RHSA-2023:5575: Important: kpatch-patch security update
Important: kpatch-patch security update
Other sources
This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.Security Fix(es): kernel: net/sched: Use-after-free vulnerabilities in the net/sched classifiers: clsfw, clsu32 and clsroute (CVE-2023-4128) kernel: nftables: use-after-free in nftchainlookupbyid() (CVE-2023-31248) kernel: nftables: stack-out-of-bounds-read in nftbyteordereval() (CVE-2023-35001) kernel: clsflower: out-of-bounds write in flsetgeneveopt() (CVE-2023-35788) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:5575?
RHSA-2023:5575 is classified as important due to its potential impact on system security.
How do I fix RHSA-2023:5575?
To fix RHSA-2023:5575, you should update the kpatch-patch package to a version that includes the security fix, specifically versions 5_14_0-70_49_1-1-6.el9_0 or later.
What vulnerabilities are addressed in RHSA-2023:5575?
RHSA-2023:5575 addresses use-after-free vulnerabilities in the net/sched classifiers.
Which software is affected by RHSA-2023:5575?
Affected software includes various versions of Red Hat Enterprise Linux, particularly for x86_64 and Power LE architectures.
Is there a specific RPM package associated with RHSA-2023:5575?
Yes, the specific RPM package associated with RHSA-2023:5575 is kpatch-patch.