ALT-PU-2024-1031-1
Package kernel-image-centos updated to version 5.14.0.403-alt1.el9 for branch sisyphus in task 337690.
Closed vulnerabilities
BDU:2023-07513
Уязвимость функции io_uring_show_fdinfo() в модуле io_uring/fdinfo.c подсистемы io_uring ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2023-08130
Уязвимость функции nvmet_ctrl_find_get() в модуле drivers/nvme/target/core.c подсистемы NVMe-oF/TCP ядра операционной системы Linux, позволяющая нарушителю получить доступ к защищаемой информации
Modified: 2024-11-21
CVE-2023-46862
An issue was discovered in the Linux kernel through 6.5.9. During a race with SQ thread exit, an io_uring/fdinfo.c io_uring_show_fdinfo NULL pointer dereference can occur.
- https://bugzilla.kernel.org/show_bug.cgi?id=218032#c4
- https://bugzilla.kernel.org/show_bug.cgi?id=218032#c4
- https://github.com/torvalds/linux/commit/7644b1a1c9a7ae8ab99175989bfc8676055edb46
- https://github.com/torvalds/linux/commit/7644b1a1c9a7ae8ab99175989bfc8676055edb46
- [debian-lts-announce] 20240111 [SECURITY] [DLA 3711-1] linux-5.10 security update
- [debian-lts-announce] 20240111 [SECURITY] [DLA 3711-1] linux-5.10 security update
Modified: 2024-11-21
CVE-2023-6121
An out-of-bounds read vulnerability was found in the NVMe-oF/TCP subsystem in the Linux kernel. This issue may allow a remote attacker to send a crafted TCP packet, triggering a heap-based buffer overflow that results in kmalloc data being printed and potentially leaked to the kernel ring buffer (dmesg).
Modified: 2024-11-21
CVE-2023-6679
A null pointer dereference vulnerability was found in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.c in the Digital Phase Locked Loop (DPLL) subsystem in the Linux kernel. This issue could be exploited to trigger a denial of service.
- RHSA-2024:0439
- RHSA-2024:0439
- RHSA-2024:0448
- RHSA-2024:0448
- RHSA-2024:0461
- RHSA-2024:0461
- https://access.redhat.com/security/cve/CVE-2023-6679
- https://access.redhat.com/security/cve/CVE-2023-6679
- RHBZ#2253986
- RHBZ#2253986
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7LSPIOMIJYTLZB6QKPQVVAYSUETUWKPF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LBVHM4LGMFIHBN4UBESYRFMYX3WUICV5/
- https://lore.kernel.org/netdev/20231211083758.1082853-1-jiri@resnulli.us/
- https://lore.kernel.org/netdev/20231211083758.1082853-1-jiri@resnulli.us/