Lucene search

K
redhatRedHatRHSA-2023:4130
HistoryJul 18, 2023 - 7:19 a.m.

(RHSA-2023:4130) Important: kernel security and bug fix update

2023-07-1807:19:35
access.redhat.com
21
kernel security
privilege escalation
netfilter
traffic control index filter
nf_tables
bug fix
s390/smp
powerstore luns
qla2xxx
iscsi target
azure
xfs deadlock
intel e810
ice
fips
cvm patch
esxi
hyper-v

0.0004 Low

EPSS

Percentile

5.1%

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: tcindex: use-after-free vulnerability in traffic control index filter allows privilege escalation (CVE-2023-1281)

  • kernel: netfilter: use-after-free in nf_tables when processing batch requests can lead to privilege escalation (CVE-2023-32233)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • RHEL8.4 - s390/smp,vdso: fix ASCE handling (BZ#2176464)

  • After powerstore LUNs are mapped, OS crashed and host reboot. (BZ#2179068)

  • qla2xxx NVMe-FC: WARNING: CPU: 0 PID: 124072 at drivers/scsi/qla2xxx/qla_init.c:70 qla2xxx_rel_done_warning+0x25/0x30 [qla2xxx] (BZ#2181529)

  • iscsi target deadlocks when the same host acts as an initiator to itself (i.e. connects via 127.0.0.1) (BZ#2182095)

  • Dying percpu kworkers cause issues on isolated CPUs [rhel-8] (BZ#2189597)

  • Azure RHEL8: Live resize of disk does not trigger a rescan of the device capacity (BZ#2192345)

  • RHEL8.4 - kernel: fix __clear_user() inline assembly constraints (BZ#2192604)

  • RHEL8.6, lockd : oops on nlmsvc_mark_host (BZ#2196386)

  • xfs: deadlock in xfs_btree_split_worker (BZ#2196392)

  • Intel E810 card unable to create a MACVLAN on interface already configured as SRIOV (BZ#2203217)

  • ice: ptp4l cpu usage spikes (BZ#2203287)

  • Kernel - Significant performance drop for getrandom system call when FIPS is enabled (compared to RHEL 8.x for all x < 6.z) (BZ#2208130)

  • Azure RHEL8: CVM patch list requirement-storvsc patch (BZ#2208601)

  • BUG_ON “kernel BUG at mm/rmap.c:1041!” in __page_set_anon_rmap() when vma->anon_vma==NULL (BZ#2211661)

  • RHEL 8.6 opening console with mkvterm on novalink terminal fails due to drmgr reporting failure (L3:) (BZ#2212374)

  • ESXi RHEL8: Haswell generation CPU are impacted with performance due to IBRS (BZ#2213367)

  • Hyper-V RHEL-8: Fix VM crash/hang Issues due to fast VF add/remove events (BZ#2216544)