- Issued:
- 2023-08-01
- Updated:
- 2023-08-01
RHSA-2023:4378 - Security Advisory
Synopsis
Important: kernel-rt security and bug fix update
Type/Severity
Security Advisory: Important
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
Topic
An update for kernel-rt is now available for Red Hat Enterprise Linux 9.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.
Security Fix(es):
- kernel: ipvlan: out-of-bounds write caused by unclear skb->cb (CVE-2023-3090)
- kernel: cls_flower: out-of-bounds write in fl_set_geneve_opt() (CVE-2023-35788)
- kernel: KVM: x86/mmu: race condition in direct_page_fault() (CVE-2022-45869)
- kernel: speculative pointer dereference in do_prlimit() in kernel/sys.c (CVE-2023-0458)
- kernel: Spectre v2 SMT mitigations problem (CVE-2023-1998)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
- RHEL9 rt: blktests block/024 failed (BZ#2209920)
- Backport pinned timers RT specific behavior for FIFO tasks (BZ#2210071)
- kernel-rt: update RT source tree to the RHEL-9.2z2 source tree (BZ#2215122)
- kernel-rt: update RT source tree to the RHEL-9.2z2b source tree (BZ#2222796)
Solution
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258
The system must be rebooted for this update to take effect.
Affected Products
- Red Hat Enterprise Linux for Real Time 9 x86_64
- Red Hat Enterprise Linux for Real Time for NFV 9 x86_64
- Red Hat Enterprise Linux for Real Time for x86_64 - 4 years of updates 9.4 x86_64
- Red Hat Enterprise Linux for Real Time for NFV for x86_64 - 4 years of updates 9.4 x86_64
Fixes
- BZ - 2151317 - CVE-2022-45869 kernel: KVM: x86/mmu: race condition in direct_page_fault()
- BZ - 2187257 - CVE-2023-1998 kernel: Spectre v2 SMT mitigations problem
- BZ - 2193219 - CVE-2023-0458 kernel: speculative pointer dereference in do_prlimit() in kernel/sys.c
- BZ - 2215768 - CVE-2023-35788 kernel: cls_flower: out-of-bounds write in fl_set_geneve_opt()
- BZ - 2218672 - CVE-2023-3090 kernel: ipvlan: out-of-bounds write caused by unclear skb->cb
Red Hat Enterprise Linux for Real Time 9
SRPM | |
---|---|
kernel-rt-5.14.0-284.25.1.rt14.310.el9_2.src.rpm | SHA-256: e65077e4ace45952ff5f3d564cfe8de68b56153b46841d067d445ef106f22df2 |
x86_64 | |
kernel-rt-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: ee3bd78d1c0073173672cde10847d4d9b1ee34a2bfc7de0aaefbff530c163180 |
kernel-rt-core-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: ea8a8a9656f5bde3cf9a5016aec792083a94efcb566e6f029f86aa8404d34d08 |
kernel-rt-debug-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 6e551bfee6972d9c946a8047fdf2815658b8f0ac3ece08840b4384fb21b932b3 |
kernel-rt-debug-core-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: c096332f82d53dce2cd78a8bf93a154897a30e8bad57c5046c2f2cf206583d73 |
kernel-rt-debug-debuginfo-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 655ce69c165604cc451e6e42a2ad81b3e1ee80a085c62388c172b38688e45289 |
kernel-rt-debug-devel-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: ba30b18a247ccd5bb9d58382833ef33c64ea2630594d03bf006015346b5daabc |
kernel-rt-debug-modules-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 1f82e26a47d68dcb00ddabb2e1f79461fe102460494b854b17fa17435dc221a1 |
kernel-rt-debug-modules-core-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 1eb371c30edff32438bb82a42103e7d236d2e6e18f2e9c7186bb4d53f1e2d835 |
kernel-rt-debug-modules-extra-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 332cf5cebf71c1a1533f93f69e9b2738785b8aa9410d018b41e1f8ed43b48627 |
kernel-rt-debuginfo-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: f9720519735186d47f8932df6366291e3f455ffa2a9a7152fef2ccb47cdfae3e |
kernel-rt-debuginfo-common-x86_64-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 963988c1f141eab3d14f9dbe101ddac44f7a5870df5a14e790fda79d44c43386 |
kernel-rt-devel-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 7c9c4f592325eb3da4563ad45be1d5cc4ce31463d721401a1edb5a840748c22d |
kernel-rt-modules-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 09f967e44f11955abd35f0ef9ca74ddc5053e699ed2a5ddce695ef6ac1729e94 |
