Lucene search

K
redhatRedHatRHSA-2024:5282
HistoryAug 13, 2024 - 2:21 p.m.

(RHSA-2024:5282) Important: kernel-rt security update

2024-08-1314:21:27
access.redhat.com
11
kernel-rt
real time linux kernel
netfilter
network route management
use after netif_napi_del()
nfsd
rhel-8.4.z batch 27

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.2

Confidence

Low

The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.

Security Fix(es):

  • kernel: netfilter: nf_tables: honor table dormant flag from netdev release event path (CVE-2024-36005)

  • kernel: net: CVE-2024-36971 kernel: UAF in network route management (CVE-2024-36971)

  • kernel: ionic: fix use after netif_napi_del() (CVE-2024-39502)

  • kernel: NFSD: Fix the behavior of READ near OFFSET_MAX (CVE-2022-48827)

  • kernel: NFSD: Fix ia_size underflow (CVE-2022-48828)

  • kernel: NFSD: Fix NFSv3 SETATTR/CREATE's handling of large file sizes (CVE-2022-48829)

Bug Fix(es):

  • kernel-rt: update RT source tree to the latest RHEL-8.4.z Batch 27 (JIRA:RHEL-50526)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer the CVE page(s) listed in the References section.

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.2

Confidence

Low