Lucene search

K
redhatRedHatRHSA-2024:0980
HistoryFeb 26, 2024 - 9:13 a.m.

(RHSA-2024:0980) Important: kernel security update

2024-02-2609:13:33
access.redhat.com
14
kernel packages
linux kernel
use-after-free
l2cap_connect
l2cap_le_connect_req
sch_qfq
igb driver
buffer size
cve-2022-42896
cve-2023-4921
cve-2023-45871
security vulnerabilities
cvss score

9.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

50.4%

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: use-after-free in l2cap_connect and l2cap_le_connect_req in net/bluetooth/l2cap_core.c (CVE-2022-42896)

  • kernel: use-after-free in sch_qfq network scheduler (CVE-2023-4921)

  • kernel: IGB driver inadequate buffer size for frames larger than MTU (CVE-2023-45871)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.