Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:5235 - Security Advisory
Issued:
2023-09-19
Updated:
2023-09-19

RHSA-2023:5235 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: kpatch-patch security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for kpatch-patch is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.

Security Fix(es):

  • kernel: UAF in nftables when nft_set_lookup_global triggered after handling named and anonymous sets in batch requests (CVE-2023-3390)
  • kernel: net/sched: Use-after-free vulnerabilities in the net/sched classifiers: cls_fw, cls_u32 and cls_route (CVE-2023-4128)
  • kernel: nf_tables: stack-out-of-bounds-read in nft_byteorder_eval() (CVE-2023-35001)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.1 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.1 x86_64

Fixes

  • BZ - 2213260 - CVE-2023-3390 kernel: UAF in nftables when nft_set_lookup_global triggered after handling named and anonymous sets in batch requests
  • BZ - 2220892 - CVE-2023-35001 kernel: nf_tables: stack-out-of-bounds-read in nft_byteorder_eval()
  • BZ - 2225511 - CVE-2023-4128 Kernel: net/sched: Use-after-free vulnerabilities in the net/sched classifiers: cls_fw, cls_u32 and cls_route

CVEs

  • CVE-2023-3390
  • CVE-2023-4128
  • CVE-2023-35001

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.1

SRPM
kpatch-patch-4_18_0-147_80_1-1-6.el8_1.src.rpm SHA-256: 97ae3a74db188cfb26930cb6394e3f268f1c03336db7c2590d5b219af888f7b0
kpatch-patch-4_18_0-147_81_1-1-5.el8_1.src.rpm SHA-256: 31ea300e25e5fe46f7e23421a2f0410fe4814f08c0893da574992112b686e66e
kpatch-patch-4_18_0-147_83_1-1-4.el8_1.src.rpm SHA-256: 3d5ee99a3e4780ee542fe9995872946a5e0c24d3f1067f57b22b3ad1548773ae
kpatch-patch-4_18_0-147_85_1-1-2.el8_1.src.rpm SHA-256: 361c36bbe0191239f3d0a528693bc2d65230a07e6a5b3ce6d012032042dabc54
kpatch-patch-4_18_0-147_87_1-1-1.el8_1.src.rpm SHA-256: 9ee466bd113f33c9ed67093372c839da395e1430b78036bc9ebb2cdcc783e300
ppc64le
kpatch-patch-4_18_0-147_80_1-1-6.el8_1.ppc64le.rpm SHA-256: d07817e3056f097588b45a70dc957cd352ae50f7d3bb6222309caa113eb19b28
kpatch-patch-4_18_0-147_80_1-debuginfo-1-6.el8_1.ppc64le.rpm SHA-256: 80f3505a76b546e377cedecd8616bf5e87701b0ffd2f3363026be5d8033a20ba
kpatch-patch-4_18_0-147_80_1-debugsource-1-6.el8_1.ppc64le.rpm SHA-256: ab620a1ab09cde3d365fd56826c56118b0cb58070ddeb9d561ccc36fb6cf9263
kpatch-patch-4_18_0-147_81_1-1-5.el8_1.ppc64le.rpm SHA-256: 337711152291c6965ea029b3db7de4907c59126bb72b3aaf92e850060126ff6c
kpatch-patch-4_18_0-147_81_1-debuginfo-1-5.el8_1.ppc64le.rpm SHA-256: fa2d29abd3c8a13759e79c326958e67b7d1d1cc4a2e1372ffe15aa5572293d31
kpatch-patch-4_18_0-147_81_1-debugsource-1-5.el8_1.ppc64le.rpm SHA-256: 101c33f8449da99a7b3a9786b64d2055ae195e9cee1a45b27fcb0496fcb0fb66
kpatch-patch-4_18_0-147_83_1-1-4.el8_1.ppc64le.rpm SHA-256: 25a138b4b86e7f6842f02bced90888b6f4725ffdd628d67cc3af2f951b1f9910
kpatch-patch-4_18_0-147_83_1-debuginfo-1-4.el8_1.ppc64le.rpm SHA-256: c1d0cb83e16fd50c188df9e70d868eb561e98463d93f6edf989e317e714c3de2
kpatch-patch-4_18_0-147_83_1-debugsource-1-4.el8_1.ppc64le.rpm SHA-256: db59cfae2ffe72f41645d966130c9fb4d1dd02db7056d9f1edfea0dde645b1b9
kpatch-patch-4_18_0-147_85_1-1-2.el8_1.ppc64le.rpm SHA-256: 3386ed5e5877877c359cabc5a1fcd5aefb043d4f4d673abccf3818c59f86035d
kpatch-patch-4_18_0-147_85_1-debuginfo-1-2.el8_1.ppc64le.rpm SHA-256: fe2aa28d645b60b4b782455571462546e7234af4885be5d121a061a366437d55
kpatch-patch-4_18_0-147_85_1-debugsource-1-2.el8_1.ppc64le.rpm SHA-256: 80ccdce8e1815a7b947456752db5de7afd3ef048271bf67df1bdbe7b63f082c8
kpatch-patch-4_18_0-147_87_1-1-1.el8_1.ppc64le.rpm SHA-256: 65bc0632dc73930a31a0a94bcd799572a30d2dff638dd68341b95f137617e324
kpatch-patch-4_18_0-147_87_1-debuginfo-1-1.el8_1.ppc64le.rpm SHA-256: ee77319e138363dc9d2e0b57a5e4c792948758120a9d319b507b8f0cad984a31
kpatch-patch-4_18_0-147_87_1-debugsource-1-1.el8_1.ppc64le.rpm SHA-256: a8db99d201e044e0df06fb84f6b3c455a62914f5cd06375614b583d04d671dbf

