RHSA-2023:1471: Important: kpatch-patch security update
This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.Security Fix(es): kernel: tun: avoid double free in tunfreenetdev (CVE-2022-4744) ALSA: pcm: Move rwsem lock inside sndctlelemread to prevent UAF (CVE-2023-0266) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:1471?
The severity of RHSA-2023:1471 is classified as important.
What vulnerabilities are addressed by RHSA-2023:1471?
RHSA-2023:1471 addresses a double free vulnerability in tun_free_netdev (CVE-2022-4744) among other issues.
How do I fix RHSA-2023:1471?
To fix RHSA-2023:1471, you should upgrade to the recommended kpatch-patch versions provided in the advisory.
Which software packages are affected by RHSA-2023:1471?
The affected software packages under RHSA-2023:1471 include various versions of the kpatch-patch package.
Is there a specific version to update to for RHSA-2023:1471?
Yes, you should update to kpatch-patch versions at or above 5_14_0-162_12_1-1-2.el9_1 for a security fix.