Lucene search

K
redhatRedHatRHSA-2024:1831
HistoryApr 16, 2024 - 12:09 a.m.

(RHSA-2024:1831) Important: kernel security update

2024-04-1600:09:13
access.redhat.com
43
kernel packages
linux operating system
out-of-bounds write
qfq_change_class
net/sched
sch_qfq
cls_fw
tcf_change_indev
use-after-free

7.3 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

16.1%

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: out-of-bounds write in qfq_change_class function (CVE-2023-31436)
  • kernel: net/sched: sch_qfq component can be exploited if in qfq_change_agg function happens qfq_enqueue overhead (CVE-2023-3611)
  • kernel: net/sched: cls_fw component can be exploited as result of failure in tcf_change_indev function (CVE-2023-3776)
  • kernel: use-after-free in sch_qfq network scheduler (CVE-2023-4921)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.