Release Info

Advisory: CLSA-2024:1727167500

OS: CentOS 7 ELS

Public date: 2024-09-24 04:45:03

Project: kernel

Version: 3.10.0-1160.119.1.el7.tuxcare.els7

Errata link: https://errata.tuxcare.com/els_os/centos7els/CLSA-2024-1727167500.html

Changelog

- wifi: mac80211: Avoid address calculations via out of bounds array indexing {CVE-2024-41071} - bnx2x: Fix multiple UBSAN array-index-out-of-bounds {CVE-2024-42148} - exec: Fix ToCToU between perm check and set-uid/gid usage {CVE-2024-43882} - scsi: aacraid: Fix double-free on probe failure {CVE-2024-46673} - ipv6: prevent UAF in ip6_send_skb() {CVE-2024-44987} - fou: remove warn in gue_gro_receive on unsupported protocol {CVE-2024-44940} - media: xc2028: avoid use-after-free in load_firmware_cb() {CVE-2024-43900} - dev/parport: fix the array out-of-bounds risk {CVE-2024-42301} - mISDN: Fix a use after free in hfcmulti_tx() {CVE-2024-42280} - netfilter: nftables: exthdr: fix 4-byte stack OOB write {CVE-2023-52628} - Bluetooth: af_bluetooth: Fix Use-After-Free in bt_sock_recvmsg {CVE-2023-51779}

Update

Update command: yum update kernel*

Packages list

bpftool-3.10.0-1160.119.1.el7.tuxcare.els7.x86_64.rpm kernel-3.10.0-1160.119.1.el7.tuxcare.els7.x86_64.rpm kernel-debug-3.10.0-1160.119.1.el7.tuxcare.els7.x86_64.rpm kernel-debug-devel-3.10.0-1160.119.1.el7.tuxcare.els7.x86_64.rpm kernel-devel-3.10.0-1160.119.1.el7.tuxcare.els7.x86_64.rpm kernel-headers-3.10.0-1160.119.1.el7.tuxcare.els7.x86_64.rpm kernel-tools-3.10.0-1160.119.1.el7.tuxcare.els7.x86_64.rpm kernel-tools-libs-3.10.0-1160.119.1.el7.tuxcare.els7.x86_64.rpm kernel-tools-libs-devel-3.10.0-1160.119.1.el7.tuxcare.els7.x86_64.rpm perf-3.10.0-1160.119.1.el7.tuxcare.els7.x86_64.rpm python-perf-3.10.0-1160.119.1.el7.tuxcare.els7.x86_64.rpm

CVEs

CVE-2024-42148
CVE-2024-44940
CVE-2024-41071
CVE-2024-44987
CVE-2024-42280
CVE-2024-43882
CVE-2023-51779
CVE-2023-52628
CVE-2024-42301
CVE-2024-43900
CVE-2024-46673