Lucene search

K
redhatRedHatRHSA-2023:1559
HistoryApr 04, 2023 - 6:33 a.m.

(RHSA-2023:1559) Important: kernel security and bug fix update

2023-04-0406:33:17
access.redhat.com
68
kernel
linux
security
bug fix
cve
alsa
iavf
rhel8.4
windows server 2019
kvm

7.9 High

CVSS3

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:H

0.001 Low

EPSS

Percentile

41.1%

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: use-after-free caused by l2cap_reassemble_sdu() in net/bluetooth/l2cap_core.c (CVE-2022-3564)

  • ALSA: pcm: Move rwsem lock inside snd_ctl_elem_read to prevent UAF (CVE-2023-0266)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • iavf: Fix updating statistics (BZ#2142509)

  • RHEL8.4: Backport the new cgroup slab memory controller in v.5.9 (BZ#2164636)

  • Windows Server 2019 guest randomly pauses with “KVM: entry failed, hardware error 0x80000021” (BZ#2166371)

  • RHEL8.3: Backport upstream locking changes up to v5.6 (BZ#2170061)

7.9 High

CVSS3

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:H

0.001 Low

EPSS

Percentile

41.1%