kernel-rt-modules-core-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 567dd7803b666eb5221a07af7d86404219c8d059f55d8a974ff41078b79cefc2 |
kernel-rt-modules-extra-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 4950171de3314a6e7b09f0603ee6e38f736881c6e52d2423ae317a7902d9afdf |
Red Hat Enterprise Linux for Real Time for NFV 9
SRPM | |
---|---|
kernel-rt-5.14.0-284.25.1.rt14.310.el9_2.src.rpm | SHA-256: e65077e4ace45952ff5f3d564cfe8de68b56153b46841d067d445ef106f22df2 |
x86_64 | |
kernel-rt-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: ee3bd78d1c0073173672cde10847d4d9b1ee34a2bfc7de0aaefbff530c163180 |
kernel-rt-core-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: ea8a8a9656f5bde3cf9a5016aec792083a94efcb566e6f029f86aa8404d34d08 |
kernel-rt-debug-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 6e551bfee6972d9c946a8047fdf2815658b8f0ac3ece08840b4384fb21b932b3 |
kernel-rt-debug-core-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: c096332f82d53dce2cd78a8bf93a154897a30e8bad57c5046c2f2cf206583d73 |
kernel-rt-debug-debuginfo-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 655ce69c165604cc451e6e42a2ad81b3e1ee80a085c62388c172b38688e45289 |
kernel-rt-debug-devel-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: ba30b18a247ccd5bb9d58382833ef33c64ea2630594d03bf006015346b5daabc |
kernel-rt-debug-kvm-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: fe2f3c8f0d862e77b70538bf99a7e77d8a838c4ffdc68376da10e46f1d7c2ee8 |
kernel-rt-debug-modules-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 1f82e26a47d68dcb00ddabb2e1f79461fe102460494b854b17fa17435dc221a1 |
kernel-rt-debug-modules-core-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 1eb371c30edff32438bb82a42103e7d236d2e6e18f2e9c7186bb4d53f1e2d835 |
kernel-rt-debug-modules-extra-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 332cf5cebf71c1a1533f93f69e9b2738785b8aa9410d018b41e1f8ed43b48627 |
kernel-rt-debuginfo-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: f9720519735186d47f8932df6366291e3f455ffa2a9a7152fef2ccb47cdfae3e |
kernel-rt-debuginfo-common-x86_64-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 963988c1f141eab3d14f9dbe101ddac44f7a5870df5a14e790fda79d44c43386 |
kernel-rt-devel-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 7c9c4f592325eb3da4563ad45be1d5cc4ce31463d721401a1edb5a840748c22d |
kernel-rt-kvm-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 8bbd29de92cde9879c9711af67abd6e4805ba2f6e10953b45e297397edde28cb |
kernel-rt-modules-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 09f967e44f11955abd35f0ef9ca74ddc5053e699ed2a5ddce695ef6ac1729e94 |
kernel-rt-modules-core-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 567dd7803b666eb5221a07af7d86404219c8d059f55d8a974ff41078b79cefc2 |
kernel-rt-modules-extra-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 4950171de3314a6e7b09f0603ee6e38f736881c6e52d2423ae317a7902d9afdf |
Red Hat Enterprise Linux for Real Time for x86_64 - 4 years of updates 9.4
SRPM | |
---|---|
kernel-rt-5.14.0-284.25.1.rt14.310.el9_2.src.rpm | SHA-256: e65077e4ace45952ff5f3d564cfe8de68b56153b46841d067d445ef106f22df2 |
x86_64 | |
kernel-rt-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: ee3bd78d1c0073173672cde10847d4d9b1ee34a2bfc7de0aaefbff530c163180 |
kernel-rt-core-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: ea8a8a9656f5bde3cf9a5016aec792083a94efcb566e6f029f86aa8404d34d08 |
kernel-rt-debug-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 6e551bfee6972d9c946a8047fdf2815658b8f0ac3ece08840b4384fb21b932b3 |
kernel-rt-debug-core-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: c096332f82d53dce2cd78a8bf93a154897a30e8bad57c5046c2f2cf206583d73 |
kernel-rt-debug-debuginfo-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 655ce69c165604cc451e6e42a2ad81b3e1ee80a085c62388c172b38688e45289 |
kernel-rt-debug-devel-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: ba30b18a247ccd5bb9d58382833ef33c64ea2630594d03bf006015346b5daabc |
