Red Hat Security Advisory: kpatch-patch-5_14_0-70_112_1, kpatch-patch-5_14_0-70_121_1, kpatch-patch-5_14_0-70_124_1, and kpatch-patch-5_14_0-70_85_1 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-52922 — kernel: can: bcm: Fix UAF in bcm_proc_show()
🎯 Affected products29
- Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_112_1-0:1-4.el9_0.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_112_1-0:1-4.el9_0.src as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_112_1-0:1-4.el9_0.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_112_1-debuginfo-0:1-4.el9_0.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_112_1-debuginfo-0:1-4.el9_0.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_112_1-debugsource-0:1-4.el9_0.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_112_1-debugsource-0:1-4.el9_0.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_121_1-0:1-3.el9_0.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_121_1-0:1-3.el9_0.src as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_121_1-0:1-3.el9_0.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_121_1-debuginfo-0:1-3.el9_0.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_121_1-debuginfo-0:1-3.el9_0.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_121_1-debugsource-0:1-3.el9_0.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_121_1-debugsource-0:1-3.el9_0.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_124_1-0:1-1.el9_0.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_124_1-0:1-1.el9_0.src as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_124_1-0:1-1.el9_0.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_124_1-debuginfo-0:1-1.el9_0.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_124_1-debuginfo-0:1-1.el9_0.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_124_1-debugsource-0:1-1.el9_0.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_124_1-debugsource-0:1-1.el9_0.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_85_1-0:1-8.el9_0.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_85_1-0:1-8.el9_0.src as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_85_1-0:1-8.el9_0.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_85_1-debuginfo-0:1-8.el9_0.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_85_1-debuginfo-0:1-8.el9_0.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_85_1-debugsource-0:1-8.el9_0.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
- kpatch-patch-5_14_0-70_85_1-debugsource-0:1-8.el9_0.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.0)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: To mitigate this vulnerability, prevent the `bcm` kernel module from loading by blacklisting it. Create a file named `/etc/modprobe.d/blacklist-bcm.conf` with the following content: ``` blacklist bcm ``` After creating the file, regenerate the initramfs and reboot the system for the changes to take effect. This mitigation may impact systems that rely on CAN BCM functionality. If CAN BCM is required, this mitigation is not suitable. A system reboot is required for the changes to take effect.