RHSA-2024:0439
Vulnerability Summary
Timeline
Description
Red Hat Security Advisory: kernel-rt security update
CVSS Metrics
- v3.1•HIGH•Score: 8.2CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Affected Systems
- redhat•kernel-rt
< 0:5.14.0-284.48.1.rt14.333.el9_2 | < 0:5.14.0-284.48.1.rt14.333.el9_2
- redhat•kernel-rt-core
< 0:5.14.0-284.48.1.rt14.333.el9_2 | < 0:5.14.0-284.48.1.rt14.333.el9_2
- redhat•kernel-rt-debug
< 0:5.14.0-284.48.1.rt14.333.el9_2 | < 0:5.14.0-284.48.1.rt14.333.el9_2
- redhat•kernel-rt-debug-core
< 0:5.14.0-284.48.1.rt14.333.el9_2 | < 0:5.14.0-284.48.1.rt14.333.el9_2
- redhat•kernel-rt-debug-debuginfo
< 0:5.14.0-284.48.1.rt14.333.el9_2 | < 0:5.14.0-284.48.1.rt14.333.el9_2
- redhat•kernel-rt-debug-devel
< 0:5.14.0-284.48.1.rt14.333.el9_2 | < 0:5.14.0-284.48.1.rt14.333.el9_2
- redhat•kernel-rt-debug-kvm
< 0:5.14.0-284.48.1.rt14.333.el9_2 | < 0:5.14.0-284.48.1.rt14.333.el9_2
- redhat•kernel-rt-debug-modules
< 0:5.14.0-284.48.1.rt14.333.el9_2 | < 0:5.14.0-284.48.1.rt14.333.el9_2
- redhat•kernel-rt-debug-modules-core
< 0:5.14.0-284.48.1.rt14.333.el9_2 | < 0:5.14.0-284.48.1.rt14.333.el9_2
- redhat•kernel-rt-debug-modules-extra
< 0:5.14.0-284.48.1.rt14.333.el9_2 | < 0:5.14.0-284.48.1.rt14.333.el9_2
- redhat•kernel-rt-debuginfo
< 0:5.14.0-284.48.1.rt14.333.el9_2 | < 0:5.14.0-284.48.1.rt14.333.el9_2
- redhat•kernel-rt-debuginfo-common-x86_64
< 0:5.14.0-284.48.1.rt14.333.el9_2 | < 0:5.14.0-284.48.1.rt14.333.el9_2
- redhat•kernel-rt-devel
< 0:5.14.0-284.48.1.rt14.333.el9_2 | < 0:5.14.0-284.48.1.rt14.333.el9_2
- redhat•kernel-rt-kvm
< 0:5.14.0-284.48.1.rt14.333.el9_2 | < 0:5.14.0-284.48.1.rt14.333.el9_2
- redhat•kernel-rt-modules
< 0:5.14.0-284.48.1.rt14.333.el9_2 | < 0:5.14.0-284.48.1.rt14.333.el9_2
- redhat•kernel-rt-modules-core
< 0:5.14.0-284.48.1.rt14.333.el9_2 | < 0:5.14.0-284.48.1.rt14.333.el9_2
- redhat•kernel-rt-modules-extra
< 0:5.14.0-284.48.1.rt14.333.el9_2 | < 0:5.14.0-284.48.1.rt14.333.el9_2
References (120)
- https://access.redhat.com/errata/RHSA-2024:0439
- https://access.redhat.com/security/updates/classification/#important
- https://bugzilla.redhat.com/show_bug.cgi?id=2144379
- https://bugzilla.redhat.com/show_bug.cgi?id=2154178
- https://bugzilla.redhat.com/show_bug.cgi?id=2161310
- https://bugzilla.redhat.com/show_bug.cgi?id=2187773
- https://bugzilla.redhat.com/show_bug.cgi?id=2187813
- https://bugzilla.redhat.com/show_bug.cgi?id=2187931
- https://bugzilla.redhat.com/show_bug.cgi?id=2207625
- https://bugzilla.redhat.com/show_bug.cgi?id=2221463
- https://bugzilla.redhat.com/show_bug.cgi?id=2226783
- https://bugzilla.redhat.com/show_bug.cgi?id=2230042
- https://bugzilla.redhat.com/show_bug.cgi?id=2230094
- https://bugzilla.redhat.com/show_bug.cgi?id=2231800
- https://bugzilla.redhat.com/show_bug.cgi?id=2237750
- https://bugzilla.redhat.com/show_bug.cgi?id=2237752
- https://bugzilla.redhat.com/show_bug.cgi?id=2237757
- https://bugzilla.redhat.com/show_bug.cgi?id=2237760
- https://bugzilla.redhat.com/show_bug.cgi?id=2240249
- https://bugzilla.redhat.com/show_bug.cgi?id=2244723
