CVE-2023-35825
Description
RHSA-2023:7077: kernel security, bug fix, and enhancement update (Important)
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
Description kernel: r592: race condition leading to use-after-free in r592_remove() CVSS v3: 6.4 (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 8kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9RHSA-2023:69012023-11-14T00:00:00Z Red Hat Enterprise Linux 8kernel-0:4.18.0-513.5.1.el8_9RHSA-2023:70772023-11-14T00:00:00Z Red Hatβ¦
Description
kernel: r592: race condition leading to use-after-free in r592_remove()
CVSS v3: 6.4 (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)
Errata / fixed releases
| Product | Package | Advisory | Released |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9 | RHSA-2023:6901 | 2023-11-14T00:00:00Z |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-513.5.1.el8_9 | RHSA-2023:7077 | 2023-11-14T00:00:00Z |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.91.1.el8_6 | RHSA-2024:0724 | 2024-02-07T00:00:00Z |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kernel-0:4.18.0-477.43.1.el8_8 | RHSA-2024:0575 | 2024-01-30T00:00:00Z |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.8.1.el9_3 | RHSA-2023:6583 | 2023-11-07T00:00:00Z |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.8.1.el9_3 | RHSA-2023:6583 | 2023-11-07T00:00:00Z |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.91.1.el8_6 | RHSA-2024:0724 | 2024-02-07T00:00:00Z |
Package state
| Product | Package | State |
|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Out of support scope |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected |
Apply commands
yum update -y kernel-rt
# or:
dnf upgrade -y kernel-rt
Affected
| Vendor | Product | Version |
|---|---|---|
| redhat | Red Hat Enterprise Linux 9 | Affected |
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| rhel | 9 | fixed | |
| sles | affected | | |
| almalinux | 8 | fixed | kernel-doc-4.18.0-513.5.1.el8_9.noarch.rpm |
| rhel | 8 | fixed | |
References
- https://access.redhat.com/errata/RHSA-2023:6583
- https://www.suse.com/security/cve/CVE-2023-35825.html
- https://access.redhat.com/errata/RHSA-2023:7077
- https://bugzilla.redhat.com/2024989
- https://bugzilla.redhat.com/2073091
- https://bugzilla.redhat.com/2133453
- https://bugzilla.redhat.com/2133455
- https://bugzilla.redhat.com/2139610
- https://bugzilla.redhat.com/2147356
- https://bugzilla.redhat.com/2148520
- https://bugzilla.redhat.com/2149024
- https://bugzilla.redhat.com/2151317
- https://bugzilla.redhat.com/2156322
- https://bugzilla.redhat.com/2165741
- https://bugzilla.redhat.com/2165926
- https://bugzilla.redhat.com/2168332
- https://bugzilla.redhat.com/2173403
- https://bugzilla.redhat.com/2173430
- https://bugzilla.redhat.com/2173434
- https://bugzilla.redhat.com/2173444
- https://bugzilla.redhat.com/2174400
- https://bugzilla.redhat.com/2175903
- https://bugzilla.redhat.com/2176140
- https://bugzilla.redhat.com/2177371
- https://bugzilla.redhat.com/2177389
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.