpm

SHA-256: 79bda04f95148c80ce08c800c37a430ed98265610cf7c0fe39043b5bd3d54298

kpatch-patch-5_14_0-70_49_1-debugsource-1-1.el9_0.x86_64.rpm

SHA-256: c54b9714713c68773d8e0f4f5f6b063d4859d954f396587872b80a70032d2edb

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.0

SRPM

kpatch-patch-5_14_0-70_26_1-1-6.el9_0.src.rpm

SHA-256: ecfbe57fee9e212177deeaa29f587d00a1bc2db96075e5324b69b6577d13f6d7

kpatch-patch-5_14_0-70_30_1-1-4.el9_0.src.rpm

SHA-256: 187a242e71686f5e84cd6f9d8c8d50d147901f1c3f97322bec88dbcba2ee91bb

kpatch-patch-5_14_0-70_36_1-1-3.el9_0.src.rpm

SHA-256: cbf65c0a0339ab57866b51ba69a8060fbc0cce9d253f95e1696d550bbd9e10cf

kpatch-patch-5_14_0-70_43_1-1-2.el9_0.src.rpm

SHA-256: 223dd5cbe2e97e6e31aa55be4782989fcbc1d7d8681f9f3befb5b760044055e7

kpatch-patch-5_14_0-70_49_1-1-1.el9_0.src.rpm

SHA-256: d551094c052ef64adb374ef1eccedcd7bee613e803804298091d2bf6a6588425

ppc64le

kpatch-patch-5_14_0-70_26_1-1-6.el9_0.ppc64le.rpm

SHA-256: 68ee5421af6bd408acf313c2f291bcfc720e995b80e0e55426532cb626973262

kpatch-patch-5_14_0-70_26_1-debuginfo-1-6.el9_0.ppc64le.rpm

SHA-256: 326386e57b26af32114e3ea5fae2c30660f40d131862fbcf3fc040f9d561108c

kpatch-patch-5_14_0-70_26_1-debugsource-1-6.el9_0.ppc64le.rpm

SHA-256: 599e8a86c858141f7bc7e433e05ec58343a5e6624bd07d48e1407aae4342ce95

kpatch-patch-5_14_0-70_30_1-1-4.el9_0.ppc64le.rpm

SHA-256: 162ff31b3eec7ef725723664d4905b778c3f852157440edc602eeac4f88dcc29

kpatch-patch-5_14_0-70_30_1-debuginfo-1-4.el9_0.ppc64le.rpm

SHA-256: 57aeedd0778a4116a55aced049d64e834d43251b15901764061cb04f60f3436a

kpatch-patch-5_14_0-70_30_1-debugsource-1-4.el9_0.ppc64le.rpm

SHA-256: a1766eddf7c82fda8680e4da622faed2128a4c0299829335c77bafb86612dbc0

kpatch-patch-5_14_0-70_36_1-1-3.el9_0.ppc64le.rpm

SHA-256: 36aedad54d639b7e48fbeb3b81c9e66e2ea6327bbcfbfdbc4b2b70310e22c3c5

kpatch-patch-5_14_0-70_36_1-debuginfo-1-3.el9_0.ppc64le.rpm

SHA-256: 1360fe3e7b2c0e191058608609b266fd06c65d3ddf0402b7453c9ca59435108a

kpatch-patch-5_14_0-70_36_1-debugsource-1-3.el9_0.ppc64le.rpm

SHA-256: 66bcacbb7b5fa9152f5d360081cc43b4c038232e0de2e8ad259d2853ed2d164e

kpatch-patch-5_14_0-70_43_1-1-2.el9_0.ppc64le.rpm

SHA-256: 0f153dd86d4872c78337374db58507fe2ae51d50bb2d684652ddb139349cd14f

kpatch-patch-5_14_0-70_43_1-debuginfo-1-2.el9_0.ppc64le.rpm

SHA-256: 89e7ef0a4d556f028a2ee03b6bb71c8601a948e8c999d8b1f6fc583ae85505e4

kpatch-patch-5_14_0-70_43_1-debugsource-1-2.el9_0.ppc64le.rpm

SHA-256: 1a148ed6abce74d84880963ae62618f2aee39408c286bbf6bf0335f418bd2516

kpatch-patch-5_14_0-70_49_1-1-1.el9_0.ppc64le.rpm

SHA-256: 9177f6368e816ea7cb1d44d41f71b46b7bece086fa16863b2a5101f686f4c329

kpatch-patch-5_14_0-70_49_1-debuginfo-1-1.el9_0.ppc64le.rpm

SHA-256: a0f47ff8afe70c43dea631e2536270b8f05addb4d00d55f5fbc717d5e45d4d49

kpatch-patch-5_14_0-70_49_1-debugsource-1-1.el9_0.ppc64le.rpm

SHA-256: db91fc46b80488667751a36e24900d966b0c506f466f0ad9444ac5130270b025

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM

kpatch-patch-5_14_0-70_26_1-1-6.el9_0.src.rpm

SHA-256: ecfbe57fee9e212177deeaa29f587d00a1bc2db96075e5324b69b6577d13f6d7

kpatch-patch-5_14_0-70_30_1-1-4.el9_0.src.rpm

SHA-256: 187a242e71686f5e84cd6f9d8c8d50d147901f1c3f97322bec88dbcba2ee91bb

