RHSA-2023:0399: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operating system.<br>Security Fix(es):<br><li> kernel: memory corruption in AX88179178A based USB ethernet device. (CVE-2022-2964)</li> <li> hw: cpu: LFENCE/JMP Mitigation Update for CVE-2017-5715 (CVE-2021-26401)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> Prevent unnecessary resets - Avoid leaving shost->lastreset with stale value if EH does not run (BZ#2128337)</li> <li> i40e: Request to backport upstream commit 2e5a20573a92 (BZ#2129248)</li> <li> disable VMA-based swap-in readahead on PowerPC (BZ#2142455)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:0399?
The severity of RHSA-2023:0399 is classified as critical due to the presence of memory corruption vulnerabilities.
How do I fix RHSA-2023:0399?
To fix RHSA-2023:0399, update the affected kernel packages to version 3.10.0-1160.83.1.el7 or later.
What vulnerabilities are addressed in RHSA-2023:0399?
RHSA-2023:0399 addresses vulnerabilities such as memory corruption in AX88179_178A based USB ethernet devices and CPU security mitigations.
Which software is affected by RHSA-2023:0399?
Affected software includes kernel packages, bpftool, and their associated debuginfo packages in version 3.10.0-1160.83.1.el7.
Is it necessary to apply the update for RHSA-2023:0399 immediately?
Yes, it is recommended to apply the update for RHSA-2023:0399 immediately to mitigate the risk of exploitation.