RHSA-2023:0496: Important: kernel security and bug fix update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: memory corruption in AX88179178A based USB ethernet device. (CVE-2022-2964) kernel: i915: Incorrect GPU TLB flush can lead to random memory access (CVE-2022-4139) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): fix for "CoW after fork() issue" aka "vmsplice child -> parent attack" aka "GUP after fork bug" (BZ#2137547) After upgrading to ocp4.11.1, our dpdk application using vlan strip offload is not working (BZ#2138207) i40e sriov virtual functions not created (BZ#2140103) net/ice: VIRTCHNLOPCONFIGVSIQUEUES command handling failure with in-tree driver (BZ#2142019) HPE: Premature swapping with swappiness=0 while there’s still plenty of pagecache to be reclaimed. (BZ#2151634) The "kernel BUG at mm/usercopy.c:103!" from BZ 2041529 is back on rhel-8.5 (BZ#2153232) Azure: Sometimes newly deployed VMs are not getting accelerated network during provisioning (BZ#2155274) Azure: VM Deployment Failures Patch Request (BZ#2155282) RHEL 8.8: Backport upstream patches to reduce memory cgroup memory consumption and OOM problem (BZ#2157924) RHEL 8.5: Backport upstream memory cgroup commits up to v5.12 (BZ#2158049)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-abi-stableliststo a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-docto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-s390xto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-zfcpdumpto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-zfcpdump-coreto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-zfcpdump-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-zfcpdump-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-zfcpdump-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-zfcpdump-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64leto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-debuginfo-common-aarch64to a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4.aa - Upgrade
Upgrade
bpftoolto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
kernelto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
kernel-abi-stableliststo a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
kernel-coreto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
kernel-cross-headersto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
kernel-debugto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
kernel-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
kernel-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
kernel-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
kernel-debuginfo-common-aarch64to a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
kernel-debuginfo-common-ppc64leto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
kernel-debuginfo-common-x86_64to a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
kernel-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
kernel-docto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
kernel-headersto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
kernel-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
kernel-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
kernel-toolsto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
kernel-tools-libsto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
perfto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
python3-perfto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4 - Upgrade
Upgrade
bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.76.1.el8_4
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:0496?
The severity of RHSA-2023:0496 is categorized as important, indicating a significant risk to the system.
How do I fix RHSA-2023:0496?
To resolve RHSA-2023:0496, you should update to the kernel package version 4.18.0-305.76.1.el8_4 or later.
Which kernel vulnerabilities does RHSA-2023:0496 address?
RHSA-2023:0496 addresses vulnerabilities related to memory corruption in AX88179_178A USB ethernet devices and incorrect GPU TLB flushes in i915.
What systems are affected by RHSA-2023:0496?
RHSA-2023:0496 affects multiple packages including kernel, bpftool, and their respective debuginfo packages across various architectures.
Is a system reboot required after applying RHSA-2023:0496?
Yes, a system reboot is required for changes to take effect after applying the updates from RHSA-2023:0496.