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.1

SRPM
kpatch-patch-4_18_0-147_80_1-1-6.el8_1.src.rpm SHA-256: 97ae3a74db188cfb26930cb6394e3f268f1c03336db7c2590d5b219af888f7b0
kpatch-patch-4_18_0-147_81_1-1-5.el8_1.src.rpm SHA-256: 31ea300e25e5fe46f7e23421a2f0410fe4814f08c0893da574992112b686e66e
kpatch-patch-4_18_0-147_83_1-1-4.el8_1.src.rpm SHA-256: 3d5ee99a3e4780ee542fe9995872946a5e0c24d3f1067f57b22b3ad1548773ae
kpatch-patch-4_18_0-147_85_1-1-2.el8_1.src.rpm SHA-256: 361c36bbe0191239f3d0a528693bc2d65230a07e6a5b3ce6d012032042dabc54
kpatch-patch-4_18_0-147_87_1-1-1.el8_1.src.rpm SHA-256: 9ee466bd113f33c9ed67093372c839da395e1430b78036bc9ebb2cdcc783e300
x86_64
kpatch-patch-4_18_0-147_80_1-1-6.el8_1.x86_64.rpm SHA-256: 7ed927bd3329f5558f0cdf5699cb554756656fe020be5d76297505a35e23c713
kpatch-patch-4_18_0-147_80_1-debuginfo-1-6.el8_1.x86_64.rpm SHA-256: 7fb803ec8697ed187f76a1c133b22d862045e35bebddd4d560408e1d38e024ab
kpatch-patch-4_18_0-147_80_1-debugsource-1-6.el8_1.x86_64.rpm SHA-256: 7c44034d6a8b568f723ff0c9aeaba61e890224d6ad5b65ddd05c7738c97b0925
kpatch-patch-4_18_0-147_81_1-1-5.el8_1.x86_64.rpm SHA-256: 8f38527198057d42e417e960023bb71c31b98d5f7ef9cee63aebcf8c93e20a73
kpatch-patch-4_18_0-147_81_1-debuginfo-1-5.el8_1.x86_64.rpm SHA-256: c12f0ae3e993f0593b985ad0f0a0e49eec68a814c99c0d319ecc6c565dd93609
kpatch-patch-4_18_0-147_81_1-debugsource-1-5.el8_1.x86_64.rpm SHA-256: a77892e84125a660bc762be70e583c8b39ead9655fd9232bdfbccabbe7d80aee
kpatch-patch-4_18_0-147_83_1-1-4.el8_1.x86_64.rpm SHA-256: 625f34f357ece0c192137274dc9b0f167077e2f4a82a3e2c2acab773b6ff6f78
kpatch-patch-4_18_0-147_83_1-debuginfo-1-4.el8_1.x86_64.rpm SHA-256: 3334f252564b80df95933f6dbaef9fd22c37acf4fd6aeb8e0ebd5d277eb47f89
kpatch-patch-4_18_0-147_83_1-debugsource-1-4.el8_1.x86_64.rpm SHA-256: 836fc70c70b8a183eb0b98e068dbba04b812b753cb9dfab9d4a240d05f2c2262
kpatch-patch-4_18_0-147_85_1-1-2.el8_1.x86_64.rpm SHA-256: 8ee2a4aa761a28f338a7d4e54c8bcf7652d2ad910c51c4ab713dabd9644d3d20
kpatch-patch-4_18_0-147_85_1-debuginfo-1-2.el8_1.x86_64.rpm SHA-256: 94791373008c45d855fd390e902edd30a0783314e96e9f084e27b8f38f911870
kpatch-patch-4_18_0-147_85_1-debugsource-1-2.el8_1.x86_64.rpm SHA-256: 417fe283e07d39b9907ed45745104954d75a4b4e7b8434747a8ddaf9ba373daa
kpatch-patch-4_18_0-147_87_1-1-1.el8_1.x86_64.rpm SHA-256: 9409d8273782c168df3ecc4c0709bae73248f4e89e7ea7488fb3ea1d1ae421a4
kpatch-patch-4_18_0-147_87_1-debuginfo-1-1.el8_1.x86_64.rpm SHA-256: b3f00203df74236dcf939bb347fce370d80dab12667c12eb13c6e5740369b1d4
kpatch-patch-4_18_0-147_87_1-debugsource-1-1.el8_1.x86_64.rpm SHA-256: 7aa55b2d005dc9dc83561e4e2631c4d1c0bac5f9805c62c15ddbf9f7f858743e

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility