FlawAtlas
Search the atlas
ALSA-2024:0113 Not scored

Important: kernel security update

The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: use after free in unix_stream_sendpage (CVE-2023-4622) * kernel: vmwgfx: reference count issue leads to use-after-free in surface handling (CVE-2023-5633) * kernel: netfilter: potential slab-out-of-bound access due to integer underflow (CVE-2023-42753) * Kernel: UAF during login when accessing the shost ipaddress (CVE-2023-2162) * hw amd: Return Address Predictor vulnerability leading to information disclosure (CVE-2023-20569) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * Backport OVS l4 Symmetric Hashing to almalinux-8 (JIRA:AlmaLinux-12746) * Unbounded memory usage by TCP for receive buffers (JIRA:AlmaLinux-15096) * various kind of guests freeze on rhel 8.8 (JIRA:AlmaLinux-15121) * AlmaLinux 8: netfilter: conntrack: Fix gre tunneling over ipv6 (JIRA:AlmaLinux-15259) * NFSv4.1 needs to handle ENOENT error from GETDEVICEINFO (JIRA:AlmaLinux-16407) * DM multipath showing failed path for an nvme-o-FC LUN when performing I/O operations (JIRA:AlmaLinux-14718)

Exploit probability Not scored
Published January 10, 2024
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

AlmaLinux:8 bpftool
AlmaLinux:8 kernel
AlmaLinux:8 kernel-abi-stablelists
AlmaLinux:8 kernel-core
AlmaLinux:8 kernel-cross-headers
AlmaLinux:8 kernel-debug
AlmaLinux:8 kernel-debug-core
AlmaLinux:8 kernel-debug-devel
AlmaLinux:8 kernel-debug-modules
AlmaLinux:8 kernel-debug-modules-extra
AlmaLinux:8 kernel-devel
AlmaLinux:8 kernel-doc
AlmaLinux:8 kernel-modules
AlmaLinux:8 kernel-modules-extra
AlmaLinux:8 kernel-tools
AlmaLinux:8 kernel-tools-libs
AlmaLinux:8 kernel-tools-libs-devel
AlmaLinux:8 kernel-zfcpdump
AlmaLinux:8 kernel-zfcpdump-core
AlmaLinux:8 kernel-zfcpdump-devel
AlmaLinux:8 kernel-zfcpdump-modules
AlmaLinux:8 kernel-zfcpdump-modules-extra
AlmaLinux:8 perf
AlmaLinux:8 python3-perf

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities ALSA-2024:0113

The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: use after free in unix_stream_sendpage (CVE-2023-4622) * kernel: vmwgfx: reference count issue leads to use-after-free in surface handling (CVE-2023-5633) * kernel: netfilter: potential slab-out-of-bound access due to integer underflow (CVE-2023-42753) * Kernel: UAF during login when accessing the shost ipaddress (CVE-2023-2162) * hw amd: Return Address Predictor vulnerability leading to information disclosure (CVE-2023-20569) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * Backport OVS l4 Symmetric Hashing to almalinux-8 (JIRA:AlmaLinux-12746) * Unbounded memory usage by TCP for receive buffers (JIRA:AlmaLinux-15096) * various kind of guests freeze on rhel 8.8 (JIRA:AlmaLinux-15121) * AlmaLinux 8: netfilter: conntrack: Fix gre tunneling over ipv6 (JIRA:AlmaLinux-15259) * NFSv4.1 needs to handle ENOENT error from GETDEVICEINFO (JIRA:AlmaLinux-16407) * DM multipath showing failed path for an nvme-o-FC LUN when performing I/O operations (JIRA:AlmaLinux-14718)

View original source

05 / REFERENCES

Further evidence