- https://bugzilla.redhat.com/show_bug.cgi?id=2246944
- https://bugzilla.redhat.com/show_bug.cgi?id=2246945
- https://bugzilla.redhat.com/show_bug.cgi?id=2253986
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0439.json
- https://access.redhat.com/security/cve/CVE-2022-3545
- https://www.cve.org/CVERecord?id=CVE-2022-3545
- https://nvd.nist.gov/vuln/detail/CVE-2022-3545
- https://git.kernel.org/pub/scm/linux/kernel/git/klassert/ipsec-next.git/commit/?id=02e1a114fdb71e59ee6770294166c30d437bf86a
- https://access.redhat.com/security/cve/CVE-2022-41858
- https://www.cve.org/CVERecord?id=CVE-2022-41858
- https://nvd.nist.gov/vuln/detail/CVE-2022-41858
- https://github.com/torvalds/linux/commit/ec4eb8a86ade4d22633e1da2a7d85a846b7d1798
- https://access.redhat.com/security/cve/CVE-2023-1192
- https://www.cve.org/CVERecord?id=CVE-2023-1192
- https://nvd.nist.gov/vuln/detail/CVE-2023-1192
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d527f51331cace562393a8038d870b3e9916686fCVE-2023-52
- https://access.redhat.com/security/cve/CVE-2023-2162
- https://www.cve.org/CVERecord?id=CVE-2023-2162
- https://nvd.nist.gov/vuln/detail/CVE-2023-2162
- https://www.spinics.net/lists/linux-scsi/msg181542.html
- https://access.redhat.com/security/cve/CVE-2023-2163
- https://www.cve.org/CVERecord?id=CVE-2023-2163
- https://nvd.nist.gov/vuln/detail/CVE-2023-2163
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=71b547f561247897a0a14f3082730156c0533fed
- https://access.redhat.com/security/cve/CVE-2023-2166
- https://www.cve.org/CVERecord?id=CVE-2023-2166
- https://nvd.nist.gov/vuln/detail/CVE-2023-2166
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0acc442309a0a1b01bcdaa135e56e6398a49439c
- https://access.redhat.com/security/cve/CVE-2023-2176
- https://www.cve.org/CVERecord?id=CVE-2023-2176
- https://nvd.nist.gov/vuln/detail/CVE-2023-2176
- https://www.spinics.net/lists/linux-rdma/msg114749.html
- https://access.redhat.com/security/cve/CVE-2023-3567
- https://www.cve.org/CVERecord?id=CVE-2023-3567
- https://nvd.nist.gov/vuln/detail/CVE-2023-3567
- https://www.spinics.net/lists/stable-commits/msg285184.html
- https://access.redhat.com/security/cve/CVE-2023-3777
- https://www.cve.org/CVERecord?id=CVE-2023-3777
- https://nvd.nist.gov/vuln/detail/CVE-2023-3777
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=6eaf41e87a223ae6f8e7a28d6e78384ad7e407f8
- https://access.redhat.com/security/cve/CVE-2023-4015
- https://www.cve.org/CVERecord?id=CVE-2023-4015
- https://nvd.nist.gov/vuln/detail/CVE-2023-4015
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0a771f7b266b02d262900c75f1e175c7fe76fec2
- https://access.redhat.com/security/cve/CVE-2023-4622
- https://www.cve.org/CVERecord?id=CVE-2023-4622
- https://nvd.nist.gov/vuln/detail/CVE-2023-4622
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=linux-6.1.y&id=790c2f9d15b594350ae9bca7b236f2b1859de02c
- https://access.redhat.com/security/cve/CVE-2023-4623
- https://www.cve.org/CVERecord?id=CVE-2023-4623
- https://nvd.nist.gov/vuln/detail/CVE-2023-4623
