RHSA-2023:1469: Important: kernel-rt security and bug fix update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): kernel: tun: avoid double free in tunfreenetdev (CVE-2022-4744) ALSA: pcm: Move rwsem lock inside sndctlelemread to prevent UAF (CVE-2023-0266) kernel: net: CPU soft lockup in TC mirred egress-to-ingress action (CVE-2022-4269) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): kernel-rt: update RT source tree to the latest RHEL-9.1.z3 Batch (BZ#2170460)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:1469?
RHSA-2023:1469 addresses a security vulnerability in the kernel-rt package that has been classified as critical due to its potential impact on system stability and security.
What vulnerability does RHSA-2023:1469 fix?
RHSA-2023:1469 fixes a double free vulnerability in the tun_free_netdev function, identified as CVE-2022-4744.
How do I fix RHSA-2023:1469?
To fix RHSA-2023:1469, update the kernel-rt and related packages to version 5.14.0-162.22.2.rt21.186.el9_1.
Which packages are affected by RHSA-2023:1469?
RHSA-2023:1469 affects multiple kernel-rt packages, including kernel-rt, kernel-rt-core, and kernel-rt-debug for Red Hat Enterprise Linux 9.1.
What systems are impacted by RHSA-2023:1469?
Systems running the Real Time Linux Kernel packages on Red Hat Enterprise Linux version 9.1 are impacted by RHSA-2023:1469.