kpatch-patch-5_14_0-70_36_1-1-3.el9_0.src.rpm

SHA-256: cbf65c0a0339ab57866b51ba69a8060fbc0cce9d253f95e1696d550bbd9e10cf

kpatch-patch-5_14_0-70_43_1-1-2.el9_0.src.rpm

SHA-256: 223dd5cbe2e97e6e31aa55be4782989fcbc1d7d8681f9f3befb5b760044055e7

kpatch-patch-5_14_0-70_49_1-1-1.el9_0.src.rpm

SHA-256: d551094c052ef64adb374ef1eccedcd7bee613e803804298091d2bf6a6588425

ppc64le

kpatch-patch-5_14_0-70_26_1-1-6.el9_0.ppc64le.rpm

SHA-256: 68ee5421af6bd408acf313c2f291bcfc720e995b80e0e55426532cb626973262

kpatch-patch-5_14_0-70_26_1-debuginfo-1-6.el9_0.ppc64le.rpm

SHA-256: 326386e57b26af32114e3ea5fae2c30660f40d131862fbcf3fc040f9d561108c

kpatch-patch-5_14_0-70_26_1-debugsource-1-6.el9_0.ppc64le.rpm

SHA-256: 599e8a86c858141f7bc7e433e05ec58343a5e6624bd07d48e1407aae4342ce95

kpatch-patch-5_14_0-70_30_1-1-4.el9_0.ppc64le.rpm

SHA-256: 162ff31b3eec7ef725723664d4905b778c3f852157440edc602eeac4f88dcc29

kpatch-patch-5_14_0-70_30_1-debuginfo-1-4.el9_0.ppc64le.rpm

SHA-256: 57aeedd0778a4116a55aced049d64e834d43251b15901764061cb04f60f3436a

kpatch-patch-5_14_0-70_30_1-debugsource-1-4.el9_0.ppc64le.rpm

SHA-256: a1766eddf7c82fda8680e4da622faed2128a4c0299829335c77bafb86612dbc0

kpatch-patch-5_14_0-70_36_1-1-3.el9_0.ppc64le.rpm

SHA-256: 36aedad54d639b7e48fbeb3b81c9e66e2ea6327bbcfbfdbc4b2b70310e22c3c5

kpatch-patch-5_14_0-70_36_1-debuginfo-1-3.el9_0.ppc64le.rpm

SHA-256: 1360fe3e7b2c0e191058608609b266fd06c65d3ddf0402b7453c9ca59435108a

kpatch-patch-5_14_0-70_36_1-debugsource-1-3.el9_0.ppc64le.rpm

SHA-256: 66bcacbb7b5fa9152f5d360081cc43b4c038232e0de2e8ad259d2853ed2d164e

kpatch-patch-5_14_0-70_43_1-1-2.el9_0.ppc64le.rpm

SHA-256: 0f153dd86d4872c78337374db58507fe2ae51d50bb2d684652ddb139349cd14f

kpatch-patch-5_14_0-70_43_1-debuginfo-1-2.el9_0.ppc64le.rpm

SHA-256: 89e7ef0a4d556f028a2ee03b6bb71c8601a948e8c999d8b1f6fc583ae85505e4

kpatch-patch-5_14_0-70_43_1-debugsource-1-2.el9_0.ppc64le.rpm

SHA-256: 1a148ed6abce74d84880963ae62618f2aee39408c286bbf6bf0335f418bd2516

kpatch-patch-5_14_0-70_49_1-1-1.el9_0.ppc64le.rpm

SHA-256: 9177f6368e816ea7cb1d44d41f71b46b7bece086fa16863b2a5101f686f4c329

kpatch-patch-5_14_0-70_49_1-debuginfo-1-1.el9_0.ppc64le.rpm

SHA-256: a0f47ff8afe70c43dea631e2536270b8f05addb4d00d55f5fbc717d5e45d4d49

kpatch-patch-5_14_0-70_49_1-debugsource-1-1.el9_0.ppc64le.rpm

SHA-256: db91fc46b80488667751a36e24900d966b0c506f466f0ad9444ac5130270b025

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM

kpatch-patch-5_14_0-70_26_1-1-6.el9_0.src.rpm

SHA-256: ecfbe57fee9e212177deeaa29f587d00a1bc2db96075e5324b69b6577d13f6d7

kpatch-patch-5_14_0-70_30_1-1-4.el9_0.src.rpm

SHA-256: 187a242e71686f5e84cd6f9d8c8d50d147901f1c3f97322bec88dbcba2ee91bb

kpatch-patch-5_14_0-70_36_1-1-3.el9_0.src.rpm

SHA-256: cbf65c0a0339ab57866b51ba69a8060fbc0cce9d253f95e1696d550bbd9e10cf

kpatch-patch-5_14_0-70_43_1-1-2.el9_0.src.rpm

SHA-256: 223dd5cbe2e97e6e31aa55be4782989fcbc1d7d8681f9f3befb5b760044055e7

kpatch-patch-5_14_0-70_49_1-1-1.el9_0.src.rpm

SHA-256: d551094c052ef64adb374ef1eccedcd7bee613e803804298091d2bf6a6588425

x86_64

kpatch-patch-5_14_0-70_26_1-1-6.el9_0.x86_64.rpm