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b3d26c5702c7d6c45456326e56d2ccf3f103e60f
- https://access.redhat.com/security/cve/CVE-2023-5717
- https://www.cve.org/CVERecord?id=CVE-2023-5717
- https://nvd.nist.gov/vuln/detail/CVE-2023-5717
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/kernel/events?id=32671e3799ca2e4590773fd0e63aaa4229e50c06
- https://access.redhat.com/security/cve/CVE-2023-6679
- https://www.cve.org/CVERecord?id=CVE-2023-6679
- https://nvd.nist.gov/vuln/detail/CVE-2023-6679
- https://lore.kernel.org/netdev/20231211083758.1082853-1-jiri@resnulli.us/
- https://access.redhat.com/security/cve/CVE-2023-20569
- https://www.cve.org/CVERecord?id=CVE-2023-20569
- https://nvd.nist.gov/vuln/detail/CVE-2023-20569
- https://access.redhat.com/solutions/7049120
- https://www.amd.com/content/dam/amd/en/documents/corporate/cr/speculative-return-stack-overflow-whitepaper.pdf
- https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7005.html
- https://access.redhat.com/security/cve/CVE-2023-38409
- https://www.cve.org/CVERecord?id=CVE-2023-38409
- https://nvd.nist.gov/vuln/detail/CVE-2023-38409
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=fffb0b52d5258554c645c966c6cbef7de50b851d
- https://access.redhat.com/security/cve/CVE-2023-39191
- https://www.cve.org/CVERecord?id=CVE-2023-39191
- https://nvd.nist.gov/vuln/detail/CVE-2023-39191
- https://www.zerodayinitiative.com/advisories/ZDI-CAN-19399/
- https://access.redhat.com/security/cve/CVE-2023-40283
- https://www.cve.org/CVERecord?id=CVE-2023-40283
- https://nvd.nist.gov/vuln/detail/CVE-2023-40283
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=1728137b33c00d5a2b5110ed7aafb42e7c32e4a1
- https://access.redhat.com/security/cve/CVE-2023-45871
- https://www.cve.org/CVERecord?id=CVE-2023-45871
- https://nvd.nist.gov/vuln/detail/CVE-2023-45871
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=bb5ed01cd2428cd25b1c88a3a9cba87055eb289f
- https://access.redhat.com/security/cve/CVE-2023-46813
- https://www.cve.org/CVERecord?id=CVE-2023-46813
- https://nvd.nist.gov/vuln/detail/CVE-2023-46813
- https://bugzilla.suse.com/show_bug.cgi?id=1212649
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.5.9
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=63e44bc52047f182601e7817da969a105aa1f721
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a37cd2a59d0cb270b1bba568fd3a3b8668b9d3ba
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b9cb9c45583b911e0db71d09caa6b56469eb2bdf
- https://access.redhat.com/security/cve/CVE-2023-52973
- https://bugzilla.redhat.com/show_bug.cgi?id=2355433
- https://www.cve.org/CVERecord?id=CVE-2023-52973
- https://nvd.nist.gov/vuln/detail/CVE-2023-52973
- https://lore.kernel.org/linux-cve-announce/2025032703-CVE-2023-52973-a993@gregkh/T
- https://access.redhat.com/security/cve/CVE-2022-50879
- https://bugzilla.redhat.com/show_bug.cgi?id=2426076
- https://www.cve.org/CVERecord?id=CVE-2022-50879
- https://nvd.nist.gov/vuln/detail/CVE-2022-50879
- https://lore.kernel.org/linux-cve-announce/2025123024-CVE-2022-50879-47a7@gregkh/T