Lucene search

K
redhatRedHatRHSA-2024:3460
HistoryMay 29, 2024 - 7:38 a.m.

(RHSA-2024:3460) Moderate: kernel-rt security and bug fix update

2024-05-2907:38:15
access.redhat.com
6
real time linux
security update
bug fix
determinism
netfilter
ipv6
ip tunnel
cifs
sysfs
rhel-9.2

7.4 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.7%

The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.

Security Fix(es):

  • kernel: netfilter: nf_tables: mark set as dead when unbinding anonymous set with timeout (CVE-2024-26643)

  • kernel: netfilter: nf_tables: disallow anonymous set with timeout flag (CVE-2024-26642)

  • kernel: netfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations (CVE-2024-26673)

  • kernel: ipv6: sr: fix possible use-after-free and null-ptr-deref (CVE-2024-26735)

  • kernel: net: ip_tunnel: prevent perpetual headroom growth (CVE-2024-26804)

  • kernel: cifs: fix underflow in parse_server_interfaces() (CVE-2024-26828)

  • kernel: fs: sysfs: Fix reference leak in sysfs_break_active_protection() (CVE-2024-26993)

Bug Fix:

  • kernel-rt: update RT source tree to the latest RHEL-9.2 ad hoc schedule build (JIRA:RHEL-36221)