SHA-256: 2e203b4ea87ba09587a131ee01039eb336a8f5fe88230f1078d8ea1744e90539

kpatch-patch-5_14_0-70_26_1-debuginfo-1-6.el9_0.x86_64.rpm

SHA-256: 50f2e93be180572b8e60d576d61c571d2d03ef3654ef285a6b30ee61f0a1e189

kpatch-patch-5_14_0-70_26_1-debugsource-1-6.el9_0.x86_64.rpm

SHA-256: ee90416f0df756750e961de6680cfd8bc1e5b4425a07ce4c5241e35ba70ca200

kpatch-patch-5_14_0-70_30_1-1-4.el9_0.x86_64.rpm

SHA-256: 3166275bf38dc573783cfa1c60184712407f28618d034c66a4abb281dcaa21db

kpatch-patch-5_14_0-70_30_1-debuginfo-1-4.el9_0.x86_64.rpm

SHA-256: e280d8fc5ff55547194ed9132e0e8d31cddf3380e0f20eb838530b41c6cb0adc

kpatch-patch-5_14_0-70_30_1-debugsource-1-4.el9_0.x86_64.rpm

SHA-256: 4dae0fcf107c5981b3332a69441292ccfa1683fee47b4bccc38d4012bbefc123

kpatch-patch-5_14_0-70_36_1-1-3.el9_0.x86_64.rpm

SHA-256: 9df3a27da658d78dd9c2ca1438989643d4d5d9adc886700cf3481a59da6f3fa8

kpatch-patch-5_14_0-70_36_1-debuginfo-1-3.el9_0.x86_64.rpm

SHA-256: 737c4e75148ef9ede01c232de74cdf3da0b1c67ab9be9b88df042867b1fa4684

kpatch-patch-5_14_0-70_36_1-debugsource-1-3.el9_0.x86_64.rpm

SHA-256: 2dfc043ed9b8ca2dc417e0cc37ae0d03f7366371e7c00f0f93d413e2961af41b

kpatch-patch-5_14_0-70_43_1-1-2.el9_0.x86_64.rpm

SHA-256: 82fdf30cc4b04778bb29ca98a876acd74dac4cd2cd0d721bbc58b8b98df78c37

kpatch-patch-5_14_0-70_43_1-debuginfo-1-2.el9_0.x86_64.rpm

SHA-256: 245fa4b01f2783d848d95412cfe001d9f9fddc9a08d7af44195f839fe0d3819c

kpatch-patch-5_14_0-70_43_1-debugsource-1-2.el9_0.x86_64.rpm

SHA-256: c7446ec0519ca1eb69a079e49efc8fa8675a9211f658c213adfa217895da8ecc

kpatch-patch-5_14_0-70_49_1-1-1.el9_0.x86_64.rpm

SHA-256: 0cad296422422550f56b5a1e91a410dc63d26386b333d13605b246a72c817784

kpatch-patch-5_14_0-70_49_1-debuginfo-1-1.el9_0.x86_64.rpm

SHA-256: 79bda04f95148c80ce08c800c37a430ed98265610cf7c0fe39043b5bd3d54298

kpatch-patch-5_14_0-70_49_1-debugsource-1-1.el9_0.x86_64.rpm

SHA-256: c54b9714713c68773d8e0f4f5f6b063d4859d954f396587872b80a70032d2edb

The Red Hat security contact is [email protected]. More contact details at https://access.redhat.com/security/team/contact/.

Related news

Red Hat Security Advisory 2023-7077-01

Red Hat Security Advisory 2023-7077-01 - An update for kernel is now available for Red Hat Enterprise Linux 8. Issues addressed include buffer overflow, denial of service, double free, information leakage, memory leak, null pointer, out of bounds access, out of bounds write, and use-after-free vulnerabilities.

CVE-2023-32463: DSA-2023-200: Security Update for Dell VxRail for Multiple Third-Party Component Vulnerabilities

Dell VxRail, version(s) 8.0.100 and earlier contain a denial-of-service vulnerability in the upgrade functionality. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to degraded performance and system malfunction.

CVE-2022-4744

A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the device when the register_netdevice function fails (NETDEV_REGISTER notifier). This flaw allows a local user to crash or potentially escalate their privileges on the system.

Red Hat Security Advisory 2023-1470-01

Red Hat Security Advisory 2023-1470-01 - The kernel packages contain the Linux kernel, the core of any Linux operating system. Issues addressed include a double free vulnerability.