kernel-rt-debug-modules-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 1f82e26a47d68dcb00ddabb2e1f79461fe102460494b854b17fa17435dc221a1 |
kernel-rt-debug-modules-core-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 1eb371c30edff32438bb82a42103e7d236d2e6e18f2e9c7186bb4d53f1e2d835 |
kernel-rt-debug-modules-extra-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 332cf5cebf71c1a1533f93f69e9b2738785b8aa9410d018b41e1f8ed43b48627 |
kernel-rt-debuginfo-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: f9720519735186d47f8932df6366291e3f455ffa2a9a7152fef2ccb47cdfae3e |
kernel-rt-debuginfo-common-x86_64-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 963988c1f141eab3d14f9dbe101ddac44f7a5870df5a14e790fda79d44c43386 |
kernel-rt-devel-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 7c9c4f592325eb3da4563ad45be1d5cc4ce31463d721401a1edb5a840748c22d |
kernel-rt-modules-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 09f967e44f11955abd35f0ef9ca74ddc5053e699ed2a5ddce695ef6ac1729e94 |
kernel-rt-modules-core-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 567dd7803b666eb5221a07af7d86404219c8d059f55d8a974ff41078b79cefc2 |
kernel-rt-modules-extra-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 4950171de3314a6e7b09f0603ee6e38f736881c6e52d2423ae317a7902d9afdf |
Red Hat Enterprise Linux for Real Time for NFV for x86_64 - 4 years of updates 9.4
SRPM | |
---|---|
kernel-rt-5.14.0-284.25.1.rt14.310.el9_2.src.rpm | SHA-256: e65077e4ace45952ff5f3d564cfe8de68b56153b46841d067d445ef106f22df2 |
x86_64 | |
kernel-rt-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: ee3bd78d1c0073173672cde10847d4d9b1ee34a2bfc7de0aaefbff530c163180 |
kernel-rt-core-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: ea8a8a9656f5bde3cf9a5016aec792083a94efcb566e6f029f86aa8404d34d08 |
kernel-rt-debug-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 6e551bfee6972d9c946a8047fdf2815658b8f0ac3ece08840b4384fb21b932b3 |
kernel-rt-debug-core-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: c096332f82d53dce2cd78a8bf93a154897a30e8bad57c5046c2f2cf206583d73 |
kernel-rt-debug-debuginfo-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 655ce69c165604cc451e6e42a2ad81b3e1ee80a085c62388c172b38688e45289 |
kernel-rt-debug-devel-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: ba30b18a247ccd5bb9d58382833ef33c64ea2630594d03bf006015346b5daabc |
kernel-rt-debug-kvm-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: fe2f3c8f0d862e77b70538bf99a7e77d8a838c4ffdc68376da10e46f1d7c2ee8 |
kernel-rt-debug-modules-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 1f82e26a47d68dcb00ddabb2e1f79461fe102460494b854b17fa17435dc221a1 |
kernel-rt-debug-modules-core-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 1eb371c30edff32438bb82a42103e7d236d2e6e18f2e9c7186bb4d53f1e2d835 |
kernel-rt-debug-modules-extra-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 332cf5cebf71c1a1533f93f69e9b2738785b8aa9410d018b41e1f8ed43b48627 |
kernel-rt-debuginfo-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: f9720519735186d47f8932df6366291e3f455ffa2a9a7152fef2ccb47cdfae3e |
kernel-rt-debuginfo-common-x86_64-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 963988c1f141eab3d14f9dbe101ddac44f7a5870df5a14e790fda79d44c43386 |
kernel-rt-devel-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 7c9c4f592325eb3da4563ad45be1d5cc4ce31463d721401a1edb5a840748c22d |
kernel-rt-kvm-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 8bbd29de92cde9879c9711af67abd6e4805ba2f6e10953b45e297397edde28cb |
kernel-rt-modules-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 09f967e44f11955abd35f0ef9ca74ddc5053e699ed2a5ddce695ef6ac1729e94 |
kernel-rt-modules-core-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 567dd7803b666eb5221a07af7d86404219c8d059f55d8a974ff41078b79cefc2 |
kernel-rt-modules-extra-5.14.0-284.25.1.rt14.310.el9_2.x86_64.rpm | SHA-256: 4950171de3314a6e7b09f0603ee6e38f736881c6e52d2423ae317a7902d9afdf |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.