Lucene search

K
redhatRedHatRHSA-2023:1435
HistoryMar 23, 2023 - 8:59 a.m.

(RHSA-2023:1435) Important: kpatch-patch security update

2023-03-2308:59:14
access.redhat.com
18
kpatch-patch
security update
kernel
use-after-free
stack overflow
remote denial of service
netfilter
alsa

0.002 Low

EPSS

Percentile

56.8%

This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.

Security Fix(es):

  • kernel: use-after-free caused by l2cap_reassemble_sdu() in net/bluetooth/l2cap_core.c (CVE-2022-3564)

  • kernel: stack overflow in do_proc_dointvec and proc_skip_spaces (CVE-2022-4378)

  • kernel: use-after-free in __nfs42_ssc_open() in fs/nfs/nfs4file.c leading to remote Denial of Service attack (CVE-2022-4379)

  • kernel: Netfilter integer overflow vulnerability in nft_payload_copy_vlan (CVE-2023-0179)

  • ALSA: pcm: Move rwsem lock inside snd_ctl_elem_read to prevent UAF (CVE-2023-0266)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.