Red Hat Security Advisory 2023-1468-01

Red Hat Security Advisory 2023-1468-01 - The kernel packages contain the Linux kernel, the core of any Linux operating system. Issues addressed include a double free vulnerability.

Red Hat Security Advisory 2023-1467-01

Red Hat Security Advisory 2023-1467-01 - The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Issues addressed include a double free vulnerability.

Red Hat Security Advisory 2023-1469-01

Red Hat Security Advisory 2023-1469-01 - The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Issues addressed include a double free vulnerability.

Red Hat Security Advisory 2023-1471-01

Red Hat Security Advisory 2023-1471-01 - This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel. Issues addressed include a double free vulnerability.

RHSA-2023:1468: Red Hat Security Advisory: kernel security, bug fix, and enhancement update

An update for kernel is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2022-4744: A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the device when the register_netdevice function fails (NETDEV_REGISTER notifier). This flaw allows a local user to crash or potentially escalate their privileges on the system.

RHSA-2023:1470: Red Hat Security Advisory: kernel security, bug fix, and enhancement update

An update for kernel is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2022-4269: A flaw was found in the Linux kernel Traffic Control (TC) subsystem. Using a specific networking configuration (redirecting egress packets to ingress using TC action "mirred") a local unprivileged user could trigger a CPU soft lockup (ABBA deadlock) when the transport protocol in use (TCP or SCTP) does a retransmission, resulting in a denial of se...

RHSA-2023:1471: Red Hat Security Advisory: kpatch-patch security update

An update for kpatch-patch is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2022-4744: A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the device when the register_netdevice function fails (NETDEV_REGISTER notifier). This flaw allows a local user to crash or potentially escalate their privileges on the system. * CVE-2023-0266: A use-after-free flaw was found in the...

RHSA-2023:1469: Red Hat Security Advisory: kernel-rt security and bug fix update

An update for kernel-rt is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2022-4269: A flaw was found in the Linux kernel Traffic Control (TC) subsystem. Using a specific networking configuration (redirecting egress packets to ingress using TC action "mirred") a local unprivileged user could trigger a CPU soft lockup (ABBA deadlock) when the transport protocol in use (TCP or SCTP) does a retransmission, resulting in a denial of...

RHSA-2023:1467: Red Hat Security Advisory: kernel-rt security and bug fix update

An update for kernel-rt is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2022-4744: A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the device when the register_netdevice function fails (NETDEV_REGISTER notifier). This flaw allows a local user to crash or potentially escalate their privileges on the system.