Lucene search

K
redhatRedHatRHSA-2024:1882
HistoryApr 18, 2024 - 12:58 a.m.

(RHSA-2024:1882) Important: kernel-rt security and bug fix update

2024-04-1800:58:57
access.redhat.com
9
real time linux kernel
security fix
bug fix
rsa decryption
tls
stack corruption
async decrypt
crypto requests
jira
rhel-9.2
cve-2023-6240
cve-2024-26582
cve-2024-26584
cve-2024-26586
rhel-29214
rhel-30439
rhel-26399
rhel-29687
rhel-30451

7.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

46.6%

The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.

Security Fix(es):

  • kernel: Marvin vulnerability side-channel leakage in the RSA decryption operation (CVE-2023-6240)

  • kernel: tls: use-after-free with partial reads and async decrypt (CVE-2024-26582)

  • kernel: tls: handle backlogging of crypto requests (CVE-2024-26584)

  • kernel: mlxsw: spectrum_acl_tcam: Fix stack corruption (CVE-2024-26586)

Bug Fix(es):

  • kernel-rt: kernel: mlxsw: spectrum_acl_tcam: Fix stack corruption (JIRA:RHEL-29214)

  • kernel-rt: update RT source tree to the latest RHEL-9.2 ad hoc schedule build (JIRA:RHEL-30439)

  • kernel-rt: kernel: tls: use-after-free with partial reads and async decrypt (JIRA:RHEL-26399)

  • kernel-rt: kernel: Marvin vulnerability side-channel leakage in the RSA decryption operation (JIRA:RHEL-29687)

  • kernel-rt: kernel: tls: handle backlogging of crypto requests (JIRA:RHEL-30451)