Moderate: kernel security update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: net/smc: fix illegal rmb_desc access in SMC-D connection dump (CVE-2024-26615) * kernel: block: initialize integrity buffer to zero before writing it to media (CVE-2024-43854) * kernel: iommu: Restore lost return in iommu_report_device_fault() (CVE-2024-44994) * kernel: netfilter: flowtable: initialise extack before use (CVE-2024-45018) * kernel: selinux,smack: don't bypass permissions check in inode_setsecctx hook (CVE-2024-46695) * kernel: net: avoid potential underflow in qdisc_pkt_len_init() with UFO (CVE-2024-49949) * kernel: netfilter: nft_payload: sanitize offset and length before calling skb_checksum() (CVE-2024-50251) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: net/smc: fix illegal rmb_desc access in SMC-D connection dump (CVE-2024-26615) * kernel: block: initialize integrity buffer to zero before writing it to media (CVE-2024-43854) * kernel: iommu: Restore lost return in iommu_report_device_fault() (CVE-2024-44994) * kernel: netfilter: flowtable: initialise extack before use (CVE-2024-45018) * kernel: selinux,smack: don't bypass permissions check in inode_setsecctx hook (CVE-2024-46695) * kernel: net: avoid potential underflow in qdisc_pkt_len_init() with UFO (CVE-2024-49949) * kernel: netfilter: nft_payload: sanitize offset and length before calling skb_checksum() (CVE-2024-50251) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2024:10939
- https://access.redhat.com/security/cve/CVE-2024-26615
- https://access.redhat.com/security/cve/CVE-2024-43854
- https://access.redhat.com/security/cve/CVE-2024-44994
- https://access.redhat.com/security/cve/CVE-2024-45018
- https://access.redhat.com/security/cve/CVE-2024-46695
- https://access.redhat.com/security/cve/CVE-2024-49949
- https://access.redhat.com/security/cve/CVE-2024-50251
- https://bugzilla.redhat.com/2267355
- https://bugzilla.redhat.com/2309857
- https://bugzilla.redhat.com/2311715
- https://bugzilla.redhat.com/2312083
- https://bugzilla.redhat.com/2320505
- https://bugzilla.redhat.com/2324886
- https://errata.almalinux.org/9/ALSA-2024-10939.html