Lucene search

K
redhatRedHatRHSA-2023:1468
HistoryMar 27, 2023 - 7:46 a.m.

(RHSA-2023:1468) Important: kernel security, bug fix, and enhancement update

2023-03-2707:46:57
access.redhat.com
33
rhsa-2023-1468
linux kernel
security fix
tun
double free
cve-2022-4744
bug fix
rhel 9.1
nmi watchdog
lpm
rainer
lmb
kdump
s390
kexec
ipl report
azure
rmb mana
ibm 9.2
qeth driver
kernel 6.0

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: tun: avoid double free in tun_free_netdev (CVE-2022-4744)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • RHEL 9.1 Extending NMI watchdog’s timer during LPM (BZ#2140086)

  • RHEL9.1 Rainer 2gb/4GB LMB: kdump is not working with 2GB/4GB LMB size[FW1030]. (BZ#2151867)

  • RHEL9.0 - s390/kexec: fix ipl report address for kdump (BZ#2166904)

  • Azure RHEL-9 RMB MANA: RMB Patch To Backport On The Azure Linux Images (BZ#2172876)

Enhancement(s):

  • IBM 9.2 FEAT Upgrade the QETH driver to the latest from upstream, e.g. kernel 6.0 (BZ#2166305)

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%