RHSA-2024:8617MediumCVSS 7.1

Red Hat Security Advisory: kernel security update

Published
October 30, 2024
Last Modified
September 13, 2026

🔗 CVE IDs covered (23)

📋 Description

CVE-2021-47383 — kernel: tty: Fix out-of-bound vmalloc access in imageblit CVE-2023-54153 — kernel: ext4: turn quotas off if mount failed after enabling quotas CVE-2024-2201 — hw: cpu: intel: Native Branch History Injection (BHI) CVE-2024-26640 — kernel: tcp: add sanity checks to rx zerocopy CVE-2024-26826 — kernel: mptcp: fix data re-injection from stale subflow CVE-2024-26923 — kernel: af_unix: Fix garbage collector racing against connect() CVE-2024-26935 — kernel: scsi: core: Fix unremoved procfs host directory regression CVE-2024-26961 — kernel: mac802154: fix llsec key resources release in mac802154_llsec_key_del CVE-2024-36244 — kernel: net/sched: taprio: extend minimum interval restriction to entire cycle too CVE-2024-39472 — kernel: xfs: fix log recovery buffer allocation for the legacy h_size fixup CVE-2024-39504 — kernel: netfilter: nft_inner: validate mandatory meta and payload CVE-2024-40904 — kernel: USB: class: cdc-wdm: Fix CPU lockup caused by excessive log messages CVE-2024-40931 — kernel: mptcp: ensure snd_una is properly initialized on connect CVE-2024-40960 — kernel: ipv6: prevent possible NULL dereference in rt6_probe() CVE-2024-40972 — kernel: ext4: do not create EA inode under buffer lock CVE-2024-40977 — kernel: wifi: mt76: mt7921s: fix potential hung tasks during chip recovery CVE-2024-40995 — kernel: net/sched: act_api: fix possible infinite loop in tcf_idr_check_alloc() CVE-2024-40998 — kernel: ext4: fix uninitialized ratelimit_state->lock access in __ext4_fill_super() CVE-2024-41005 — kernel: netpoll: Fix race condition in netpoll_owner_active CVE-2024-41013 — kernel: xfs: don't walk off the end of a directory data block CVE-2024-41014 — kernel: xfs: add bounds checking to xlog_recover_process_data CVE-2024-43854 — kernel: block: initialize integrity buffer to zero before writing it to media CVE-2024-45018 — kernel: netfilter: flowtable: initialise extack before use

🎯 Affected products200

  • Red Hat Enterprise Linux AppStream (v. 9)
  • Red Hat Enterprise Linux BaseOS (v. 9)
  • Red Hat Enterprise Linux CRB (v. 9)
  • Red Hat Enterprise Linux NFV (v. 9)
  • Red Hat Enterprise Linux RT (v. 9)
  • bpftool-0:7.3.0-427.42.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • bpftool-0:7.3.0-427.42.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • bpftool-0:7.3.0-427.42.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • bpftool-0:7.3.0-427.42.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • bpftool-debuginfo-0:7.3.0-427.42.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • bpftool-debuginfo-0:7.3.0-427.42.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • bpftool-debuginfo-0:7.3.0-427.42.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux CRB (v. 9)
  • bpftool-debuginfo-0:7.3.0-427.42.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • bpftool-debuginfo-0:7.3.0-427.42.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • bpftool-debuginfo-0:7.3.0-427.42.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux CRB (v. 9)
  • bpftool-debuginfo-0:7.3.0-427.42.1.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • bpftool-debuginfo-0:7.3.0-427.42.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • bpftool-debuginfo-0:7.3.0-427.42.1.el9_4.s390x as a component of Red Hat Enterprise Linux CRB (v. 9)
  • bpftool-debuginfo-0:7.3.0-427.42.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • bpftool-debuginfo-0:7.3.0-427.42.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • bpftool-debuginfo-0:7.3.0-427.42.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux CRB (v. 9)
  • bpftool-debuginfo-0:7.3.0-427.42.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 9)
  • bpftool-debuginfo-0:7.3.0-427.42.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux RT (v. 9)
  • kernel-0:5.14.0-427.42.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-0:5.14.0-427.42.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-0:5.14.0-427.42.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-0:5.14.0-427.42.1.el9_4.src as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-0:5.14.0-427.42.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-64k-0:5.14.0-427.42.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-64k-core-0:5.14.0-427.42.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • +170 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: There are no known mitigations to this issue and updating to the latest Linux kernel version is recommended to address this vulnerability​. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Fix this issue by adding the __GFP_ZERO flag to allocations for writes. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (24)