Release Info

Advisory: CLSA-2024:1719933179

OS: CentOS 8.5 ELS

Public date: 2024-07-02 11:13:02

Project: kernel

Version: 4.18.0-348.7.1.el8_5.tuxcare.els17

Errata link: https://errata.tuxcare.com/els_os/centos8.5els/CLSA-2024-1719933179.html

Changelog

- net: ip_tunnel: make sure to pull inner header in ip_tunnel_rcv() {CVE-2024-26882} - net: Set true network header for ECN decapsulation {CVE-2024-26882} - media: dvb-core: Fix use-after-free due to race at dvb_register_device() {CVE-2022-45884} - media: dvbdev: fix error logic at dvb_register_device() {CVE-2022-45884} - media: dvbdev: Fix memleak in dvb_register_device {CVE-2022-45884} - media: media/dvb: Use kmemdup rather than duplicating its implementation {CVE-2022-45884} - media: dvbdev: drop refcount on error path in dvb_device_open() {CVE-2022-45884} - media: dvbdev: fix refcnt bug {CVE-2022-45884} - media: dvbdev: adopts refcnt to avoid UAF {CVE-2022-45884} - netfilter: nf_tables: Fix potential data-race in __nft_expr_type_get() {CVE-2024-27020} - netfilter: nf_tables: __nft_expr_type_get() selects specific family type {CVE-2024-27020} - scsi: qla2xxx: Fix double free of fcport {CVE-2024-26929} - of: fdt: fix off-by-one error in unflatten_dt_nodes() {CVE-2022-48672} - USB: core: Fix deadlock in usb_deauthorize_interface() {CVE-2024-26934} - smb: client: fix use-after-free bug in cifs_debug_data_proc_show() {CVE-2023-52752} - netfilter: nf_tables: disallow anonymous set with timeout flag {CVE-2024-26642} - media: technisat-usb2: break out of loop at end of buffer {CVE-2019-15505} - Input: gtco - bounds check collection indent level {CVE-2019-13631} - ext4: fix kernel infoleak via ext4_extent_header {CVE-2022-0850} - media: uvcvideo: Avoid cyclic entity chains due to malformed USB descriptors {CVE-2020-0404} - netfilter: nft_set_pipapo: skip inactive elements during set walk {CVE-2023-6817} - libceph: harden msgr2.1 frame segment length checks {CVE-2023-44466} - media: dvb-core: Fix kernel WARNING for blocking operation in wait_event*() {CVE-2023-31084} - dm ioctl: fix nested locking in table_clear() to remove deadlock concern {CVE-2023-2269} - hwmon: (xgene) Fix use after free bug in xgene_hwmon_remove due to race condition {CVE-2023-1855} - RDMA/core: Don't infoleak GRH fields {CVE-2021-3923} - HID: betop: check shape of output reports {CVE-2023-1073} - HID: betop: fix slab-out-of-bounds Write in betop_probe {CVE-2023-1073} - HID: check empty report_list in hid_validate_values() {CVE-2023-1073} - media: ttusb-dec: fix memory leak in ttusb_dec_exit_dvb() {CVE-2022-45887}

Update

Update command: dnf update kernel*

Packages list

bpftool-4.18.0-348.7.1.el8_5.tuxcare.els17.x86_64.rpm kernel-4.18.0-348.7.1.el8_5.tuxcare.els17.x86_64.rpm kernel-core-4.18.0-348.7.1.el8_5.tuxcare.els17.x86_64.rpm kernel-cross-headers-4.18.0-348.7.1.el8_5.tuxcare.els17.x86_64.rpm kernel-debug-4.18.0-348.7.1.el8_5.tuxcare.els17.x86_64.rpm kernel-debug-core-4.18.0-348.7.1.el8_5.tuxcare.els17.x86_64.rpm kernel-debug-devel-4.18.0-348.7.1.el8_5.tuxcare.els17.x86_64.rpm kernel-debug-modules-4.18.0-348.7.1.el8_5.tuxcare.els17.x86_64.rpm kernel-debug-modules-extra-4.18.0-348.7.1.el8_5.tuxcare.els17.x86_64.rpm kernel-debug-modules-internal-4.18.0-348.7.1.el8_5.tuxcare.els17.x86_64.rpm kernel-devel-4.18.0-348.7.1.el8_5.tuxcare.els17.x86_64.rpm kernel-headers-4.18.0-348.7.1.el8_5.tuxcare.els17.x86_64.rpm kernel-ipaclones-internal-4.18.0-348.7.1.el8_5.tuxcare.els17.x86_64.rpm kernel-modules-4.18.0-348.7.1.el8_5.tuxcare.els17.x86_64.rpm kernel-modules-extra-4.18.0-348.7.1.el8_5.tuxcare.els17.x86_64.rpm kernel-modules-internal-4.18.0-348.7.1.el8_5.tuxcare.els17.x86_64.rpm kernel-selftests-internal-4.18.0-348.7.1.el8_5.tuxcare.els17.x86_64.rpm kernel-tools-4.18.0-348.7.1.el8_5.tuxcare.els17.x86_64.rpm kernel-tools-libs-4.18.0-348.7.1.el8_5.tuxcare.els17.x86_64.rpm kernel-tools-libs-devel-4.18.0-348.7.1.el8_5.tuxcare.els17.x86_64.rpm perf-4.18.0-348.7.1.el8_5.tuxcare.els17.x86_64.rpm python3-perf-4.18.0-348.7.1.el8_5.tuxcare.els17.x86_64.rpm

CVEs

CVE-2024-27020
CVE-2023-1855
CVE-2024-26642
CVE-2022-0850
CVE-2021-3923
CVE-2022-45884
CVE-2023-44466
CVE-2024-26934
CVE-2023-31084
CVE-2019-13631
CVE-2024-26929
CVE-2024-26882
CVE-2022-48672
CVE-2020-0404
CVE-2023-1073
CVE-2023-6817
CVE-2019-15505
CVE-2023-2269
CVE-2022-45887