RHSA-2023:5580: Important: kpatch-patch security update
Important: kpatch-patch security update
Other sources
This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel.Security Fix(es): kernel: use-after-free in l2capconnect and l2capleconnectreq in net/bluetooth/l2capcore.c (CVE-2022-42896) kernel: net/sched: Use-after-free vulnerabilities in the net/sched classifiers: clsfw, clsu32 and clsroute (CVE-2023-4128) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:5580?
The severity of RHSA-2023:5580 is high.
What software is affected by RHSA-2023:5580?
The kpatch-patch package with version 4_18_0-193_100_1-1-4.el8_2 and other versions are affected.
How do I fix RHSA-2023:5580?
To fix RHSA-2023:5580, update the kpatch-patch package to version 4_18_0-193_100_1-1-4.el8_2 or later.
Where can I find more information about RHSA-2023:5580?
You can find more information about RHSA-2023:5580 on the Red Hat Bugzilla website and the Red Hat Security Updates website.
What is the Common Weakness Enumeration (CWE) for RHSA-2023:5580?
The Common Weakness Enumeration (CWE) for RHSA-2023:5580 is CWE-416.